Communication method, device, electronic device and non-volatile storage medium
Through application monitoring and protection sent to terminal devices in the Zero Trust Control Center, the poor security problems caused by access to different devices are solved, and the security guarantee for the internal office system is achieved.
Patent Information
- Application Number
- CN202211446979.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-18
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-11-18
AI Technical Summary
Since internal office data can be browsed and accessed by different devices, there is a problem of poor security in the internal office system.
Send access requests to the Zero Trust Control Center through the terminal device to determine the device type and authenticate. When determining that the device type is a specific type, an application sent by the Zero Trust Control Center is received, which provides a secure access environment and monitors the access behavior of the terminal device. When abnormal access behavior is detected, perform the corresponding protection operation.
By monitoring the operations of the access personnel and protecting abnormal access operations, the security of internal office data is effectively ensured and the problem of poor security of internal office systems is solved.
Smart Images

Figure CN115801413B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information and communication technology, and in particular, to a communication method, device, electronic device and non-volatile storage medium. Background Art
[0002] With the rapid development of Internet technology, Internet office has gradually become the mainstream of modern office mode. Since Internet office can break the geographical and temporal limitations of office, it is widely used in various enterprises. However, the Internet office mode greatly increases the risk of internal enterprise data being exposed to the Internet environment, which can easily pose a great threat to office security.
[0003] With the combination of electronic technology and Internet technology, the devices for accessing internal office systems are no longer limited to fixed computers, but can be browsed and accessed by different terminal devices, increasing the risk of internal office data exposure and resulting in poor security of internal office systems.
[0004] To address the above-mentioned problems, no effective solution has been proposed yet. Summary of the invention
[0005] The embodiments of the present application provide a communication method, an apparatus, an electronic device and a non-volatile storage medium to at least solve the technical problem of poor security of the internal office system caused by the fact that internal office data in the related art can be browsed and accessed by different devices.
[0006] According to one aspect of an embodiment of the present application, a communication method is provided, including: a terminal device sends an access request to a zero trust control center, wherein the zero trust control center is used to determine the device type of the terminal device based on the access request, and authenticate the terminal device; when the device type of the terminal device is a first device type, receiving an application sent by the zero trust control center, wherein the application is used to provide a secure access environment at runtime, and monitor the access behavior of the terminal device; in the process of accessing business data through the application, when the application detects that the terminal device has abnormal access behavior, executing a protection operation corresponding to the abnormal access behavior through the application.
[0007] Optionally, the step of accessing business data through an application includes: displaying a verification interface to the target object through the application, and obtaining verification information entered by the target object in the verification interface; sending the verification information to the zero trust control center, and after the zero trust control center verifies the verification information, establishing a communication link with the office system to obtain business data from the office system.
[0008] Optionally, the step of accessing business data through an application includes: obtaining first facial feature information of the target object in the process of accessing the business data; sending the first facial feature information to a zero trust control center, wherein the zero trust control center is used to verify the first facial feature information based on second facial feature information, and the second facial feature information is pre-stored facial feature information corresponding to the verification information; if the first facial feature information is inconsistent with the second facial feature information, cutting off the communication link.
[0009] Optionally, the step of accessing business data through an application also includes: when the first facial feature information is consistent with the second facial feature information, collecting image information in a target area, wherein the target area is an area where the screen of the target device can be viewed; and when it is determined that third facial feature information exists in the image information, performing a blur operation on the business data through the application.
[0010] Optionally, the step of accessing business data through an application includes: in the process of accessing business data, monitoring a target port through the application and creating a virtual port, wherein the terminal device accesses the business data through the target port; generating dynamic random data in the same format as the business data through the application; in the case of detecting an abnormal access request, directing the abnormal access request to the virtual port through the application; and providing dynamic random data to an abnormal program that sends the abnormal access request through the virtual port.
[0011] Optionally, the step of generating dynamic random data in the same format as the business data through an application includes: determining the format of the business data; randomly generating target dynamic data in the same format as the business data; comparing the similarity between the target dynamic data and the business data; and when the similarity is less than a preset similarity threshold, determining that the target dynamic data is dynamic random data.
[0012] Optionally, the communication method further includes: when the similarity is not less than a preset similarity threshold, randomly generating target dynamic data again, and comparing the similarity between the target dynamic data and the business data until the similarity is less than the preset similarity threshold.
[0013] Optionally, the abnormal access behavior includes taking screenshots during access to business data, and the preset protection measures corresponding to the abnormal access behavior include clearing memory data of the terminal device; and reading pictures stored in the terminal device and deleting the pictures with the latest save time.
[0014] Optionally, the access request carries browser identification information of a browser running in the terminal device, wherein the browser identification information is used to determine the device type of the terminal device.
[0015] Optionally, the first device type is a device connected to an external network.
[0016] According to another aspect of an embodiment of the present application, a communication method is also provided, including: obtaining an access request sent by a terminal device; determining the device type of the terminal device based on the access request, and authenticating the terminal device; when the device type is a first device type, sending an application to the terminal device, wherein the application is used to provide a secure access environment during runtime and monitor the access behavior of the terminal device.
[0017] According to another aspect of an embodiment of the present application, a communication device is also provided, including: a first communication module, used by a terminal device to send an access request to a zero trust control center, wherein the zero trust control center is used to determine the device type of the terminal device based on the access request, and to authenticate the terminal device; a second communication module, used to receive an application sent by the zero trust control center when the device type of the terminal device is a first device type, wherein the application is used to provide a secure access environment at runtime and monitor the access behavior of the terminal device; a first processing module, used to perform protection operations corresponding to the abnormal access behavior through the application when the application detects abnormal access behavior of the terminal device during the process of accessing business data through the application.
[0018] According to another aspect of the embodiments of the present application, an electronic device is provided. The electronic device includes a processor, and the processor is used to run a program, wherein the communication method is executed when the program is run.
[0019] According to another aspect of the embodiments of the present application, a non-volatile storage medium is provided, the non-volatile storage medium includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the communication method by running the computer program.
[0020] In an embodiment of the present application, a terminal device is used to send an access request to a zero-trust control center, wherein the zero-trust control center is used to determine the device type of the terminal device based on the access request, and to authenticate the terminal device; when the device type of the terminal device is the first device type, an application sent by the zero-trust control center is received, wherein the application is used to provide a secure access environment at runtime, and to monitor the access behavior of the terminal device; in the process of accessing business data through an application, when the application detects that the terminal device has abnormal access behavior, the application executes a protection operation corresponding to the abnormal access behavior, and when the access environment formed by the apk (Android application package) sent by the zero-trust control center to the terminal device communicates with the internal office system or directly communicates with the internal office system through an intranet computer, the operation of the access personnel is monitored, and abnormal access operations are protected, thereby achieving the purpose of ensuring the security of internal office data, thereby solving the technical problem of poor security of the internal office system caused by the fact that internal office data in the related technology can be browsed and accessed by different devices. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0022] Figure 1 It is a hardware structure block diagram of a computer terminal (or electronic device) for implementing a communication method provided in an embodiment of the present application;
[0023] Figure 2 It is a schematic diagram of a communication method flow provided according to an embodiment of the present application;
[0024] Figure 3 is a schematic diagram of another communication method flow provided according to an embodiment of the present application;
[0025] Figure 4 is a schematic diagram of a zero-trust workflow provided according to an embodiment of the present application;
[0026] Figure 5 It is a schematic diagram of the architecture of a zero-trust working system provided according to an embodiment of the present application;
[0027] Figure 6 It is a structural diagram of a communication device provided according to an embodiment of the present application. DETAILED DESCRIPTION
[0028] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0029] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0030] In the related art, since the internal office data in the related art can be browsed and accessed by different devices, there is a problem of poor security of the internal office system. In order to solve this problem, the embodiments of the present application provide a relevant solution, which is described in detail below.
[0031] According to an embodiment of the present application, a communication method embodiment is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0032] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 FIG. 1 shows a hardware structure block diagram of a computer terminal (or electronic device) for implementing a communication method. Figure 1As shown, the computer terminal 10 (or electronic device 10) may include one or more (102a, 102b, ..., 102n are used to illustrate) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission module 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations are shown.
[0033] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuits". The data processing circuits may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuit may be a single independent processing module, or may be incorporated in whole or in part into any of the other components in the computer terminal 10 (or electronic device). As described in the embodiments of the present application, the data processing circuit acts as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).
[0034] The memory 104 can be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the communication method in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, realizing the above-mentioned communication method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0035] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0036] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 (or electronic device).
[0037] In the above operating environment, the embodiment of the present application provides a communication method. Figure 2 is a schematic diagram of a communication method flow provided according to an embodiment of the present application, such as Figure 2 As shown, the method comprises the following steps:
[0038] Step S202: The terminal device sends an access request to the zero trust control center, wherein the zero trust control center is used to determine the device type of the terminal device according to the access request and authenticate the terminal device;
[0039] The above-mentioned zero-trust control center is a system deployed between office equipment and internal office systems to ensure communication security. The zero-trust control center stores the company's employee information and grants each employee corresponding access rights based on their work content.
[0040] In some embodiments of the present application, the access request carries browser identification information of a browser running in the terminal device, wherein the browser identification information is used to determine the device type of the terminal device.
[0041] In this embodiment, the above-mentioned terminal device is an office device used by employees to access the internal office system. The office device can be a handheld office device, such as a mobile phone, a tablet, etc.; it can also be a computer-side office device, such as a desktop computer, a laptop computer, etc.
[0042] Specifically, when employees access the internal office system through office equipment, the office equipment will send the access request and the browser's kernel identification (that is, the above-mentioned browser identification information) directly to the zero trust control center. At this time, the zero trust control center will determine whether the employee accesses it through a mobile phone / tablet or a computer based on the browser identification sent.
[0043] Step S204: When the device type of the terminal device is the first device type, receiving an application sent by the zero trust control center, wherein the application is used to provide a secure access environment during operation and monitor access behavior of the terminal device;
[0044] In this embodiment, the above application is an application for information protection provided by the zero trust control center;
[0045] In some embodiments of the present application, the first device type is a device connected to an external network.
[0046] Specifically, if it is determined that the employee accesses the system through a mobile phone / tablet or a computer located on the external network (i.e., the first device type mentioned above), the zero trust control center will separately form an access apk (Android application package) file, send the apk file to the browser of the employee's mobile phone / tablet, and install the apk file to access the internal office system. When the apk file is installed and opened, the zero trust control center will verify the identity of the employee. After successful verification, the access request will be sent to the internal office system together with the employee's access rights. At this time, the internal office system will send the corresponding data to the access environment formed by the employee's mobile phone / tablet apk file according to the employee's access rights;
[0047] In some embodiments of the present application, the communication method further includes: when the device type is a second device type, obtaining business data through an intranet, wherein the second device type is a device connected to the intranet.
[0048] Specifically, if it is determined that the employee accesses the data through a computer located on the intranet (i.e., the second device type mentioned above), the zero trust control center verifies the employee's identity information. After successful verification, the access request together with the user's access rights will be sent to the internal office system. The internal office system will send the corresponding data directly to the computer according to the employee's access rights, and the data can be browsed and added, deleted, and modified through the browser on the computer.
[0049] Step S206: During the process of accessing business data through the application program, when the application program detects that the terminal device has abnormal access behavior, the application program executes a protection operation corresponding to the abnormal access behavior.
[0050] In some embodiments of the present application, the step of accessing business data through an application includes the following steps: displaying a verification interface to a target object through an application, and obtaining verification information entered by the target object in the verification interface; sending the verification information to a zero-trust control center, and after the zero-trust control center verifies the verification information, establishing a communication link with the office system to obtain business data from the office system.
[0051] Specifically, when an employee (i.e., the target object mentioned above) opens an apk file or a zero-trust client to access the internal office system, the zero-trust control center receives the employee's access request and sends the verification page data to the access environment formed by the employee's mobile phone / tablet apk file or to the zero-trust client. The employee then enters his or her name, work number, and employee access password on the verification page, or uses a mobile phone number for SMS authentication (i.e., the above-mentioned verification information), and submits it to the zero-trust control center for matching verification. If the match is successful, the access environment formed by the mobile phone / tablet apk file or the communication between the zero-trust client and the internal office system is established. Otherwise, no communication is established.
[0052] In order to further improve security, the steps of accessing business data through an application include the following steps: in the process of accessing business data, obtaining first facial feature information of the target object; sending the first facial feature information to the zero trust control center, wherein the zero trust control center is used to verify the first facial feature information based on second facial feature information, and the second facial feature information is pre-stored facial feature information corresponding to the verification information; when the first facial feature information is inconsistent with the second facial feature information, cutting off the communication link.
[0053] In some embodiments of the present application, the step of accessing business data through an application also includes the following steps: when the first facial feature information is consistent with the second facial feature information, collecting image information in a target area, wherein the target area is an area where the screen of the target device can be viewed; when it is determined that the third facial feature information exists in the image information, performing a blur operation on the business data through the application.
[0054] Specifically, when an employee communicates with the internal office system through a mobile phone / tablet / computer in an access environment formed by an apk file or a zero-trust client, the apk file and the zero-trust client will retrieve the camera on the mobile phone / tablet / computer to take real-time photos of the employee's facial information (i.e., the first facial feature information mentioned above) and upload it to the zero-trust control center. The zero-trust control center will compare the facial information taken in real time with the facial information previously entered by the employee (i.e., the second facial feature information mentioned above). If the comparison is successful, the communication between the collection / tablet / computer and the internal office system will continue. Otherwise, the communication between the mobile phone / tablet / computer and the internal office system will be interrupted. When the facial information comparison is successful, if the camera captures other people around the employee watching the screen (i.e., the situation where the third facial feature information is determined in the above-mentioned image information), the apk file and the zero-trust client will automatically blur the page. When the camera does not detect that there are other people around watching the computer screen, the apk file and the zero-trust client will restore the page to normal, avoiding the problem of office data being peeped.
[0055] In some embodiments of the present application, the step of accessing business data through an application includes the following steps: in the process of accessing business data, monitoring a target port through an application and creating a virtual port, wherein a terminal device accesses business data through the target port; generating dynamic random data in the same format as the business data through an application; in the case of detecting an abnormal access request, directing the abnormal access request to the virtual port through the application; and providing dynamic random data to an abnormal program that sends the abnormal access request through the virtual port.
[0056] Specifically, the apk file and the zero-trust client monitor the port of the access terminal (i.e., the target port mentioned above) in real time, and build a virtual port at the same time. Based on the form of the internal office data currently being accessed, they dynamically and randomly generate data similar to the form of the internal office data (i.e., the dynamic random data mentioned above), and then store these data in the form of a data table in the terminal memory. When it is detected that other programs or software access the port for communication between the terminal and the internal office system, the apk file and the zero-trust client will transfer the access request to the built virtual port and feed back the previously dynamically and randomly generated data to the current program or software.
[0057] In some embodiments of the present application, the step of generating dynamic random data in the same format as business data through an application includes the following steps: determining the format of the business data; randomly generating target dynamic data in the same format as the business data; comparing the similarity between the target dynamic data and the business data; and when the similarity is less than a preset similarity threshold, determining that the target dynamic data is dynamic random data.
[0058] In some embodiments of the present application, the communication method also includes the following steps: when the similarity is not less than a preset similarity threshold, randomly generating target dynamic data again, and comparing the similarity between the target dynamic data and the business data until the similarity is less than the preset similarity threshold.
[0059] Specifically, first obtain the current communication office data (i.e. the above-mentioned business data), parse the obtained data, determine the format type of the obtained business data, generate target dynamic data with the same format type as the current one, and compare the generated target dynamic data with the currently obtained business data. If the similarity reaches 60% (i.e. the above-mentioned preset similarity threshold), the generated data will be destroyed, and then continue to generate data until the similarity is less than 60%, and then store the generated data (i.e. the above-mentioned dynamic random data) in the form of a data table in the terminal memory.
[0060] The above preset similarity threshold can be adjusted according to actual needs.
[0061] In some embodiments of the present application, abnormal access behavior includes taking screenshots during access to business data, and the preset protection measures corresponding to the abnormal access behavior include clearing the memory data of the terminal device; and reading the pictures stored in the terminal device and deleting the pictures with the latest save time.
[0062] As an optional implementation method, when the internal office system is browsed and data is added, deleted and modified through the access environment formed by the apk file (i.e., the above-mentioned application) on the mobile phone / tablet / external network computer, the apk file will monitor the employee's operations in real time. When it is detected that the employee is taking a screenshot, the apk file will retrieve the image file in the employee's mobile phone / tablet and delete the most recently saved image, or clear the memory in the external network computer; when the employee is browsing and adding, deleting and modifying data in the internal office system through the intranet computer, the zero trust control center will monitor the employee's operations in real time. When it is detected that the employee is taking a screenshot, the zero trust control center will interrupt the communication between the intranet computer and the internal office system, thereby avoiding the problem of internal office data leakage.
[0063] The present application also provides a communication method. Figure 3 is a schematic diagram of another communication method flow provided according to an embodiment of the present application, such as Figure 3 As shown, the method comprises the following steps:
[0064] Step S302, obtaining an access request sent by a terminal device;
[0065] Step S304, determining the device type of the terminal device according to the access request, and performing identity authentication on the terminal device;
[0066] Step S306, when the device type is the first device type, sending the application to the terminal device, wherein the application is used to provide a secure access environment during operation and monitor the access behavior of the terminal device.
[0067] The following further introduces the communication method in steps S202 to S206 and the communication method in steps S302 to S306 of the embodiments of the present application.
[0068] Figure 4 is a schematic diagram of a zero-trust workflow provided according to an embodiment of the present application, Figure 5 is a schematic diagram of the architecture of a trust work system provided according to an embodiment of the present application, through Figure 5 Zero Trust Work System Architecture Execution Figure 4 The zero trust workflow shown includes the following steps:
[0069] Step S402, deploying a zero trust control center;
[0070] Specifically, a zero-trust control center is deployed between office equipment (i.e., the above-mentioned terminal equipment) and the internal office system. The office equipment can be a handheld office equipment, such as a mobile phone, a tablet, etc.; it can also be a computer-side office equipment, such as a desktop computer, a laptop, etc.;
[0071] Step S404, establishing a network connection;
[0072] Specifically, a cache server and a backup server are deployed in the office system, and a network connection is established between the cache server, the backup server and the zero-trust control center;
[0073] Step S406, input employee information and grant access rights;
[0074] Specifically, the company's employee information is entered into the zero-trust control center, and each employee is granted corresponding access rights according to their work content. Specifically, the employee's name, work number, employee access password, mobile phone number, responsible work content, and employee facial information are first entered into the zero-trust control center, and then the employee is granted corresponding access rights information according to the work content information, and the access rights information is stored in the zero-trust control center together with the employee's identity information;
[0075] Step S408, sending an access request and a kernel identifier to determine whether it is a mobile phone or tablet terminal or a computer terminal;
[0076] Specifically, when employees access the internal office system through office equipment, the office equipment will send the access request and the browser's kernel identification (that is, the above-mentioned browser identification information) directly to the zero trust control center. At this time, the zero trust control center will determine whether the employee accesses it through a mobile phone / tablet or a computer based on the browser identification sent.
[0077] Step S410, forming an apk file, installing the apk file and then accessing it;
[0078] Specifically, if it is determined that the employee accesses the system through a mobile phone / tablet (i.e., the first device type mentioned above), the zero trust control center will separately form an access apk (Android application package) file, send the apk file to the browser of the employee's mobile phone / tablet, and install the apk file to access the internal office system. When the apk file is installed and opened, the zero trust control center will verify the identity of the employee. After successful verification, the access request will be sent to the internal office system together with the employee's access rights. At this time, the internal office system will send the corresponding data to the access environment formed by the employee's mobile phone / tablet apk file according to the employee's access rights;
[0079] In the present application, the internal office system will send the corresponding data to the employee's office equipment according to the employee's access rights, thereby reducing the exposure of the office system in the network and further increasing the security of the office environment.
[0080] Step S412, obtaining the IP address of the computer, determining whether it is an intranet or an extranet, performing identity authentication, and sending the data corresponding to the access rights to the computer after successful authentication;
[0081] Specifically, if it is determined that the employee accesses the internal office system through a computer, the zero trust control center will obtain the IP address of the computer and determine whether the computer is located on the intranet or the extranet. If it is determined that the employee accesses the system through a computer located on the intranet (i.e., the second device type mentioned above), the zero trust control center will verify the employee's identity information. After successful verification, the access request will be sent to the internal office system together with the user's access rights. The internal office system will send the corresponding data directly to the computer based on the employee's access rights. Data browsing and addition, deletion and modification operations can be achieved through the browser on the computer. If it is determined that the computer is on the extranet, the operation in step S410 is executed.
[0082] This application solution isolates the office area from the personal area of the mobile phone / tablet / computer by determining the device type of the device accessing the internal office data, thus greatly ensuring the security of the office data.
[0083] Step S414, the apk file monitors the mobile phone and tablet terminal in real time, and automatically disconnects from the internal office system when a screenshot is found;
[0084] Specifically, when browsing, adding, deleting, and modifying data in the internal office system through the access environment formed by the apk file (i.e., the above-mentioned application) on the mobile phone / tablet / external network computer, the apk file will monitor the employee's operation in real time. When it is detected that the employee is taking a screenshot, the apk file will retrieve the image file in the employee's mobile phone / tablet and delete the most recently saved image, or clear the memory in the external network computer; when the employee browses, adding, deleting, and modifying data in the internal office system through the intranet computer, the zero trust control center will monitor the employee's operation in real time. When it is detected that the employee is taking a screenshot, the zero trust control center will interrupt the communication between the intranet computer and the internal office system;
[0085] As an optional implementation, after the communication connection between the office device and the internal office system is disconnected, the apk file will automatically scan whether there is any data leakage inside the office device. If any data is detected to be residual, the residual data will be automatically and permanently deleted.
[0086] As an optional implementation, when the apk file or the zero trust control center detects that an employee has taken screenshots more than three times, the zero trust control center will automatically reduce the employee's access rights; when it detects that an employee has taken screenshots more than five times, all access rights of the employee will be cleared, and the employee's information will be deleted from the zero trust control center, prohibiting the employee from accessing the internal office system. Dynamic monitoring of terminal environments and behaviors allows for dynamic permission adjustment and reduction, avoiding the risk of data leakage that traditional solutions cannot reduce for risky behaviors.
[0087] Step S416, when attacked, the data is stored in the cache server, and the cache server data is transferred to the backup server, and the office equipment establishes a connection with the backup server.
[0088] Specifically, when office equipment is communicating with the internal office system, if the core server of the internal office system is attacked or runs abnormally, the zero-trust control center will first store the data sent by the office equipment in the cache server, and at the same time transfer the data in the core server of the internal office system to any selected backup server, and then transfer the data in the cache server to the selected backup server, and establish a connection between the office equipment and the selected backup server;
[0089] When the core server of the internal office system has completed the attack defense or is repaired or overhauled to operate normally, the Zero Trust Control Center will disconnect the office equipment from the selected backup server, and store the data transmitted by the office equipment in the cache server. The data in the backup server will then be transferred to the core server, and the office equipment will be connected to the core server again.
[0090] Through the above steps, when the access environment formed by the apk sent by the zero trust control center to the terminal device communicates with the internal office system or directly communicates with the internal office system through the intranet computer, the operations of the access personnel are monitored and abnormal access operations are protected, thereby achieving the purpose of ensuring the security of internal office data, and further solving the technical problem of poor security of the internal office system caused by the fact that internal office data in related technologies can be browsed and accessed by different devices.
[0091] According to an embodiment of the present application, an embodiment of a communication device is also provided. Figure 6 is a schematic diagram of the structure of a communication device provided according to an embodiment of the present application. Figure 6 As shown, the device comprises:
[0092] A first communication module 60 is used for a terminal device to send an access request to a zero-trust control center, wherein the zero-trust control center is used to determine the device type of the terminal device according to the access request and to authenticate the terminal device;
[0093] The second communication module 62 is used to receive an application sent by the zero-trust control center when the device type of the terminal device is the first device type, wherein the application is used to provide a secure access environment during operation and monitor the access behavior of the terminal device;
[0094] The first processing module 64 is used to execute a protection operation corresponding to the abnormal access behavior through the application program when the application program detects that the terminal device has abnormal access behavior during the process of accessing business data through the application program.
[0095] It should be noted that the various modules in the above-mentioned communication device can be program modules (for example, a set of program instructions that implement a certain specific function) or hardware modules. For the latter, it can be expressed in the following forms, but is not limited to this: the expression form of each of the above-mentioned modules is a processor, or the functions of each of the above-mentioned modules are implemented by a processor.
[0096] It should be noted that the communication device provided in this embodiment can be used to perform Figure 2 The communication method shown, therefore, the relevant explanations and descriptions of the above communication method are also applicable to the embodiments of the present application and will not be repeated here.
[0097] The embodiment of the present application also provides a non-volatile storage medium, the non-volatile storage medium includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the following communication method by running the computer program: the terminal device sends an access request to the zero trust control center, wherein the zero trust control center is used to determine the device type of the terminal device based on the access request, and authenticate the terminal device; when the device type of the terminal device is the first device type, receive an application sent by the zero trust control center, wherein the application is used to provide a secure access environment at runtime, and monitor the access behavior of the terminal device; in the process of accessing business data through the application, when the application detects that the terminal device has abnormal access behavior, the application executes a protection operation corresponding to the abnormal access behavior. The above serial numbers of the embodiments of the present application are for description only and do not represent the advantages and disadvantages of the embodiments.
[0098] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0099] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the units can be a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0100] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0101] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0102] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk and other media that can store program codes.
[0103] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A communication method, characterized in that: include: The terminal device sends an access request to the zero trust control center, wherein the zero trust control center is used to determine the device type of the terminal device according to the access request, and authenticate the terminal device; In a case where the device type of the terminal device is the first device type, receiving an application sent by the zero trust control center, wherein the application is used to provide a secure access environment during runtime and monitor access behavior of the terminal device; In the process of accessing business data through the application, when the application detects that the terminal device has abnormal access behavior, the application performs a protection operation corresponding to the abnormal access behavior; The step of accessing the service data through the application comprises: in the process of accessing the service data, monitoring the target port through the application and creating a virtual port, wherein the terminal device accesses the service data through the target port; generating dynamic random data in the same format as the service data through the application; in the case of detecting an abnormal access request, directing the abnormal access request to the virtual port through the application; providing the dynamic random data to the abnormal program that sends the abnormal access request through the virtual port; The step of generating dynamic random data with the same format as the business data through the application includes: determining the format of the business data; randomly generating target dynamic data with the same format as the business data; comparing the similarity between the target dynamic data and the business data; and determining that the target dynamic data is the dynamic random data when the similarity is less than a preset similarity threshold.
2. The communication method according to claim 1, characterized in that: The communication method further comprises: In the case that the similarity is not less than the preset similarity threshold, the target dynamic data is randomly generated again, and the similarity between the target dynamic data and the business data is compared until the similarity is less than the preset similarity threshold.
3. The communication method according to claim 1, characterized in that: The abnormal access behavior includes taking screenshots during access to the business data, and the preset protection measures corresponding to the abnormal access behavior include clearing the memory data of the terminal device; and reading the pictures stored in the terminal device and deleting the pictures with the latest saving time.
4. The communication method according to claim 1, characterized in that: The access request carries browser identification information of the browser running in the terminal device, wherein the browser identification information is used to determine the device type of the terminal device.
5. The communication method according to claim 1, characterized in that: The first device type is a device connected to an external network.
6. The communication method according to claim 1, characterized in that: The communication method further comprises: In a case where the device type is a second device type, the business data is obtained through an intranet, wherein the second device type is a device connected to an intranet.
7. A communication device, characterized in that: include: A first communication module, configured for a terminal device to send an access request to a zero-trust control center, wherein the zero-trust control center is configured to determine a device type of the terminal device based on the access request, and to authenticate the terminal device; A second communication module is used to receive an application sent by the zero-trust control center when the device type of the terminal device is the first device type, wherein the application is used to provide a secure access environment during operation and monitor the access behavior of the terminal device; A first processing module is used for, in the process of accessing business data through the application program, when the application program detects that the terminal device has abnormal access behavior, executing a protection operation corresponding to the abnormal access behavior through the application program; Accessing the service data through the application comprises: in the process of accessing the service data, monitoring the target port through the application and creating a virtual port, wherein the terminal device accesses the service data through the target port; generating dynamic random data in the same format as the service data through the application; in the case of detecting an abnormal access request, directing the abnormal access request to the virtual port through the application; providing the dynamic random data to the abnormal program that sends the abnormal access request through the virtual port; The method of generating dynamic random data having the same format as the business data through the application includes: determining the format of the business data; randomly generating target dynamic data having the same format as the business data; comparing the similarity between the target dynamic data and the business data; and determining that the target dynamic data is the dynamic random data when the similarity is less than a preset similarity threshold.
8. A non-volatile storage medium, characterized in that: The non-volatile storage medium stores a program, wherein when the program is executed, the device where the non-volatile storage medium is located is controlled to execute the communication method according to any one of claims 1 to 6.
9. An electronic device, characterized in that: include: A memory and a processor, wherein the processor is used to run a program stored in the memory, wherein the program executes the communication method according to any one of claims 1 to 6 when running.
Citation Information
Patent Citations
Method and device for determining network environment of terminal user
CN108243414A
Method and device for downloading application program and processor
CN114826599A