An external network access processing method and device

By intercepting and processing external network access requests, and using third-party identification and keys to generate verification information, the problem of user internal account leakage during external network access is solved and information security is improved.

CN115694865BActive Publication Date: 2025-06-24INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210756097.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-30
Publication Date
2025-06-24
Estimated Expiration
2042-06-30

AI Technical Summary

Technical Problem

During the external network access process, the confidentiality of the company's confidential information is threatened, and the user's internal account and password are at risk of leakage.

Method used

By intercepting external access requests, desensitize the user's internal account based on the third-party identity, generate a digital identity, and use the agreed key and timestamp to generate verification information, and send forward requests to the third-party server.

Benefits of technology

It effectively avoids the leakage of user internal accounts, improves the security of information, and ensures the confidentiality of confidential information in the enterprise.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115694865B_ABST
    Figure CN115694865B_ABST
Patent Text Reader

Abstract

The present invention provides an external network access processing method and apparatus, relating to the field of information security technology. The method includes: intercepting an external access request, where the external access request includes a user's internal account and a third-party identifier; performing desensitization processing on the user's internal account based on the third-party identifier to obtain a digital identity identifier corresponding to the user's internal account; obtaining a predefined key according to the third-party identifier, and generating verification information according to the predefined key, the digital identity identifier, and a timestamp; sending a forwarding request corresponding to the external access request to a third-party server corresponding to the third-party identifier, where the forwarding request includes the verification information and the digital identity identifier. The apparatus is used to execute the above method. The external network access processing method and apparatus provided by the embodiments of the present invention can avoid the leakage of the user's internal account and improve the security of information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to an external network access processing method and device. Background Art

[0002] Live training is becoming more and more widely used as a new training method that is not restricted by time and space and can ensure interactivity and timeliness.

[0003] Currently, many companies have launched third-party live broadcast platforms to train their employees. However, due to the insecurity of the external network environment, the confidentiality of the company's confidential information is threatened. For example, there is a risk of leakage of the internal user accounts and passwords of corporate employees. Therefore, how to improve the security of information during access to the external network has become an important issue that needs to be solved in this field. Summary of the invention

[0004] In view of the problems in the prior art, an embodiment of the present invention provides an external network access processing method and device, which can at least partially solve the problems in the prior art.

[0005] In a first aspect, the present invention provides an external network access processing method, comprising:

[0006] Intercepting external access requests, wherein the external access requests include the user's internal account and third-party identification;

[0007] Desensitizing the user's internal account based on the third-party identifier to obtain a digital identity identifier corresponding to the user's internal account;

[0008] Obtaining an agreed key according to the third-party identifier, and generating verification information according to the agreed key, the digital identity identifier and the timestamp;

[0009] Sending a forwarding request corresponding to the external access request to a third-party server corresponding to the third-party identifier, wherein the forwarding request includes the verification information and the digital identity identifier.

[0010] In a second aspect, the present invention provides an external network access processing device, comprising:

[0011] An interception module, used to intercept external access requests, wherein the external access requests include a user's internal account and a third-party identifier;

[0012] A desensitization module, used to perform desensitization processing on the user's internal account based on the third-party identifier to obtain a digital identity identifier corresponding to the user's internal account;

[0013] A generation module, used to obtain an agreed key according to the third-party identifier, and generate verification information according to the agreed key, the digital identity identifier and a timestamp;

[0014] A sending module, configured to send a forwarding request corresponding to the external access request to a third-party server corresponding to the third-party identifier, where the forwarding request includes the verification information and the digital identity identifier.

[0015] In a third aspect, the present invention provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the external network access processing method described in any of the above embodiments is implemented.

[0016] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the external network access processing method described in any of the above embodiments is implemented.

[0017] In a fifth aspect, the present invention provides a computer program product, where the computer program product includes a computer program. When the computer program is executed by a processor, the external network access processing method described in any of the above embodiments is implemented.

[0018] The external network access processing method and device provided by the embodiments of the present invention intercept an external access request, where the external access request includes a user's internal account and a third-party identifier; perform desensitization processing on the user's internal account based on the third-party identifier to obtain a digital identity identifier corresponding to the user's internal account; obtain a predefined key according to the third-party identifier, and generate verification information according to the predefined key, the digital identity identifier, and a timestamp; send a forwarding request corresponding to the external access request to a third-party server corresponding to the third-party identifier, where the forwarding request includes the verification information and the digital identity identifier, which can avoid the leakage of the user's internal account and improve the security of information. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts. In the drawings:

[0020] Figure 1 is a schematic structural diagram of an external network access processing system provided by the first embodiment of the present invention.

[0021] Figure 2 is a schematic flowchart of an external network access processing method provided by the second embodiment of the present invention.

[0022] Figure 3 is a schematic flowchart of an external network access processing method provided by the third embodiment of the present invention.

[0023] Figure 4 It is a schematic flowchart of the external network access processing method provided by the fourth embodiment of the present invention.

[0024] Figure 5 It is a schematic flowchart of the external network access processing method provided by the fifth embodiment of the present invention.

[0025] Figure 6 It is a schematic structural diagram of the external network access processing system provided by the sixth embodiment of the present invention.

[0026] Figure 7 It is a schematic flowchart of the external network access processing method provided by the seventh embodiment of the present invention.

[0027] Figure 8 It is a schematic structural diagram of the external network access processing device provided by the eighth embodiment of the present invention.

[0028] Figure 9 It is a schematic structural diagram of the external network access processing device provided by the ninth embodiment of the present invention.

[0029] Figure 10 It is a schematic structural diagram of the external network access processing device provided by the tenth embodiment of the present invention.

[0030] Figure 11 It is a schematic structural diagram of the external network access processing device provided by the eleventh embodiment of the present invention.

[0031] Figure 12 It is a schematic structural diagram of the external network access processing device provided by the twelfth embodiment of the present invention.

[0032] Figure 13 It is a schematic structural diagram of the external network access processing device provided by the thirteenth embodiment of the present invention.

[0033] Figure 14 It is a schematic structural diagram of the external network access processing device provided by the fourteenth embodiment of the present invention.

[0034] Figure 15 It is a schematic physical structure diagram of the electronic device provided by the fifteenth embodiment of the present invention. Detailed implementation manners

[0035] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer and more understandable, the following further describes the embodiments of the present invention in detail with reference to the accompanying drawings. Herein, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but do not limit the present invention. It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be arbitrarily combined with each other.

[0036] Figure 1 It is a schematic structural diagram of an external network access processing system provided by the first embodiment of the present invention. As Figure 1 described, the external network access processing system provided by the embodiment of the present invention includes at least one internal terminal 1, a relay server 2, and at least one third-party server 3, where:

[0037] The relay server 2 is communicatively connected to each third-party server 3, and each internal terminal 1 is communicatively connected to the relay server 2. Each internal terminal 1 needs to access the external network through the relay server 2. Among them, the internal terminal 1 is each device within the enterprise that can communicate over the network, including but not limited to electronic devices such as desktop computers, laptop computers, and tablet computers. The third-party server 3 is a server that can provide external services for the enterprise, such as a server providing online meeting services, a server providing live broadcast services, etc.

[0038] The relay server 2 is used to execute the external network access processing method provided by the embodiment of the present invention, intercept the external access requests sent by the internal terminal 1, and perform relevant processing to prevent the leakage of confidential information within the enterprise, so as to improve information security.

[0039] Figure 2 It is a schematic flowchart of an external network access processing method provided by the first embodiment of the present invention. As Figure 2 shown, the external network access processing method provided by the embodiment of the present invention includes:

[0040] S201. Intercept the external access request, where the external access request includes a user's internal account and a third-party identifier;

[0041] Specifically, when an enterprise employee needs to access a third-party server, an external access request can be sent to the third-party server through the internal terminal, and the relay server will intercept the external access request. Among them, the external access request includes a user's internal account and a third-party identifier. The enterprise employee can log in to the user's internal account on the internal terminal. The third-party identifier is set according to actual needs, and the embodiment of the present invention does not make any limitations.

[0042] For example, for a third-party live broadcast platform, there will be a dedicated live broadcast software, and the application identifier unique to the live broadcast software can be used as the third-party identifier.

[0043] S202. Perform de-sensitization processing on the user's internal account based on the third-party identifier to obtain a digital identity identifier corresponding to the user's internal account;

[0044] Specifically, after intercepting the external access request, the relay server performs desensitization processing on the user's internal account through the third-party identifier, and can obtain the digital identity identifier corresponding to the user's internal account. Each user internal account uniquely corresponds to a digital identity identifier. The relay server can store the correspondence between the user internal account and the digital identity identifier. Performing desensitization processing on the user internal account can avoid directly exposing the user internal account to the third-party server and improve the security of the user internal account.

[0045] S203. Obtain the agreed key according to the third-party identifier, and generate verification information according to the agreed key, the digital identity identifier, and the timestamp

[0046] Specifically, the relay server can query and obtain the agreed key corresponding to the third-party identifier according to the third-party identifier, and then generate verification information according to the agreed key, the digital identity identifier, and the timestamp. Among them, the correspondence between the third-party identifier and the agreed key is preset. The third-party server corresponding to the third-party identifier can interact with the relay server to determine the agreed key. The timestamp can be generated based on the time of intercepting the external access request.

[0047] S204. Send a forwarding request corresponding to the external access request to the third server corresponding to the third-party identifier, where the forwarding request includes the verification information and the digital identity identifier.

[0048] Specifically, the relay server sends a forwarding request carrying the verification information and the digital identity identifier to the third-party server. The verification information is used to verify the security and timeliness of the forwarding request. The digital identity identifier is used to identify the enterprise employee accessing the third-party server. The forwarding request corresponds to the external access request.

[0049] After receiving the forwarding request, the third-party server can query and obtain the agreed key according to the device identifier of the relay server, then generate verification information according to the agreed key, the digital identity identifier, and the received timestamp, and then compare the above verification information with the verification information. If the verification information is the same as the verification information, it indicates that the forwarding request is valid, and the third-party server will allow the login access through the digital identity identifier. If the verification information is different from the verification information, it indicates that the forwarding request is invalid, and the third-party server can return a prompt message indicating that the forwarding request is invalid to the relay server. Among them, the method used to generate the verification information is the same as the method used to generate the verification information. The received timestamp can be generated based on the reception time of receiving the forwarding request.

[0050] The external network access processing method provided by the embodiment of the present invention intercepts external access requests, where the external access requests include user internal accounts and third-party identifiers; performs desensitization processing on the user internal accounts based on the third-party identifiers to obtain digital identity identifiers corresponding to the user internal accounts; obtains a predefined key according to the third-party identifier, and generates verification information according to the predefined key, the digital identity identifier, and the time stamp; and sends a forwarding request corresponding to the external access request to a third-party server corresponding to the third-party identifier, where the forwarding request includes the verification information and the digital identity identifier, which can avoid the leakage of user internal accounts and improve information security.

[0051] Figure 3 is a schematic flowchart of the external network access processing method provided by the third embodiment of the present invention. As Figure 3 shown, on the basis of the above embodiments, further, the performing desensitization processing on the user internal account based on the third-party identifier to obtain a digital identity identifier corresponding to the user internal account includes:

[0052] S301. Generate a user internal identifier uniquely corresponding to the user internal account;

[0053] Specifically, the relay server generates a user internal identifier uniquely corresponding to the user internal account by using a set algorithm. Among them, the set algorithm is set according to actual needs, such as a hash algorithm, which is not limited in the embodiment of the present invention. The relay server may store the correspondence between the user internal identifier and the user internal account.

[0054] S302. Encrypt the user internal identifier according to the third-party identifier to obtain a digital identity identifier corresponding to the user internal account.

[0055] Specifically, the relay server may use the third-party identifier as a key to encrypt the user internal identifier to obtain a digital identity identifier corresponding to the user internal account. The relay server may store the one-to-one correspondence between the user internal identifier and the digital identity identifier.

[0056] Figure 4 is a schematic flowchart of the external network access processing method provided by the fourth embodiment of the present invention. As Figure 4 shown, on the basis of the above embodiments, further, the generating verification information according to the predefined key, the digital identity identifier, and the time stamp includes:

[0057] S401. Concatenate the predefined key, the digital identity identifier, and the time stamp into an information string;

[0058] Specifically, the relay server splices the agreed key, the digital identity identifier, and the timestamp into an information string, and the information string can be obtained by concatenating the agreed key, the digital identity identifier, and the timestamp end to end.

[0059] S402. Encrypt the information string through a preset algorithm to obtain the verification information.

[0060] Specifically, the relay server encrypts the information string through a preset algorithm, and the encrypted information string is the verification information. Among them, the preset algorithm is set according to actual needs. For example, the MD5 algorithm is adopted, and the embodiments of the present invention are not limited thereto.

[0061] On the basis of the above embodiments, further, the external network access processing method provided by the embodiments of the present invention further includes:

[0062] Verify the legality of the user's internal account.

[0063] Specifically, after intercepting the external access request, the relay server can verify the legality of the user's internal account, and can verify whether the user's internal account has been logged in. If not logged in, the relay server will prohibit the external access request. If logged in, the relay server will proceed to step S202.

[0064] Figure 5 is a flowchart of the external network access processing method provided by the fifth embodiment of the present invention. As Figure 5 shown, on the basis of the above embodiments, further, the external network access processing method provided by the embodiments of the present invention further includes:

[0065] S501. Receive user training data, where the user training data includes training data corresponding to each digital identity identifier;

[0066] Specifically, enterprise employees can access a third-party server to participate in online live training, and the third-party server stores the training data of enterprise employees corresponding to the digital identity identifiers. The relay server can receive the user training data from the third-party server. Among them, the user training data may include each digital identity identifier and corresponding training data. The training data may include information such as training duration, training content, training location, training teacher, and teacher evaluation.

[0067] For example, the relay server can regularly send a training data acquisition request to the third-party server, and the third-party server will respond to the training data acquisition request and return user training data to the relay server. Or, after the live training is completed, the third-party server sends user training data to the relay server.

[0068] S502. Decrypt each digital identity identifier according to the third - party identifier to obtain the user internal identifier corresponding to each digital identity identifier, and obtain the user internal account corresponding to each digital identity identifier according to the corresponding relationship between the user internal identifier and the user internal account;

[0069] Specifically, the relay server decrypts each digital identity identifier according to the third - party identifier, can obtain the user internal identifier corresponding to each digital identity identifier, and then obtain the user internal account corresponding to each digital identity identifier according to the user internal identifier corresponding to each digital identity identifier and the corresponding relationship between the user internal identifier and the user internal account. Among them, the digital identity identifier is obtained after encrypting the user internal identifier with the third - party identifier as the key, and the digital identity identifier and the user internal identifier are in one - to - one correspondence. The user internal identifier is generated by a set algorithm and is in one - to - one correspondence with the user internal account. The corresponding relationship between the user internal identifier and the user internal account is stored in advance.

[0070] S503. Store the user internal account and the training data in correspondence according to the training data corresponding to each digital identity identifier and the user internal account corresponding to each digital identity identifier.

[0071] Specifically, the relay server corresponds the training data corresponding to each digital identity identifier with the user internal account corresponding to each digital identity identifier, realizes the correspondence between the user internal account and the training data, and stores the training data corresponding to the user internal account, so as to obtain the training data of enterprise employees that can be recognized within the enterprise.

[0072] The external network access processing method provided by the embodiment of the present invention realizes the automatic collection and archiving of training data, and improves the data collection efficiency.

[0073] On the basis of the above - mentioned embodiments, further, the external network access processing method provided by the embodiment of the present invention further includes:

[0074] If it is known that the data format of the user training data is different from the preset storage format, then convert the user training data into the data of the preset storage format.

[0075] Specifically, the relay server compares the data format of the user training data with the preset storage format. If the data format of the user training data is different from the preset storage format, then the user training data will be converted into the data of the preset storage format. Among them, the preset storage format is set according to actual needs, such as set to the object format, which is not limited in the embodiment of the present invention.

[0076] Different third-party servers store data in various formats. Through format conversion, data in different formats are all converted into a unified preset storage format, which facilitates the aggregation and storage of user training data from different sources. The aggregated data is also convenient for analysis and evaluation.

[0077] For example, if the preset storage format is the object format and the received user training data is in XML format, then the user training data is converted from XML format to object format.

[0078] Based on the above embodiments, further, the external network access processing method provided by the embodiments of the present invention further includes:

[0079] Screen the training data corresponding to the user's internal account according to the data screening rule to obtain the retained training data corresponding to the user's internal account.

[0080] Specifically, for the received user training data, there may be redundant or meaningless information. To reduce the amount of stored data, the training data corresponding to the user's internal account can be screened according to the data screening rule to obtain the retained training data corresponding to the user's internal account. Among them, the data screening rule is preset and is set according to actual needs, which is not limited in the embodiments of the present invention.

[0081] For example, the user training data includes training duration, training content, training location, teacher evaluation, and training teacher. For the training duration and training content that the enterprise focuses on for employees, the screening rule is set to retain the training duration and training content. The transfer server will screen out the training duration and training content corresponding to each digital identity identifier from the user training data, and remove the training location, teacher evaluation, and training teacher.

[0082] Next, taking the access of enterprise employees to a third-party live broadcast platform as an example, the specific implementation process of the external network access processing method provided by the embodiments of the present invention will be described.

[0083] Figure 6 It is a schematic structural diagram of the external network access processing system provided by the sixth embodiment of the present invention. As Figure 6 shown, the external network access processing system provided by the embodiments of the present invention includes a plurality of internal terminals 601, a transfer server 602, and at least one third-party live broadcast platform 603, where:

[0084] Each internal terminal 601 is connected to the transfer server 602 through the enterprise internal network, and the transfer server 602 is communicatively connected to each third-party live broadcast platform 603.

[0085] Enterprise employees log in to internal applications on the internal terminal 601 through their internal user accounts, and the internal applications record the operations of enterprise employees on the internal terminal 601. Each enterprise employee has a unique corresponding internal user account. The specific process for enterprise employees to access a third-party live streaming platform is as Figure 7 shown.

[0086] Step 1: Send an external access request. An enterprise employee sends an external access request through the internal terminal 601. The external access request includes the internal user account and the application identifier of the live streaming software of the third-party live streaming platform 603.

[0087] Step 2: Intercept the external access request. The relay server 602 intercepts the external access request sent by the internal terminal 601.

[0088] Step 3: Judge the legitimacy of the internal user account. The relay server 602 judges whether the internal user account has been logged in. If the internal user account has been logged in, then it passes the legitimacy verification and enters the fourth step; if the internal user account has not been logged in, then a prompt message indicating the failure of the legitimacy verification of the internal user account is returned to the internal terminal 601.

[0089] Among them, the relay server 602 can send a login query request to the server corresponding to the internal application. The login query request includes the internal user account. The server corresponding to the internal application can query the current status of the internal user account. If the internal user account is in the logged-in state, then the logged-in information is returned to the relay server 602. Based on the logged-in information, the relay server 602 determines that the internal user account passes the legitimacy verification. If the internal user account is in the non-logged-in state, then the non-logged-in information is returned to the relay server 602. Based on the non-logged-in information, the relay server 602 determines that the legitimacy verification of the internal user account fails.

[0090] Step 4: Perform desensitization processing on the internal user account. The relay server 602 generates a unique corresponding internal user identifier for the internal user account based on the hash algorithm, and then encrypts the internal user identifier with the application identifier as the key to obtain the digital identity identifier corresponding to the internal user account.

[0091] Step 5: Generate verification information. The relay server 602 queries and obtains the agreed key corresponding to the application identifier according to the application identifier, and generates a timestamp a based on the time when the external access request is intercepted. Then, the agreed key, the digital identity identifier, and the timestamp a are concatenated into an information string X, and the information string X is encrypted through the MD5 algorithm to obtain the verification information. Among them, the application identifier and the agreed key corresponding to the application identifier are stored in advance.

[0092] Step 6: Send a forwarding request. The relay server 602 sends the digital identity identifier and the authentication information in the forwarding request to the third-party live streaming platform 603.

[0093] Step 7: Verify the forwarding request. The third-party live streaming platform 603 generates a timestamp b based on the reception time of the forwarding request, queries and obtains the agreed key according to the device identifier of the relay server 602, then concatenates the agreed key, the digital identity identifier, and the timestamp b into an information string Y, and then encrypts the information string Y through the MD5 algorithm to obtain the verification information. The third-party live streaming platform 603 compares the verification information with the verification information. If the verification information is the same as the verification information, it means that the forwarding request is valid. Then the third-party live streaming platform 603 will return the live streaming page to the relay server 602, and the relay server 602 will send the live streaming page to the internal terminal 601, and enterprise employees can view the live streaming page. If the verification information is different from the verification information, it means that the forwarding request is invalid. Then the third-party live streaming platform 603 can send a prompt message indicating that the forwarding request is invalid to the relay server 602.

[0094] The third-party live streaming platform 603 can record the digital identity identifier and the corresponding live streaming to obtain user training data. The relay server 602 can regularly obtain user training information from the third-party live streaming platform 603. If enterprise employees watch live streams on different third-party live streaming platforms 603, then the relay server 602 can regularly obtain user training data from different third-party live streaming platforms 603. If the data format of the user training data provided by the third-party live streaming platform 603 is different from the preset storage format of the relay server 602, then the user training data is converted into data in the preset storage format, and the user training data of the same employee on different third-party live streaming platforms 603 is integrated through the digital identity identifier to form employee training data within the enterprise.

[0095] The employee training data is presented to the administrator in different forms such as cockpit views and data reports, including but not limited to information such as employee training files, employee evaluations of teachers, utilization rates of each live streaming platform, and annual training distribution, facilitating better operation of enterprise education resources by the administrator.

[0096] Figure 8 is a schematic structural diagram of the external network access processing device provided in the eighth embodiment of the present invention, as Figure 8 shown, the external network access processing device provided in the embodiment of the present invention includes an interception module 801, a desensitization module 802, a generation module 803, and a sending module 804, where:

[0097] The interception module 801 is used to intercept external access requests, and the external access requests include the user's internal account and the third-party identifier; the desensitization module 802 is used to desensitize the user's internal account based on the third-party identifier to obtain the digital identity identifier corresponding to the user's internal account; the generation module 803 is used to obtain the agreed key according to the third-party identifier, and generate verification information according to the agreed key, the digital identity identifier, and the time stamp; the sending module 804 is used to send the forwarding request corresponding to the external access request to the third-party server corresponding to the third-party identifier, and the forwarding request includes the verification information and the digital identity identifier.

[0098] Specifically, when an enterprise employee needs to access a third-party server, an external access request can be sent to the interception module 801 through an internal terminal, and the interception module 801 will intercept the external access request. Among them, the external access request includes the user's internal account and the third-party identifier. The enterprise employee can log in to the user's internal account on the internal terminal. The third-party identifier is set according to actual needs, and the embodiments of the present invention do not make any limitations.

[0099] After intercepting the external access request, the desensitization module 802 will desensitize the user's internal account through the third-party identifier, and can obtain the digital identity identifier corresponding to the user's internal account. Each user's internal account will uniquely correspond to a digital identity identifier. The desensitization module 802 can store the corresponding relationship between the user's internal account and the digital identity identifier. Desensitizing the user's internal account can avoid directly exposing the user's internal account to the third-party server and improve the security of the user's internal account.

[0100] The generation module 803 can query and obtain the agreed key corresponding to the third-party identifier according to the third-party identifier, and then generate verification information according to the agreed key, the digital identity identifier, and the time stamp. Among them, the corresponding relationship between the third-party identifier and the agreed key is preset. The time stamp can be generated based on the time when the external access request is intercepted.

[0101] The sending module 804 sends a forwarding request carrying the verification information and the digital identity identifier to the third-party server. The verification information is used to verify the security and timeliness of the forwarding request. The digital identity identifier is used to identify the enterprise employee accessing the third-party server. The forwarding request corresponds to the external access request.

[0102] The external network access processing device provided by an embodiment of the present invention intercepts an external access request, where the external access request includes a user's internal account and a third-party identifier; desensitizes the user's internal account based on the third-party identifier to obtain a digital identity identifier corresponding to the user's internal account; obtains a predefined key according to the third-party identifier, and generates verification information according to the predefined key, the digital identity identifier, and a timestamp; and sends a forwarding request corresponding to the external access request to a third-party server corresponding to the third-party identifier, where the forwarding request includes the verification information and the digital identity identifier, which can avoid the leakage of the user's internal account and improve information security.

[0103] Figure 9 FIG. is a schematic structural diagram of the external network access processing device provided by the ninth embodiment of the present invention. As Figure 9 shown, on the basis of the above embodiments, further, the desensitization module 802 includes a generation unit 8021 and a first encryption unit 8022, where:

[0104] The generation unit 8021 is configured to generate a user internal identifier uniquely corresponding to the user's internal account; the first encryption unit 8022 is configured to encrypt the user internal identifier according to the third-party identifier to obtain a digital identity identifier corresponding to the user's internal account.

[0105] Figure 10 FIG. is a schematic structural diagram of the external network access processing device provided by the tenth embodiment of the present invention. As Figure 10 shown, on the basis of the above embodiments, further, the generation module 803 includes a splicing unit 8031 and a second encryption unit 8032, where:

[0106] The splicing unit 8031 is configured to splice the predefined key, the digital identity identifier, and the timestamp into an information string; the second encryption unit 8032 is configured to encrypt the information string through a preset algorithm to obtain the verification information.

[0107] Figure 11 FIG. is a schematic structural diagram of the external network access processing device provided by the eleventh embodiment of the present invention. As Figure 11 shown, on the basis of the above embodiments, further, the external network access processing device provided by an embodiment of the present invention further includes a verification module 805, where:

[0108] The verification module 805 is configured to perform a legality verification on the user's internal account.

[0109] Figure 12 FIG. is a schematic structural diagram of the external network access processing device provided by the twelfth embodiment of the present invention. As Figure 12As shown, based on the above embodiments, further, the external network access processing device provided by an embodiment of the present invention further includes a receiving module 806, a decryption module 807, and a storage module 808, where:

[0110] The receiving module 806 is configured to receive user training data, where the user training data includes training data corresponding to each digital identity identifier; the decryption module 807 is configured to decrypt each digital identity identifier according to the third-party identifier to obtain the user internal identifier corresponding to each digital identity identifier, and obtain the user internal account corresponding to each digital identity identifier according to the correspondence between the user internal identifier and the user internal account; the storage module 808 is configured to store the user internal account and the training data in a corresponding manner according to the training data corresponding to each digital identity identifier and the user internal account corresponding to each digital identity identifier.

[0111] Figure 13 is a schematic structural diagram of the external network access processing device provided by the thirteenth embodiment of the present invention. As Figure 13 As shown, based on the above embodiments, further, the external network access processing device provided by an embodiment of the present invention further includes a conversion module 809, where:

[0112] The conversion module 809 is configured to convert the user training data into data in the preset storage format after learning that the data format of the user training data is different from the preset storage format.

[0113] Figure 14 is a schematic structural diagram of the external network access processing device provided by the fourteenth embodiment of the present invention. As Figure 14 As shown, based on the above embodiments, further, the external network access processing device provided by an embodiment of the present invention further includes a screening module 810, where:

[0114] The screening module 810 is configured to screen the user training data corresponding to the user internal account according to the data screening rule to obtain the retained training data corresponding to the user internal account.

[0115] The embodiments of the device provided by the embodiments of the present invention can specifically be used to execute the processing procedures of the above method embodiments, and their functions will not be elaborated here. Reference can be made to the detailed descriptions of the above method embodiments.

[0116] It should be noted that the external network access processing method and device provided by the embodiments of the present invention can be used in the financial field and can also be used in any technical field other than the financial field. The embodiments of the present invention do not limit the application fields of the external network access processing method and device.

[0117] Figure 15 is a schematic physical structure diagram of the electronic device provided by the fifteenth embodiment of the present invention. As Figure 15As shown, the electronic device may include: a processor 1501, a communications interface 1502, a memory 1503, and a communication bus 1504. Among them, the processor 1501, the communications interface 1502, and the memory 1503 complete mutual communication through the communication bus 1504. The processor 1501 may call logic instructions in the memory 1503 to execute the following method: intercept an external access request, where the external access request includes a user internal account and a third-party identifier; perform de-sensitization processing on the user internal account based on the third-party identifier to obtain a digital identity identifier corresponding to the user internal account; obtain a pre-agreed key according to the third-party identifier, and generate verification information according to the pre-agreed key, the digital identity identifier, and a timestamp; send a forwarding request corresponding to the external access request to a third-party server corresponding to the third-party identifier, where the forwarding request includes the verification information and the digital identity identifier.

[0118] In addition, when the logic instructions in the above-mentioned memory 1503 are implemented in the form of a software functional unit and sold or used as an independent product, they may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, may be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs.

[0119] This embodiment discloses a computer program product. The computer program product includes a computer program stored on a computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the methods provided in the above method embodiments, for example, including: intercepting an external access request, where the external access request includes a user internal account and a third-party identifier; performing de-sensitization processing on the user internal account based on the third-party identifier to obtain a digital identity identifier corresponding to the user internal account; obtaining a pre-agreed key according to the third-party identifier, and generating verification information according to the pre-agreed key, the digital identity identifier, and a timestamp; sending a forwarding request corresponding to the external access request to a third-party server corresponding to the third-party identifier, where the forwarding request includes the verification information and the digital identity identifier.

[0120] This embodiment provides a computer-readable storage medium storing a computer program that causes a computer to execute the methods provided in the above method embodiments, for example, including: intercepting an external access request, where the external access request includes a user internal account and a third-party identifier; performing de-sensitization processing on the user internal account based on the third-party identifier to obtain a digital identity identifier corresponding to the user internal account; obtaining a pre-agreed key according to the third-party identifier, and generating verification information according to the pre-agreed key, the digital identity identifier, and a time stamp; sending a forwarding request corresponding to the external access request to a third-party server corresponding to the third-party identifier, where the forwarding request includes the verification information and the digital identity identifier.

[0121] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0122] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the specified functions in Figure 1 one or more of the flows Figure 1 or multiple flows and / or blocks

[0123] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that realizes the specified functions in Figure 1 one or more of the flows Figure 1 or multiple flows and / or blocks

[0124] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are executed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions for implementing the functions specified in one process or a plurality of processes and / or boxes Figure 1 one process or a plurality of processes and / or boxes Figure 1 steps for implementing the functions specified in one box or a plurality of boxes.

[0125] In the description of this specification, the description with reference to the terms "one embodiment", "a specific embodiment", "some embodiments", "for example", "example", "specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0126] The specific embodiments described above further elaborate on the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. An external network access processing method, characterized in that, Including: Intercept an external access request, where the external access request includes a user internal account and a third-party identifier; wherein, the third-party identifier is a server identifier uniquely corresponding to a third-party server that matches the third-party identifier; Based on the third-party identifier, perform desensitization processing on the user internal account to obtain a digital identity identifier corresponding to the user internal account; Obtain a predefined key according to the third-party identifier, and generate verification information according to the predefined key, the digital identity identifier, and a timestamp; Send a forwarding request corresponding to the external access request to the third-party server corresponding to the third-party identifier, where the forwarding request includes the verification information and the digital identity identifier; Wherein, the performing desensitization processing on the user internal account based on the third-party identifier to obtain a digital identity identifier corresponding to the user internal account includes: generating a user internal identifier uniquely corresponding to the user internal account; encrypting the user internal identifier according to the third-party identifier to obtain a digital identity identifier corresponding to the user internal account; Wherein, the obtaining a predefined key according to the third-party identifier includes: querying, according to a predefined correspondence between the third-party identifier and the predefined key, to obtain the predefined key corresponding to the third-party identifier.

2. The method according to claim 1, characterized in that, The generating verification information according to the predefined key, the digital identity identifier, and a timestamp includes: Concatenating the predefined key, the digital identity identifier, and the timestamp into an information string; Encrypting the information string through a predefined algorithm to obtain the verification information.

3. The method according to claim 1, wherein Also including: Performing a legality verification on the user internal account.

4. The method according to any one of claims 1 to 3, characterized in that, Also including: Receiving user training data, where the user training data includes training data corresponding to each digital identity identifier; Decrypting each digital identity identifier according to the third-party identifier to obtain a user internal identifier corresponding to each digital identity identifier, and according to the correspondence between the user internal identifier and the user internal account, obtaining a user internal account corresponding to each digital identity identifier; Correspondingly storing the user internal account and the training data according to the training data corresponding to each digital identity identifier and the user internal account corresponding to each digital identity identifier.

5. The method according to claim 4, wherein Also including: If it is known that the data format of the user training data is different from a predefined storage format, then convert the user training data into data in the predefined storage format.

6. The method according to claim 4, characterized in that Also including: Filtering the user training data corresponding to the user internal account according to a data filtering rule to obtain reserved training data corresponding to the user internal account.

7. An external network access processing device, characterized in that, Including: An interception module, configured to intercept an external access request, where the external access request includes a user internal account and a third-party identifier; wherein, the third-party identifier is a server identifier uniquely corresponding to a third-party server that matches the third-party identifier; A desensitization module, configured to perform desensitization processing on the user internal account based on the third-party identifier to obtain a digital identity identifier corresponding to the user internal account; A generation module, configured to obtain a predefined key according to the third-party identifier, and generate verification information according to the predefined key, the digital identity identifier, and a timestamp; A sending module, configured to send a forwarding request corresponding to the external access request to a third-party server corresponding to the third-party identifier, where the forwarding request includes the verification information and the digital identity identifier; Among them, the desensitization module includes a generation unit and a first encryption unit, where: the generation unit is configured to generate a user internal identifier uniquely corresponding to the user internal account; the first encryption unit is configured to encrypt the user internal identifier according to the third-party identifier to obtain a digital identity identifier corresponding to the user internal account; Among them, the generation module is specifically configured to: query, according to a preset correspondence between a third-party identifier and a convention key, a convention key corresponding to the third-party identifier.

8. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, the method according to any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

10. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Cross-application access method and apparatus

    CN106302606A

  • Interface access control method based on multiple identities of user and related equipment

    CN113765676A