A network access method, a network connection system and a storage medium

By embedding client type identification information in SSL VPN technology and determining access permissions based on preset permission relationships, the problem of information leakage after client access is solved, enabling access control for clients with different device and operating system types, and improving the security of server network resources.

CN115834234BActive Publication Date: 2026-04-17BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING TOPSEC NETWORK SECURITY TECH
Filing Date
2022-12-21
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing SSL VPN technology has low security after the client accesses the enterprise's internal network, which may lead to information leakage.

Method used

By including identification information representing the client type in the client request message, the server determines access permissions based on preset permission relationships, generates user identity information, establishes an authorization tunnel for communication, and restricts access for different types of clients.

Benefits of technology

It improves the security of server network resources, reduces the risk of information leakage, and enhances access control for clients with different device types and operating system types.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834234B_ABST
    Figure CN115834234B_ABST
Patent Text Reader

Abstract

The application provides a network access method, a network connection system and a storage medium, and relates to the field of network security.The network access method is applied to a server end, and the network access method comprises the following steps: receiving a request message of a client for accessing a network, wherein the request message carries identification information representing a client type; determining an access authority of the client based on a preset authority relationship between the request message, an access authority and the client type; the client type is a device type or an operating system type of the client; and the access authority is distributed to the client, so that the client establishes a communication connection between the client and the server end based on the access authority.When the client accesses, the access authority is distributed to the client according to the client type, the influence of the security problems of different clients on the network resources of the server is reduced, and the security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and more specifically, to a network access method, a network connection system, and a storage medium. Background Technology

[0002] SSL (Security Socket Layer) VPN (Virtual Private Network) technology is a VPN technology that establishes a secure remote access channel based on the Secure Socket Layer protocol, enabling devices to access both the Internet and the enterprise's internal network simultaneously.

[0003] Currently, SSL VPN connections typically verify the identity of requesting clients using their user accounts and passwords to determine whether access is permitted. However, some devices have lower security levels, potentially leading to the leakage of internal corporate information via the internet after connection to the corporate network, thus compromising information security. Summary of the Invention

[0004] In view of this, this application provides a network access method, a network connection system, and a computer-readable storage medium to improve the security of the server network after the client accesses the server.

[0005] In a first aspect, embodiments of this application provide a network access method applied to a server. The network access method includes: receiving a request message from a client requesting network access, the request message carrying identification information representing the client type; determining the client's access permission based on a preset permission relationship between the request message, access permission, and the client type; the client type being the client's device type or operating system type; and assigning the access permission to the client, so that the client establishes a communication connection between the client and the server based on the access permission.

[0006] In this embodiment, the client's network access request message carries identification information representing the client type. As a result, the server can determine the type of client requesting access and allocate access permissions to the server based on the client type. This restricts access to the server for different types of clients, reduces access for clients with lower security, thereby reducing security issues such as information leakage and improving the security of server network resources.

[0007] In one embodiment, the preset permission relationship includes allowed client types. Determining the client's access permission based on the preset permission relationship between the request message, access permission, and the client type includes: determining the identification information in the request message; determining the client type corresponding to the identification information; and determining that the client's access permission is allowed when the corresponding client device type is determined to be one of the allowed client types.

[0008] In this embodiment, the client type can be determined by the identification information carried in the request message, and it can be determined whether the client is allowed to access. Thus, the client is granted the corresponding access permission. This can reduce the access of clients with lower security, thereby reducing the impact of client access on the security of server network resources.

[0009] In one embodiment, allocating the access permission to the client includes: when it is determined that the access permission is allowed, generating user identity information representing the access scope of the client; and sending the user identity information to the client so that the client can communicate with the server based on the user identity information.

[0010] In this embodiment of the application, after allowing client access, the scope of access allowed by the client is restricted by the user's identity information, thereby reducing the information obtained by the client from the server, thus reducing the information leakage problem that may be caused by client security issues and improving the security of client access to the server.

[0011] In one embodiment, after sending the user identity information to the client, the method further includes: establishing an authorization tunnel between the client and the server based on the user identity information; receiving the user identity information sent by the client based on the authorization tunnel; verifying the user identity information; and, upon determining that the verification is successful, enabling the authorization channel to take effect, so that the client and the server can communicate based on the authorization channel.

[0012] Secondly, embodiments of this application provide a network access method applied to a client. The network access method includes: generating a network access request message based on the client type of the client; sending the request message to a server; receiving access permissions generated by the server based on the client type; and establishing a communication connection between the client and the server based on the access permissions.

[0013] In this embodiment, the client type is included in the request message of the client requesting network access. As a result, the server can assign access permissions to the client based on the client type, thereby reducing the access of clients with lower security types and improving the security of clients accessing the server's network resources.

[0014] In one embodiment, generating a request message for accessing the network based on the client type includes: generating identification information based on the client type; and concatenating the identification information with an initial request message to obtain the request message.

[0015] In this embodiment, by concatenating the identification information with the initial request message, the concatenation process is relatively fast, which can reduce the latency caused to the network connection by making the request message carry the identification information, thereby improving the efficiency of the client accessing the server.

[0016] In one embodiment, the client type includes the device type of the client, and generating identification information based on the client type includes generating the identification information based on the device type of the client, wherein the device type includes mobile terminal and PC terminal.

[0017] In this embodiment, identification information is generated based on the client's device type. This allows for restrictions on access from clients of different device types, reducing access from clients with lower security levels and improving the security of server network resources.

[0018] In one embodiment, the client type includes the client's operating system type, and generating identification information based on the client type includes generating the identification information based on the client's operating system type.

[0019] In this embodiment, identification information is generated based on the client's operating system type. This allows for restrictions on access by clients with different operating system types, reducing access by clients with less secure operating system types and improving the security of server network resources.

[0020] Thirdly, this application provides a network connection system, comprising: a client for performing the method as described in any of the second aspects; and a server for performing the method as described in any of the first aspects.

[0021] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when run on a computer, causes the computer to perform the network access method as described in the first aspect or the network access method as described in the second aspect. Attached Figure Description

[0022] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a schematic diagram of the structure of a network connection system provided in an embodiment of this application;

[0024] Figure 2 An interactive schematic diagram of a network access method provided in an embodiment of this application;

[0025] Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application;

[0026] Icons: Electronic device 300; Processor 310; Memory 320. Detailed Implementation

[0027] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0028] Before introducing the solution of this application, the scenario targeted by this application will be explained in order to facilitate understanding of the solution.

[0029] Typically, corporate internal networks do not allow access from non-corporate devices, while internal devices can access them normally. For example, employees can access company administrative systems using their office devices, but not their personal devices. However, in scenarios requiring remote work, users can use their personal devices to establish a remote data communication channel with the corporate internal network via SSL VPN technology. This channel offers high security, allowing users' personal devices to securely access the corporate internal network.

[0030] However, different devices may have security issues, such as data collection and eavesdropping. Since user devices can connect to the Internet and transmit data through the Internet, if the device is connected to the company's internal network, it may lead to the collection and publication of internal company data on the Internet, resulting in the leakage of internal company information, security problems, and economic losses to the company.

[0031] Please see Figure 1 , Figure 1 This is a schematic diagram of a network access system provided in an embodiment of this application. The network access system includes a server and a client.

[0032] On the server side, an SSL VPN gateway is configured, which can be used to verify the identity of clients requesting access.

[0033] The client can be any type of electronic device. For example, the client can be a mobile phone, a computer, etc. The client can also have different operating systems, such as Android, Windows (a computer operating system), iOS (a mobile device operating system), etc.

[0034] In this scenario, the client can establish a communication connection with the server via SSL VPN to access the server's network resources.

[0035] The network access method provided in this application will now be explained in conjunction with the aforementioned network access system.

[0036] Please see Figure 2 , Figure 2 A flowchart illustrating a network access method provided in this application embodiment. The network access method includes:

[0037] S110, Generate a request message for accessing the network based on the client's client type.

[0038] When a client needs to access network resources on a server, it must be authenticated. If the client is successfully authenticated, it is allowed to access the server's network resources. In this embodiment, the client can concatenate the username and password entered by the user to generate an initial request message for authentication, so that the server can authenticate the client using the initial request message. The concatenation can be performed according to the HTTP (Hypertext Transfer Protocol) protocol format.

[0039] Then, during authentication, the client can establish an initial communication channel with the server. This initial communication channel is used for data communication during user authentication, such as sending request messages and receiving feedback from the server regarding authentication. This initial communication channel can be an SSL VPN tunnel. The client can send request messages to the server through this initial communication tunnel so that the server can verify the username and password.

[0040] In this application, the request message also carries identification information that represents the client type.

[0041] In one embodiment, enabling the request message to carry identification information includes: generating identification information based on the client type; and concatenating the identification information with the initial request message to obtain the request message.

[0042] In this embodiment, since users may use different types of devices as clients to access network resources from the server, such as mobile phones and computers, when the client generates a request message, it can simultaneously obtain its own device type and generate corresponding identification information. For example, the identification information for a PC can be "PC," and the identification information for a mobile phone can be "mobile," etc.

[0043] The identification information can be concatenated with information from the initial request message, such as the username and password, to obtain a request message carrying the identification information. In some embodiments, the request message is concatenated using the HTTP protocol format to obtain an HTTP format request message. The HTTP format request message header includes a User-Agent (an identification attribute). The User-Agent key can be used to write different strings. Therefore, a string representing the client type can be written to the User-Agent key to carry identification information in the request message.

[0044] In the embodiments of this application, the types of clients can be distinguished in different ways so that the identification information represents different information of the clients.

[0045] In one embodiment, the identification information can characterize the client's device type, so as to generate identification information based on the client's device type.

[0046] The client's device type can include mobile and PC. By using identification information to characterize the client's device type, access restrictions can be implemented for clients with different device types. For example, when the client is a PC (Personal Computer), the identification information can be "PC," and when the client is a mobile device, the identification information can be "Phone." Furthermore, the client's device type can be further subdivided to obtain different identification information; for example, when the client is an Android phone, the identification information can be "Android," and when the client is an Apple computer, the identification information can be "iMac."

[0047] In one embodiment, the identification information can characterize the client's operating system type, so as to generate identification information based on the client's operating system type.

[0048] The client's operating system type can include PC operating systems, various mobile phone operating systems, such as iOS, Windows, and Android. By using identification information to represent the client's operating system type, access restrictions on the client can be implemented based on the client's operating system type.

[0049] For example, when a Windows client connects, the identification information may include the strings "WINDOWS" or "Windows"; when a Mac client connects, the identification information may include the strings "MAC" or "iPad"; when an iOS client connects, the identification information may include the strings "IOS" or "iPhone"; and when an Android client connects, the identification information may include the strings "ANDROID" or "Android". The all-uppercase substrings are generated based on the client's operating system type. The substrings with the first letter capitalized and "iPad" are generated based on the client's device type.

[0050] It is understood that the above are merely examples and should not be construed as limiting this application.

[0051] In some embodiments, an interface can be provided to the server-side administrator to customize the client type, so that the administrator can set different client types according to their own needs, so that when the client generates a request message, it carries the client type customized by the administrator according to its own client attribute information.

[0052] S120, the client sends a request message to the server.

[0053] In this embodiment, the client can send a request message to the server through the initial communication channel so that the server can verify the request message.

[0054] After receiving the request message, the server parses it to obtain the username and password, and then verifies them. The process of verifying the username and password can be found in existing technologies and will not be elaborated upon here.

[0055] If verification fails, the server can reject the client's access and send an error message to the client. If verification succeeds, the server can proceed to the next step of verifying the client type.

[0056] S130: Determine the client's access permissions based on the preset permission relationship between the request message, access permissions, and client type.

[0057] Verifying usernames and passwords is a process of authenticating the client's identity. However, the client's device type can affect the information security of the server's network resources. Therefore, in this embodiment, after authenticating the client's identity, it is also necessary to verify the client's type. This allows for the allocation of corresponding permissions to the client based on the client type and preset permission relationships, thereby restricting the client's access.

[0058] In one embodiment, the preset permission relationship includes allowed client types. Based on the preset permission relationship between the request message, access permission, and client type, the client's access permission is determined, including: determining the identification information in the request message; determining the client type corresponding to the identification information; and when the corresponding client device type is determined to be an allowed client type, the client's access permission is determined to be allowed.

[0059] In this embodiment, the server has multiple client types and corresponding identification information for each client type, and the server also has access permissions for each client type. Access permissions may include allowing access or denying access.

[0060] After verifying the client's identity, the request message can be directly parsed to obtain the identification information carried within it. For example, in an HTTP request message, the User-Agent value can be extracted. The server then compares this identification information with preset client types to determine the client type represented by the information. Finally, based on the preset access permissions for each client type, the server determines the client's access permissions.

[0061] For example, the server denies access to PCs but allows access to mobile devices. When a request message carries the identifier information of a PC, it determines that the client type corresponding to the request message is a PC, and then the access permission for that client is denied.

[0062] In this embodiment, for clients with access denied permissions, a prompt message can be sent to the client first. The prompt message can include the reason for the access denial, for example: "The type of device used does not allow access." It should be understood that the above prompt message is merely an example, and other forms of prompt message are possible, which will not be elaborated upon here.

[0063] Optionally, access permissions may also include the scope of client access to server network resources.

[0064] In one embodiment, when the access permission is determined to be allowed, user identity information representing the client's access scope is generated so that the user identity information is sent to the client, and the client communicates with the server based on the user identity information.

[0065] In this embodiment, different access permissions can be set for different users. For example, for employees in the sales department, in addition to access permissions to company public resources and general functions, permissions for the sales system module can also be set. For employees in the production department, in addition to access permissions to company public resources and general functions, permissions for the production system module can also be set.

[0066] In this embodiment, after determining whether the client is allowed to access, a session ID can be generated for clients with access permission. That is, the session ID can be used to represent the user's identity information. Different access permissions can be granted to the client based on the user's identity information, so that after the client communicates normally with the server, it can access the resources that it can access based on the user's identity information.

[0067] In some embodiments, user identity information can be determined based on the user identity corresponding to the username. It is understood that a username can represent a user. In this case, the permissions corresponding to the username can be determined based on the user's identity, such as job type, job level, etc., and then the corresponding user identity information can be generated based on the permissions. For example, if an employee belongs to the production department of the company, after determining that the client's request message carries the employee's username, user identity information can be generated based on the employee's corresponding permissions in the production department.

[0068] In some embodiments, user identity information can also be determined based on client type. In this embodiment, since different clients may have different security levels, corresponding permissions can be set according to different client types. For example, an employee may have permissions for the production department. When accessing the system via a mobile device, their permissions are limited to accessing general functions but not the production system, and user identity information is generated based on these permissions. When accessing the system via a PC, their permissions are limited to accessing both general functions and the production system, and corresponding user identity information is generated based on these permissions.

[0069] It is understood that the above is merely an example and should not be construed as limiting this application. Server administrators can set rules for generating user identity information based on internal requirements for client device types and user identities within companies, enterprises, schools, etc. By generating user identity information, client access to the server's network resources can be restricted, thereby improving server security.

[0070] S140, the server assigns access permissions to the client.

[0071] After generating access permissions, a response message can be generated and sent to the client through the initial communication channel. The client can then receive the response message through the initial communication channel.

[0072] S150, the client establishes a communication connection with the server based on access permissions.

[0073] In this embodiment, after receiving the response message, the client can determine the access permissions carried in the response message.

[0074] If access permission is denied, the process of establishing a connection with the server ends. At this point, a pop-up window can be displayed to show the server's feedback information so that the user can know the reason for the access denial.

[0075] If the received response message carries user identification information, it indicates that the client is authorized to access the server. In this case, the client can access the permitted content based on the access scope indicated by the user identification information.

[0076] In one embodiment, the client establishes an authorization tunnel between the client and the server based on user identity information; the server receives user identity information sent by the client based on the authorization tunnel; the server verifies the user identity information; and when the verification is successful, the server enables the authorization channel to take effect, so that the client and the server can communicate based on the authorization channel.

[0077] In the above process, the initial communication channel is used to transmit data during the client authentication process. Once authentication is complete, the initial communication channel is no longer used for data transmission. At this point, the client can re-establish an SSL tunnel, i.e., an authorization tunnel, between the client and the server to enable data communication.

[0078] The authorization tunnel is established based on user identity information. Through the authorization tunnel, the client's access to the server can be restricted. After the authorization channel is established, the user identity information must be sent to the server for verification to confirm whether the accessibility of the authorization channel matches the user's identity information.

[0079] After verification, if the accessibility of the authorized channel matches the user's identity information, the server can enable the authorized channel, allowing the client to communicate through it. If the accessibility of the authorized channel does not match the user's identity information, the authorized channel is disconnected, and an error message indicating a mismatch is sent to the client.

[0080] In this embodiment, the client's network access request message carries identification information representing the client type. As a result, the server can determine the type of client requesting access and allocate access permissions to the server based on the client type. This restricts access to the server for different types of clients, reduces access for clients with lower security, thereby reducing security issues such as information leakage and improving the security of server network resources.

[0081] Please refer to Figure 3 This application also provides an electronic device 300, which can serve as the execution subject of the aforementioned network access method applied to the client or server, including: a processor 310 and a memory 320 communicatively connected to the processor 310.

[0082] The memory 320 stores instructions that can be executed by the processor 310. The processor 310 executes the instructions to enable the processor 310 to perform the electromagnetic environment simulation method in the aforementioned embodiments.

[0083] The processor 310 and memory 320 can be connected via a communication bus, or via communication modules such as wireless communication modules, Bluetooth communication modules, 4G / 5G communication modules, etc.

[0084] Processor 310 can be an integrated circuit chip with signal processing capabilities. Processor 310 can be a general-purpose processor, including a CPU (Central Processing Unit), NP (Network Processor), etc.; it can also be a digital signal processor, application-specific integrated circuit, off-the-shelf programmable gate array, or other programmable logic device or transistor logic device, or discrete hardware component. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor.

[0085] The memory 320 may include, but is not limited to, RAM (Random Access Memory), ROM (Read Only Memory), PROM (Programmable Read-Only Memory), EPROM (Erasable Programmable Read-Only Memory), EEPROM (Electric Erasable Programmable Read-Only Memory), etc.

[0086] It is understood that the electronic device 300 may also include more general modules required by itself, which will not be described one by one in the embodiments of this application.

[0087] Based on the same inventive concept, embodiments of this application also provide a computer-readable storage medium storing a computer program thereon, which executes the methods provided in the above embodiments when the computer program is run.

[0088] The storage medium can be any available medium that a computer can access, or a data storage device such as a server or data center that integrates one or more available media. The available medium can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., SSDs (Solid State Disks)).

[0089] In the embodiments provided in this application, it should be understood that the disclosed methods can also be implemented in other ways. The functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0090] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM (Read-Only Memory), RAM (Random Access Memory), magnetic disks, or optical disks.

[0091] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0092] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A network access method, characterized in that, It is applied to the server side, wherein the server side is equipped with an SSL VPN gateway, and the SSL VPN gateway is used to verify the identity of the client requesting access; The network access method includes: The server receives a request message from a client requesting network access, the request message carrying identification information representing the client type; the server establishes an initial communication channel with the client, and the client sends the request message to the server through the initial communication channel; Based on the preset permission relationship between the request message, access permission, and client type, the access permission of the client is determined; the client type is the client's device type or operating system type. The access permission is assigned to the client, so that the client can establish a communication connection between the client and the server based on the access permission; The step of allocating the access permission to the client includes: when it is determined that the access permission is allowed, generating user identity information representing the access scope of the client; and sending the user identity information to the client so that the client can communicate with the server based on the user identity information. After sending the user identity information to the client, the method further includes: establishing an authorization channel between the client and the server based on the user identity information; receiving the user identity information sent by the client based on the authorization channel; verifying the user identity information; and, upon successful verification, activating the authorization channel to enable communication between the client and the server based on the authorization channel.

2. The method of claim 1, wherein, The preset permission relationship includes the types of clients allowed to access the system. Determining the access permission of a client based on the preset permission relationship between the request message, access permission, and the client type includes: Determine the identification information in the request message; Determine the client type corresponding to the identification information; When the corresponding client device type is determined to be the allowed client type, the client's access permission is determined to be allowed.

3. A network access method, characterized by, Applied to a client, the network access method includes: A request message for accessing the network is generated based on the client type of the client. The request message is sent to the server; the server is used to execute the network access method as described in claim 1 or 2. Receive the access permissions generated by the server based on the client type; A communication connection is established between the client and the server based on the access permissions.

4. The method of claim 3, wherein, The process of generating a network access request message based on the client type includes: Generate identification information based on the client type; The identification information is concatenated with the initial request message to obtain the request message.

5. The method of claim 4, wherein, The client type includes the client's device type, and the generation of identification information based on the client type includes: The identification information is generated based on the device type of the client, which includes mobile devices and PCs.

6. The method according to claim 4, characterized in that, The client type includes the client's operating system type, and the generation of identification information based on the client type includes: The identification information is generated based on the client's operating system type.

7. A network connection system, characterized by include: A client, configured to perform the method as described in any one of claims 3-6; The server side is used to execute the method as described in claim 1 or 2.

8. A computer-readable storage medium, characterized in that, The readable storage medium stores a computer program that, when run on a computer, causes the computer to perform the method as described in claim 1 or 2, or the method as described in any one of claims 3-6.

Citation Information

Patent Citations

  • Secure access control method and device for wireless network

    CN101909298A

  • Resource management method, device and system, electronic equipment and readable storage medium

    CN113992387A

  • Network access method and system

    CN115460004A