Network access authentication method and system, remote interaction system, VPN

By receiving authorized connection requests and generating virtual network servers, the problem of insufficient security in remote medical device assistance is solved, and secure and convenient network access authentication is achieved, ensuring the secure control of remote medical devices.

CN115883117BActive Publication Date: 2026-04-17GE PRECISION HEALTHCARE LLC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GE PRECISION HEALTHCARE LLC
Filing Date
2021-09-28
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing telemedicine equipment assistance solutions are inadequate in terms of security and convenience. Traditional VPN access methods cannot effectively control unauthorized access, leading to security risks to hospital networks and equipment.

Method used

By receiving authorized connection requests, a virtual network server is generated and security rules are applied to establish a virtual network connection between the remote end and the network to be accessed. This includes the integration of authentication and resource scheduling modules to ensure the accuracy and security of authorized connections.

Benefits of technology

It enables secure control of remote medical devices, prevents unauthorized access, improves the security and convenience of network connections, and ensures real-time remote assistance for medical imaging systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115883117B_ABST
    Figure CN115883117B_ABST
Patent Text Reader

Abstract

Network access authentication method and system, remote interaction system, VPN. Embodiments of the present application disclose a remote interaction system of a medical imaging system, a network access authentication system and method, a computer readable storage medium, and a VPN. The medical imaging system comprises a medical imaging device and a computer device for controlling the medical imaging device, the computer device being connected to a local network to be accessed. The network authentication system comprises an authentication module and a resource scheduling module. The authentication module is configured to receive an authorized connection request from an authorized end, send the authorized connection request to a remote end, and receive a response message from the remote end. The resource scheduling module is configured to receive the authorized connection request sent by the authentication module, and allocate a virtual network server and generate a security rule based on the authorized connection request. The remote interaction system comprises the network authentication system and the virtual network server allocated by the resource scheduling module.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention generally relate to remote access network authentication, and more particularly to a network access authentication method and system, a computer-readable storage medium, a remote interaction system for a medical imaging system, and a Virtual Private Network (VPN). Background Technology

[0002] In the medical field, one of the main challenges in remote assistance with imaging equipment is ensuring the security and convenience of medical data and equipment data transmission during remote interaction.

[0003] Currently, there are no established standards for remote assistance with imaging equipment, such as CT and MRI. In some scenarios, video software running over the Internet is used to achieve the purpose of equipment sharing, such as social media video and third-party conferencing software. However, this solution cannot achieve interconnection and interoperability of equipment, and the actual effect of telemedicine is insufficient.

[0004] In some telemedicine scenarios, traditional Virtual Private Networks (VPNs) are used for interaction. However, due to inadequate network security management, numerous technical and management vulnerabilities are left when establishing telemedicine network channels. For example, with traditional VPN access schemes, regardless of whether the authentication system uses multi-factor authentication (such as certificates, passwords, or RSA), the access requester can complete all authentication processes independently. For instance, an access requester can access the hospital network at any time using a password, certificate, temporary token, etc., without the hospital's real-time detection. Such access methods result in a loss of security control over the hospital network and imaging equipment, potentially leading to unauthorized control of the equipment and posing significant security risks to both patients and hospital equipment. Summary of the Invention

[0005] This invention provides a network access authentication method, comprising:

[0006] Receive an authorization connection request from the authorization end, the authorization connection request including the identification information of the remote end to be authorized and the identification information of the network to be accessed;

[0007] Send the authorized connection request to the remote terminal;

[0008] Receive response messages from the remote end; and,

[0009] Based on the authorized connection request, a virtual network server is allocated and security rules are generated. The allocated virtual network server is used to apply the security rules to establish a virtual network connection with the remote terminal and the network to be accessed.

[0010] Another aspect of the present invention provides a computer-readable storage medium storing one or more instructions that can be executed by a processor to implement the network access authentication method of various aspects of the present invention.

[0011] In another aspect, the present invention provides a network access authentication system, comprising:

[0012] An authentication module is configured to receive an authorization connection request from an authorization terminal, send the authorization connection request to the remote terminal, and receive a response message from the remote terminal. The authorization connection request includes identification information of the remote terminal to be authorized and identification information of the network to be accessed.

[0013] The resource scheduling module is used to receive the authorization connection request sent by the authentication module, allocate a virtual network server based on the authorization connection request, and generate security rules. The allocated virtual network server is used to apply the security rules to establish a virtual network connection with the remote terminal and the network to be accessed.

[0014] In another aspect, the present invention provides a remote interactive system for a medical imaging system, the medical imaging system including a medical imaging device and a computer device for controlling the medical imaging device, the computer device being connected to a local network to be accessed, and the remote interactive system including:

[0015] The aforementioned network authentication system; and,

[0016] The virtual network server allocated by the resource scheduling module is used to establish the virtual network based on the security rules and to handle the interaction tasks between the remote terminal and the computer devices in the network to be accessed.

[0017] In another aspect, the present invention provides a virtual private network, comprising:

[0018] An authentication module is configured to receive an authorization connection request from an authorization terminal, send the authorization connection request to a remote terminal, and receive a response message from the remote terminal. The authorization connection request includes identification information of the remote terminal and identification information of the local network.

[0019] A dedicated network generation module is used to receive the authorization connection request sent by the authentication module, generate security rules based on the authorization connection request, and apply the security rules to establish a virtual private network between the remote terminal and the local network. Attached Figure Description

[0020] These and other features, aspects, and advantages of the invention will become better understood when the following detailed description is read with reference to the accompanying drawings, in which the same reference numerals are used throughout to denote the same parts, wherein:

[0021] Figure 1 A schematic structural block diagram of a remote interaction system for a medical imaging system according to an embodiment of the present invention is shown.

[0022] Figure 2 A schematic structural block diagram of a network access authentication system according to an embodiment of the present invention is shown;

[0023] Figure 3 A flowchart of a network access authentication method according to an embodiment of the present invention is shown;

[0024] Figure 4 A flowchart of a network access authentication method according to another embodiment of the present invention is shown;

[0025] Figure 5 A flowchart of a network access authentication method according to another embodiment of the present invention is shown;

[0026] Figure 6 A schematic block diagram of a virtual private network according to an embodiment of the present invention is shown. Detailed Implementation

[0027] To help those skilled in the art accurately understand the subject matter claimed by this invention, specific embodiments of the invention are described in detail below with reference to the accompanying drawings. In the following detailed description of these specific embodiments, this specification omits some well-known functions or structures to avoid unnecessary detail that would affect the disclosure of this invention.

[0028] Unless otherwise defined, the technical or scientific terms used in this claim and specification shall have the ordinary meaning understood by one of ordinary skill in the art to which this invention pertains. The terms “first” to “third” and similar terms used in this specification and claims do not indicate any order, quantity, or importance, but are merely used to distinguish different components. The terms “an” or “a” and similar terms do not indicate a quantity limitation, but rather indicate the presence of at least one. The terms “comprising” or “having” and similar terms mean that the elements or objects preceding “comprising” or “having” encompass the elements or objects listed following “comprising” or “having” and their equivalents, and do not exclude other elements or objects. The terms “connected” or “linked” and similar terms are not limited to physical or mechanical connections, but can include electrical and network communication connections, whether direct or indirect.

[0029] Figure 1A schematic structural block diagram of a remote interactive system for a medical imaging system according to an embodiment of the present invention is shown, wherein a medical imaging system 12 is shown. The medical imaging system 12 may include one of the systems such as CT (Computed Tomography), MRI (Magnetic Resonance Imaging), X-ray imaging, C-arm imaging, angiography, PET (Positron Emission Computed Tomography), etc., or may include a multimodal imaging system that combines multiple of the above imaging systems.

[0030] like Figure 1 As shown, the medical imaging system 12 includes a medical imaging device 122 and a computer device 124 for controlling the imaging device. Based on typical application scenarios, the computer device 124 can control the medical imaging device 122 to scan an object (e.g., a patient) based on the operation of a local user (e.g., a radiologist). In one example, the medical imaging device 122 may be a scanning device placed in a local hospital scanning room, and the computer device 124 may be a control device placed in an operating room isolated from the scanning room. The computer device 124 and the scanning device 122 can communicate via a local network (i.e., the network to be accessed) 14 for interaction for imaging control.

[0031] When remote medical assistance is needed, for example, by an expert, the expert can access the local network 14 from the remote end 16 to interact with the computer device 124 therein.

[0032] Local network 14 includes a border device 142, which provides an entry point for external devices to access local network 14. The border device 142 may include, for example, a router, a routing switch, etc., and may provide, for example, conversion between different network protocols.

[0033] The remote interaction system also includes a network access authentication system 20 and multiple virtual network servers 28. The network access authentication system 20 is used to authenticate and authorize unauthorized parties accessing the local network 14 from external sources (e.g., remote terminal 16), and allocate network servers 28 to generate a virtual network 29. The aforementioned boundary device 142 only allows authorized users to access the local network 14. Authenticated users of the remote terminal 16 can access the local network 14 via the virtual network 29 to remotely operate the medical imaging system 12 connected to the local network 14.

[0034] The aforementioned multiple virtual network servers 28 may include distributed servers for providing cloud access points. The aforementioned authentication system 20 may also be set up within the servers of this cloud network.

[0035] Figure 2 A schematic block diagram of the network access authentication system 20 is shown. (For example...) Figure 2 As shown, the network access authentication system 20 includes an authentication module 22 and a resource scheduling module 24. The authentication module 22 and the resource scheduling module 24 can be integrated on the same server or set up on different servers. The authentication module 22 is used to receive an authorization connection request R1 from the authorization terminal 15. In this embodiment, the radiologist or technician located at the authorization terminal 15 can generate and send the authorization connection request R1 based on operations performed on computer devices located within or outside the local network 14.

[0036] In one embodiment, the authentication module 22 receives an authorization connection request R1 from the authorization terminal 15 through the access management platform 26. The access management platform 26 can be a user interface based on a web browser or application settings. For example, the user of the authorization terminal 15 can access the access management platform 26 through a browser or application and generate the authorization connection request R1 in the management platform 26 by entering commands related to the authorization connection request R1. The management platform 26 then sends the generated authorization connection request R1 to the authentication module 22 for relevant authentication.

[0037] In one embodiment, the authorized connection request R1 includes identification information of the remote terminal 16 to be authorized and identification information of the network to be accessed (e.g., local network 14). The identification information of the remote terminal 16 may include, but is not limited to, identity information, IP address information, communication information, etc., used to identify the remote terminal user. The identification information of the network to be accessed may include at least one of the following: the identity information of the authorizing party, the attribute information of the network to be accessed (e.g., network configuration information including access port, routing information, etc.), and the information of the devices in the network to be accessed (e.g., the aforementioned border devices, imaging devices of medical imaging systems, and computer devices, etc.).

[0038] In other embodiments, the aforementioned authorized connection request R1 may further include access time information, which includes at least one of the start time and end time that allow the remote terminal 16 to establish a virtual network connection with the network to be accessed.

[0039] The authentication module 22 is also used to send the received authorized connection request R1 to the remote terminal 16. Similarly, the authentication module 22 can convey the received authorized connection request R1 to the remote terminal user who also accesses the access management platform 26 through the access management platform 26.

[0040] In other embodiments, the authentication module 22 may also send the authorized connection request R1 directly to the remote terminal 16.

[0041] In one example, the authentication module 22 may include a message parsing unit 221, which is used to parse the authorization connection request R1 received from the authorization end 15 and send the parsed authorization connection request R1 to the remote end 16 via one or more of, for example, email, SMS, or website information.

[0042] The authentication module 22 is also used to receive a response message R2 from the remote terminal 16. In one embodiment, the authentication module 22 receives the response message R2 through the access management platform 26. In an example scenario, after receiving the aforementioned authorized connection request R1, the user at the remote terminal 16 can access the access management platform 26 to respond. The response message R2 can indicate agreement to remotely access the local network 14 according to the specific content of the authorized connection request R1. By providing a user interface to users at both ends of the network through the access management platform 26 to communicate with the authentication module 22, users can achieve secure remote connection through simple operations, meeting the needs of real-time remote assistance in the field of medical imaging.

[0043] The resource scheduling module 24 is used to receive the authorized connection request R1 sent from the authentication module 22, and allocate a virtual network server 28 and generate a security rule R3 based on the authorized connection request R1. The allocated virtual network server 28 is used to apply the security rule R3 to establish a virtual network connection with the remote terminal 16 and the network to be accessed (e.g., the local network 14).

[0044] The aforementioned "security rules" include rules that must be followed when the border device 142 of the local network 14 accesses the virtual network, and may also include rules that must be followed when allowing the remote terminal 16 to access the virtual network. These security rules may include at least a portion of the authorized connection request R1, and may also include network configuration information. For example, security rule R3 may include the IP address of the remote terminal, the access port of the local network 14, and the routing information of the corresponding computer device 124 to be connected. Security rule R3 may further include time information for allowing the remote terminal 16 to access the local network.

[0045] In one example, the resource scheduling module 24 communicates with multiple virtual network servers 28 and sends task scheduling commands to them. Each virtual network server 28 establishes a connection with an external network according to the received task scheduling command. For example, it allows the local network 14 to access the corresponding virtual network and allows remote users to access the virtual network, so that remote users can access the local network 14.

[0046] In one example, the resource scheduling module 24 receives multiple authorized connection requests from the authentication module 22 to generate a list of authorized connection requests. Furthermore, the resource scheduling module 24 receives status update information from each virtual network server 28. Therefore, the resource scheduling module 24 can generate a scheduling plan based on the status of each network server (e.g., idle or busy level) and allocate virtual networks according to the scheduling plan.

[0047] In the above embodiments of the present invention, the authorized connection is established based on the authorized connection request initiated by the authorizing party. Since the authorized connection request initiated by the authorizing party includes the identification information of the remote terminal to be authorized, the networking method is more accurate and secure than the traditional connection authentication method, and avoids network security problems caused by unauthorized users arbitrarily accessing the network of the authorized terminal.

[0048] The resource scheduling module 24 generates security rule R3 based on the authorized connection request, so that the network server applies the security rule when making a remote connection, thereby further ensuring network security during the network connection process.

[0049] Based on the above description, the security rule R3 generated by the resource scheduling module 24 may also include a specified time period during which the remote terminal 16 is allowed to access the network to be accessed, such as at least one of the start time and end time.

[0050] By further specifying the time information for authorized access in the authorized connection request R1, network security issues can be prevented from being caused by the authorized party accessing the local network outside the allowed time period.

[0051] To further enhance network connection security, authentication module 22 is also used to receive access release instruction R4 from authorization terminal 15. Access release instruction R4 can be generated by authorization terminal 15 through access to the access management platform 26. Authentication module 22 can be configured to send the aforementioned access connection request R1 to resource scheduling center 24 upon receiving access release instruction R4 from authorization terminal 15.

[0052] In one example, the access management platform 26 adds the currently received access release instruction R4 as an instruction tag to the earlier received access connection request R1, so as to send the access connection request R1 with the instruction tag to the authentication module 22.

[0053] Furthermore, the authentication module 22 is configured to receive the aforementioned access release instruction only within a specific time (e.g., 5 minutes) prior to the access start time of the authorized connection request.

[0054] In one embodiment, the resource scheduling module 24 may include a first task unit 241, a second task unit 242, and a third task unit 243. The first task unit 241 is used to notify the border device 142 of the network to be accessed 14 to update its network configuration (e.g., setting access ports and routing information) according to the aforementioned security rule R3 and to receive a first confirmation message C1 from the border device 142 confirming the updated network configuration. The second task unit 242 is used to receive a second confirmation message C2 from the assigned virtual network server 28 confirming that the security rule R3 has been applied. The third task unit 243 is used to send the first confirmation message C1 and the second confirmation message C2 to the authentication module 22 to notify the authentication module 22 that it is ready to establish a remote connection.

[0055] The authentication module 22, upon receiving the first confirmation message C1 and the second confirmation message C2, generates access authentication information for accessing the network to be accessed 14, thereby allowing the remote terminal to access the local network 14 via the virtual network 29 based on the access authentication information. This access authentication information may include detailed information for accessing the local network 14, such as routing information.

[0056] The authentication module 22 can further send the generated access authentication information to the remote terminal 16 via, for example, email, SMS, or website messages. In one example, the authentication module 22 sends the access authentication information to the access management platform 26, so that when the remote user accesses the access management platform 26, the user can automatically obtain the detailed information of the remote access and remotely access the network 14 to be accessed based on the detailed information.

[0057] After establishing the remote connection, the computer device 124 in the local network 14 receives remote operation instructions from the remote terminal 16 through the virtual network 29 and performs relevant medical imaging operations. In one example, the operation is used to cause the medical imaging device 122 to perform a corresponding medical imaging scan or to cause the computer device 124 to perform a corresponding process.

[0058] In other embodiments, the authentication module 22 is also used to receive a connection interruption request R5 from the authorization terminal 15 through the access management platform 26, and send a connection interruption notification N1 to the resource scheduling module 24 based on the received connection interruption request. The resource scheduling module 24 is used to send the connection interruption notification N1 to the allocated virtual network server 28, so that the virtual network server 28 disconnects the network connection with the remote terminal 16.

[0059] Specifically, after receiving a connection interruption request from the authorization terminal 15, the authentication module 22 deletes the generated authorized connection authentication and sends a connection interruption notification to the corresponding virtual network server through the resource scheduling module 24, causing the virtual network server 28 to disconnect from the network connection with the remote terminal 16 until the authorized connection authentication is regenerated based on the operation of the authorization terminal 15.

[0060] Based on the aforementioned connection interruption notification, the virtual network server 28 can simultaneously disconnect the network connection with the local network 14 and reset / delete security rule R3.

[0061] After the connection is interrupted, the virtual network server 28 reports a status update message to the resource scheduling module 24, which includes a message that the remote connection has been released and the security rules have been reset. The resource scheduling module 24 can forward the status update message to the authentication module 22 and update the resource list based on the status update message. For example, it can update the status of the allocated virtual network server 28 to idle so that it can be reassigned. Based on this status update, the resource scheduling module 24 can further update the scheduling plan.

[0062] The authentication module 22 is further used to send the received status update message to the access management platform 26, so that the authorized end 15 and the remote end 16 can know the current remote connection status by accessing the access management platform 26.

[0063] Meanwhile, the authentication module 22 can also send notifications of remote connection interruption to the remote end 16 and the authorizing end 15 via one or more of email, SMS, and website messages.

[0064] Based on the received status update message, the authentication module 22 further updates the authorization list, for example, by removing the relevant content of the aforementioned remote connection from the list or changing the status of the remote connection.

[0065] Based on the unilateral termination request initiated by the authorized end, the aforementioned remote connection can be quickly and effectively disconnected and resources reset, thus preventing the remote end from continuing to operate devices on the local network when network security concerns arise.

[0066] Embodiments of the present invention may also provide a network access authentication method. Figure 3 A flowchart 30 of the method is shown.

[0067] In step 31, an authorization connection request is received from the authorization end, which includes the identification information of the remote end to be authorized and the identification information of the network to be accessed;

[0068] In step 32, the authorized connection request R1 is sent to the remote terminal 16;

[0069] In step 33, a response message is received from the remote end; and,

[0070] In step 34, a virtual network server is allocated based on the received authorized connection request and a security rule is generated. The allocated virtual network server is used to apply the security rule to establish a virtual network connection with the remote terminal 16 and the network to be accessed 14.

[0071] Furthermore, the aforementioned authorized connection request also includes access time information, which includes at least one of the start time and end time that allow the remote terminal 16 and the network terminal 14 to establish a virtual network connection.

[0072] Furthermore, the identification information of the network to be accessed includes at least one of the following: the identity information of the authorizing party, the attribute information of the network to be accessed, and the information of the devices in the network to be accessed. The devices include at least one of a medical imaging device 122, a computer device 124 interacting with the medical imaging device 122, and a border device 142.

[0073] Further, in step 32, sending an authorization connection request to the remote terminal 16 includes: parsing the authorization connection request; and sending the parsed authorization connection request to the remote terminal 16 via email, SMS message, website message or one or more of these methods.

[0074] Figure 4 A flowchart 40 illustrating a network access authentication method according to another embodiment of the present invention is shown, which includes the above-described steps 31-34, and further includes the following steps:

[0075] Step 41: Notify the border device to be connected to the network to update its network configuration according to the security rule;

[0076] Step 42: Receive a first confirmation message from the border device confirming the updated network configuration;

[0077] Step 43: Receive a second confirmation message from the virtual network server confirming that the security rule has been applied;

[0078] Step 44: Send access authentication information for accessing the network 14 to be accessed to the remote terminal 16.

[0079] Figure 5 A flowchart 50 illustrating a network access authentication method according to another embodiment of the present invention is shown, which includes the above-described steps 31-34, and further includes the following steps:

[0080] Step 51, receive a connection interruption request from the authorized end 15; and,

[0081] Step 52: Based on the connection interruption request, a connection interruption notification is sent to the virtual network server 28 so that the virtual network server 28 disconnects the network connection with the remote terminal 16 and resets the security rules.

[0082] The term "module" as used herein can be implemented in software, hardware, or a combination of both. For example, according to certain aspects of embodiments of the present invention, the term "module" as used herein can be implemented as a computer program module.

[0083] Although the steps of the method according to a specific embodiment of the present invention are shown as functional blocks, in Figures 3 to 5 The order of the functional blocks shown and the separation of actions between them are not intended to be restrictive. For example, functional blocks may be executed in different orders, and actions associated with a functional block may be combined with one or more other functional blocks or may be subdivided into multiple functional blocks.

[0084] This invention also provides a computer-readable storage medium that stores one or more instructions, which can be executed by a processor to implement the network access authentication methods described in the various embodiments above.

[0085] Figure 6 Another embodiment of a Virtual Private Network (VPN) 60 is shown, which can be used to establish a VPN 69 using a public network (e.g., the Internet) 70, so that a remote terminal 16 can access the local network 14 through the VPN 69.

[0086] The virtual private network 60 may include a server connecting the public network 70 and the local network 14. The server may be established through hardware, software, or a combination of both.

[0087] The virtual private network 60 may include an authentication module 62 and a private network generation module 64. The authentication module 62 and the private network generation module 64 may be integrated into the server.

[0088] The authentication module 62 is similar to the authentication module 22. It is used to receive an authorization connection request R1 from the authorization terminal 15, send the authorization connection request R1 to the remote terminal 16, and receive a response message R2 from the remote terminal 16. The authorization connection request R1 includes the identification information of the remote terminal 16 and the identification information of the local network 14.

[0089] In one embodiment, the authentication module 62 can receive an authorization connection request R1 from the authorization terminal 15 through the access management platform 66. The access management platform 66 may include a VPN user interface based on a public web browser or application settings. For example, the user of the authorization terminal 15 can access the access management platform through a browser or application and generate the authorization connection request R1 in the management platform 66 by entering commands related to the authorization connection request R1. The management platform then sends the generated authorization connection request R1 to the authentication module 64 for relevant authentication.

[0090] The aforementioned authorized connection request R1 may further include access time information, which includes at least one of the start time and end time that allow the remote terminal 16 and the network to be accessed (local network 14) to establish a virtual network connection.

[0091] The authentication module 62 is also used to send the received authorized connection request R1 to the remote terminal 16. Similar to the previous embodiment, the authentication module 62 can convey the received authorized connection request R1 to the remote terminal user who also accesses the access management platform through the access management platform 66.

[0092] In other embodiments, the authentication module 62 may also send the authorized connection request R1 directly to the remote terminal 16 (e.g., via email, SMS message, website information, or one or more of these).

[0093] The authentication module 62 is also used to receive a response message R2 from the remote terminal 16. In one embodiment, the authentication module 62 receives the response message R2 through the access management platform 66. In an example scenario, after receiving the aforementioned authorized connection request R1, the user of the remote terminal 16 can access the access management platform 66 to respond. The response message R2 can indicate agreement to remotely access the local network 14 according to the specific content of the authorized connection request R1.

[0094] The dedicated network generation module 64 receives an authorized connection request R1 sent from the authentication module 62 and generates a virtual private network 69 and security rule R3 based on the authorized connection request R1. The virtual private network 69 can be a dedicated network channel established between a public network and the local network 14. Furthermore, the virtual private network 69 applies the security rule R3 to establish a virtual network connection with the remote terminal 16 and the network to be accessed (e.g., the local network 14). For example, the dedicated network generation module 64 notifies the border device 142 of the network to be accessed 14 to update its network configuration (e.g., set access ports and routing information) according to the aforementioned security rule R3.

[0095] In one example, the private network generation module 64 receives multiple authorized connection requests sent by the authentication module 62 to generate an authorized connection request list. The private network generation module 64 can then establish multiple private network channels based on this list.

[0096] Similarly, the aforementioned "security rules" include rules that the border device 142 of the local network 14 must follow when accessing the virtual network, and may also include rules that must be followed when allowing the remote terminal 16 to access the virtual network. These security rules may include at least a portion of the authorized connection request R1, and may also include network configuration information. For example, security rule R3 may include the IP address of the remote terminal, the access port of the local network 14, and the routing information of the corresponding computer device 124 to be connected. Security rule R3 may further include time information allowing the remote terminal 16 to access the local network, such as the time period during which the remote terminal 16 is allowed to access the network to be accessed.

[0097] To further enhance network connection security, authentication module 62 is also used to receive access permission instruction R4 from authorization terminal 15. Access permission instruction R4 can be generated by authorization terminal 15 through access to the access management platform 66. Authentication module 62 can be configured to send the aforementioned access connection request R1 to dedicated network generation module 64 upon receiving access permission instruction R4 from authorization terminal 15.

[0098] In one example, the access management platform 66 adds the currently received access release instruction R4 as an instruction tag to the earlier received access connection request R1, and sends the access connection request R1 with the instruction tag to the dedicated network generation module 64.

[0099] Furthermore, the authentication module 62 is configured to receive the aforementioned access release instruction R4 only within a specific time (e.g., 5 minutes) prior to the access start time of the authorized connection request.

[0100] In one embodiment, after a private virtual network 69 is generated and the relevant modules update the network configuration based on security rule R3, the authentication module 62 generates access authentication information for accessing the local network 14, allowing the remote terminal 16 to access the local network 14 via the private virtual network 69 based on this access authentication information. This access authentication information may include detailed information for accessing the local network 14, such as routing information.

[0101] The authentication module 62 can further send the generated access authentication information to the remote terminal 16 via, for example, email, SMS, or website messages. In one example, the authentication module 62 sends the access authentication information to the access management platform 66, so that when a user on the remote terminal 16 accesses the access management platform 66, the user automatically obtains the detailed information of the remote access and remotely accesses the local network 14 to be accessed based on the detailed information.

[0102] In other embodiments, the authentication module 62 is also used to receive a connection interruption request R5 from the authorization terminal 15 through the access management platform 66. Based on the received connection interruption request, the authentication module 62 deletes the already generated authorized connection authentication and sends a connection interruption notification N1 to the private network generation module 64. Based on the interruption notification N1, the private network generation module 64 disconnects the network connection with the remote terminal 16 and the local network and resets / deletes the security rule R3.

[0103] After the connection is interrupted, the dedicated network generation module 64 can report a status update message that the connection has been interrupted to the authentication module 62. The authentication module 62 then sends the received status update message to the access management platform 66, so that the authorized end 15 and the remote end 16 can know the current remote connection status by accessing the access management platform 26.

[0104] Meanwhile, the authentication module 62 can also send a notification of remote connection interruption to the remote end 16 and the authorizing end 15 via one or more of email, SMS, and website messages.

[0105] In the above embodiments, the authentication module with the authorization end authentication mode and the VPN's dedicated network generation module are integrated and communicated, thereby improving the security of VPN authentication.

[0106] The modules / platforms in the embodiments of the present invention, such as authentication modules 22 / 62, resource scheduling module 24, dedicated network generation module 64, and access management platform 26 / 66, may individually or jointly include a computer processor and a storage medium. The storage medium records a predetermined data processing program to be executed by the computer processor. For example, the storage medium may store programs for implementing access authentication, remote interaction, etc., in the embodiments of the present invention; for instance, it may store programs for implementing the network access authentication method of the embodiments of the present invention. The storage medium may include, for example, a ROM, floppy disk, hard disk, optical disk, magneto-optical disk, CD-ROM, or a non-volatile memory card.

[0107] Although the invention has been described in detail with reference to specific embodiments, those skilled in the art will understand that many modifications and variations can be made to the invention. Therefore, it is to be appreciated that the claims are intended to cover all such modifications and variations that fall within the true conception and scope of the invention.

Claims

1. A network access authentication method, comprising: Receive an authorization connection request from the authorization end, the authorization connection request including the identification information of the remote end to be authorized and the identification information of the network to be accessed; Send the authorized connection request to the remote terminal; Receive response messages from the remote end; as well as, Based on the authorized connection request, a virtual network server is allocated and security rules are generated. The allocated virtual network server is used to apply the security rules to establish a virtual network connection with the remote terminal and the network to be accessed. The identification information of the network to be accessed includes at least one of the following: the identity information of the authorizing party, the attribute information of the network to be accessed, and the information of the devices in the network to be accessed.

2. The network access authentication method as described in claim 1, wherein: The authorized connection request also includes access time information, which includes at least one of the start time and end time that allow the remote terminal and the network to access to establish a virtual network connection.

3. The network access authentication method as described in claim 1, wherein: The device includes at least one of a medical imaging device, a computer device that interacts with the medical imaging device, and a boundary device.

4. The network access authentication method of claim 1, wherein, Sending the authorized connection request to the remote terminal includes: Parse the authorized connection request; and, Send a parsed authorized connection request to the remote terminal via one or more of the following methods: email, SMS message, or website message.

5. The network access authentication method as described in claim 1, further comprising: The boundary device of the network to be accessed is notified to update its network configuration according to the security rules. Receive a first confirmation message from the border device confirming the updated network configuration; Receive a second confirmation message from the virtual network server confirming that the security rule has been applied; and, Send access authentication information for accessing the network to be accessed to the remote terminal.

6. The network access authentication method as described in claim 5, further comprising: Receive a connection interruption request from the authorizing end; as well as, Based on the connection interruption request, a connection interruption notification is sent to the virtual network server so that the virtual network server disconnects the network connection with the remote end.

7. The network access authentication method as described in claim 6, wherein: The authorized connection request, connection interruption request, and response message from the remote end are received and sent through an access management platform based on a web browser or application.

8. A computer readable storage medium, wherein, The computer-readable storage medium stores one or more instructions that can be executed by a processor to implement the network access authentication method as described in any one of claims 1 to 7.

9. A network access authentication system, comprising: The authentication module is used to receive an authorization connection request from the authorization end, send the authorization connection request to the remote end, and receive a response message from the remote end. The authorization connection request includes the identification information of the remote end to be authorized and the identification information of the network to be accessed. as well as, The resource scheduling module receives the authorized connection request sent by the authentication module, allocates a virtual network server based on the authorized connection request, and generates security rules. The allocated virtual network server is used to apply the security rules to establish a virtual network connection with the remote terminal and the network to be accessed. The identification information of the network to be accessed includes at least one of the following: the identity information of the authorizing party, the attribute information of the network to be accessed, and the information of the devices in the network to be accessed.

10. The network access authentication system as described in claim 9, wherein, The authorized connection request also includes access time information, which includes at least one of the start time and end time that allow the remote terminal and the network to access to establish a virtual network connection.

11. The network access authentication system as described in claim 9, wherein: The device includes at least one of a medical imaging device, a computer device that interacts with the medical imaging device, and a boundary device.

12. The network access authentication system as described in claim 9, wherein, It also includes an access management platform, which is built based on a web browser or application, wherein: The authentication module is used to receive an authorization connection request from the authorization end through the access management platform, send the authorization connection request to the remote end, and receive a response message from the remote end.

13. The network access authentication system of claim 12, wherein, The authentication module includes: The message parsing unit is used to parse the authorization connection request from the authorization end and send the parsed authorization connection request to the remote end via one or more of the following methods: email, SMS message, website message.

14. The network access authentication system of claim 12, wherein, The resource scheduling module includes: The first task unit is configured to notify the border device of the network to be accessed to update its network configuration according to the security rules, and to receive a first confirmation message from the border device regarding the updated network configuration; and, The second task unit is configured to receive a second confirmation message from the virtual network server indicating that the security rule has been applied; and, The third task unit is used to send the first confirmation message and the second confirmation message to the authentication module. The authentication module is used to generate access authentication information for accessing the network to be accessed after receiving the first confirmation message and the second confirmation message.

15. The network access authentication system of claim 14, wherein, The authentication module is also used for: The access management platform receives a connection interruption request from the authorized end; and... Based on the connection interruption request, a connection interruption notification is sent to the resource scheduling module. The resource scheduling module then sends the connection interruption notification to the allocated virtual network server, so that the virtual network server disconnects its network connection with the remote end.

16. A remote interactive system for a medical imaging system, the medical imaging system comprising a medical imaging device and a computer device for controlling the medical imaging device, the computer device being connected to a local network to be accessed, the remote interactive system comprising: The network access authentication system according to any one of claims 9-15; as well as, The virtual network server allocated by the resource scheduling module is used to establish the virtual network based on the security rules and to handle the interaction tasks between the remote terminal and the computer devices in the network to be accessed.

17. A Virtual Private Network, comprising: The authentication module is used to receive an authorization connection request from the authorization end, send the authorization connection request to the remote end, and receive a response message from the remote end. The authorization connection request includes the identification information of the remote end and the identification information of the local network. as well as, A dedicated network generation module is used to receive the authorized connection request sent by the authentication module, generate security rules based on the authorized connection request, and apply the security rules to establish a virtual private network between the remote terminal and the local network. The identification information of the local network includes at least one of the following: the identity information of the authorizing party, the attribute information of the local network, and the information of the devices in the local network.

18. The virtual private network of claim 17, wherein the authorized connection request further includes access time information, the access time information including at least one of a start time and an end time that allows the remote end and the network to connect to the virtual network.

Citation Information

Patent Citations

  • Method and system for remote access to campus network resources

    CN101212374A

  • Method and device for establishing communication connection

    CN104052751A