Secure access service method and system

By introducing SASE portable devices into the SASE secure cloud network, a data tunnel is established between the terminal devices and the SASE access server, solving the problem of high access costs for terminal devices with different operating systems, and realizing unified access and full utilization of the functions of the secure cloud network.

CN115987586BActive Publication Date: 2025-12-16BEIJING KNOWNSEC INFORMATION TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211604781.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-13
Publication Date
2025-12-16
Estimated Expiration
2042-12-13

AI Technical Summary

Technical Problem

The existing SASE security cloud network suffers from the diversity of user terminal device operating systems, making it impossible to use a relatively unified technology for access. This results in high development and maintenance costs, and the terminal device operating system limits the full utilization of SASE functionality.

Method used

By introducing SASE portable devices, a data tunnel is established between the SASE portable devices and the SASE access server. Terminal devices only need to install a unified SASE application. By establishing a data tunnel between the SASE portable devices and the SASE access server, terminal devices with different operating systems can access the secure cloud network using a relatively unified technology.

Benefits of technology

It greatly reduces the development and maintenance costs of secure cloud networks, avoids restrictions on different operating systems, meets the SASE functional requirements of terminal devices, and realizes unified access to secure cloud networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115987586B_ABST
    Figure CN115987586B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a kind of security access service method and system, belong to network security field, terminal equipment receives the start instruction sent by SASE controller, and SASE connection service is started by SASE application program installed in itself, so that terminal equipment can send tunnel establishment request to SASE portable device according to target connection selected by user on SASE access server, and SASE portable device establishes data tunnel between SASE access server based on tunnel authentication information, so that any terminal equipment only needs to install unified SASE application program, can establish specific user's data tunnel between SASE portable device and SASE access server, and different operating systems are realized by terminal equipment using relatively unified technology to access security cloud network, which greatly reduces the development and maintenance cost of security cloud network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security, and more specifically, to a secure access service method and system. Background Technology

[0002] Secure Access Service Edge (SASE) integrates network and security features in the cloud to ensure users can access their work applications smoothly and securely anytime, anywhere. Its core functionalities include software-defined WAN, secure web gateway, firewall-as-a-service, cloud access security broker, and zero-trust network access. The SASE model aims to unify these functionalities into a single integrated cloud service.

[0003] Currently, the SASE secure cloud network primarily relies on deploying corresponding applications on users' PCs, tablets, or mobile phones, using VPN or proxy technologies provided by the operating system to redirect user traffic and connect them to the SASE secure cloud network. However, due to the diversity of user terminal device operating systems, it is impossible to implement SASE services using a relatively uniform technology, resulting in high development and maintenance costs. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a secure access service method and system that can improve the problem of high development and maintenance costs caused by the inability to use relatively uniform technologies for terminal devices with different operating systems.

[0005] To achieve the above objectives, the technical solutions adopted in the embodiments of the present invention are as follows:

[0006] In a first aspect, embodiments of the present invention provide a secure access service method applied to a secure access service system, the secure access service system including a terminal device, a SASE controller, a SASE portable device, and a SASE access server, the SASE access server being communicatively connected to multiple data service networks, and the terminal device having an SASE application installed, the method comprising:

[0007] When the terminal device receives the start command sent by the SASE controller, it starts the SASE connection service through the SASE application; wherein, the SASE connection service includes multiple connection items, and each connection item corresponds to a data service network;

[0008] The terminal device sends a tunnel establishment request to the portable device based on the target connection item selected by the user on the SASE connection service;

[0009] When the portable device receives the tunnel establishment request, a data tunnel about the target service network is established with the SASE access server based on the tunnel verification information; wherein the target service network is a data service network corresponding to the target connection item.

[0010] Further, the method further comprises:

[0011] The terminal device sends identity verification information to the SASE controller through the SASE application;

[0012] The SASE controller, upon receiving the identity verification information, performs identity verification based on the identity verification information, and sends a start instruction to the terminal device after identity verification is passed.

[0013] Further, the method further comprises:

[0014] The SASE controller sends tunnel verification information to the terminal device after identity verification is passed;

[0015] The terminal device receives the tunnel verification information and sends the tunnel verification information to the SASE portable device.

[0016] Further, the step of establishing a data tunnel about the target service network with the SASE access server based on the tunnel verification information comprises:

[0017] The SASE portable device sends a tunnel establishment request to the SASE access server, and the SASE access server returns a verification request to the SASE portable device upon receiving the tunnel establishment request;

[0018] The SASE portable device extracts target verification information about the target service network from the tunnel verification information upon receiving the verification request, and sends the target verification information to the SASE access server;

[0019] The SASE access server performs tunnel verification based on the target verification information, and establishes a data tunnel about the target service network with the SASE portable device after tunnel verification is passed.

[0020] Further, the method further comprises:

[0021] The terminal device sends an access request to the SASE portable device, and the SASE portable device determines the data tunnel corresponding to the target service network of the access request based on the traction rule, and sends the access request to the SASE access server through the data tunnel;

[0022] After receiving the access request, the SASE access server transmits the access request to a target service network of the access request.

[0023] Further, after the SASE access server performs tunnel verification based on the target authentication information and establishes a data tunnel about the target service network with the SASE portable device after the tunnel verification passes, the method further comprises:

[0024] After the tunnel verification passes, the SASE access server sends data encryption information about the target service network to the SASE portable device.

[0025] Further, the step of determining a data tunnel corresponding to the target service network of the access request and sending the access request to the SASE access server through the data tunnel comprises:

[0026] According to the data encryption information corresponding to the target service network of the access request, the access request is encrypted, and the encrypted access request is sent to the SASE access server.

[0027] In a second aspect, an embodiment of the present application provides a secure access service method, applied to a terminal device, the terminal device being in communication connection with a SASE controller and a SASE portable device respectively, the SASE portable device being in communication connection with a SASE access server, and the terminal device being installed with a SASE application program, the method comprising:

[0028] When receiving a start instruction sent by the SASE controller, starting a SASE connection service through the SASE application program; wherein the SASE connection service comprises a plurality of connection items, each connection item corresponding to a data service network in communication connection with the SASE access server;

[0029] According to a target connection item selected by a user on the SASE connection service, sending a tunnel establishment request to the portable device; wherein the tunnel establishment request is used to prompt the portable device to establish a data tunnel about a target service network with the SASE access server based on tunnel authentication information;

[0030] The target service network is a data service network corresponding to the target connection item.

[0031] In a third aspect, an embodiment of the present application provides a secure access service method, applied to a SASE portable device, the SASE portable device being in communication connection with a terminal device and a SASE access server respectively, the method comprising:

[0032] receive a tunnel establishment request sent by the terminal device; wherein the tunnel establishment request is sent by the terminal device when a user selects a target connection item on the SASE connection service; the SASE connection service is started by the SASE application when the terminal device receives a start instruction sent by a SASE controller;

[0033] establish a data tunnel about a target service network with the SASE access server based on tunnel verification information; wherein the target service network is a data service network corresponding to the target connection item, and the data service network is in communication connection with the SASE access server.

[0034] In a fourth aspect, an embodiment of the present application provides a secure access service system, comprising a terminal device, a SASE controller, a SASE portable device and a SASE access server, the terminal device is in communication connection with the SASE controller and the SASE portable device respectively, the SASE portable device is in communication connection with the SASE access server, the SASE access server is in communication connection with a plurality of data service networks, and the terminal device is installed with a SASE application;

[0035] When the terminal device receives a start instruction sent by the SASE controller, the terminal device starts a SASE connection service through the SASE application, and sends a tunnel establishment request to the portable device according to a target connection item selected by a user on the SASE connection service; wherein the SASE connection service comprises a plurality of connection items, and each connection item corresponds to a data service network;

[0036] When the portable device receives the tunnel establishment request, the portable device establishes a data tunnel about a target service network with the SASE access server based on tunnel verification information; wherein the target service network is a data service network corresponding to the target connection item.

[0037] In a fifth aspect, an embodiment of the present application provides a secure access service device applied to a terminal device, the terminal device is in communication connection with a SASE controller and a SASE portable device respectively, the SASE portable device is in communication connection with a SASE access server, and the terminal device is installed with a SASE application, the secure access service device comprises a start module and a request connection module:

[0038] When the start module receives a start instruction sent by the SASE controller, the start module starts a SASE connection service through the SASE application; wherein the SASE connection service comprises a plurality of connection items, and each connection item corresponds to a data service network in communication connection with the SASE access server;

[0039] The request connection module is configured to send a tunnel establishment request to the portable device according to a target connection item selected by a user on the SASE connection service; wherein the tunnel establishment request is configured to prompt the portable device to establish a data tunnel about a target service network with the SASE access server based on tunnel verification information.

[0040] The target service network is a data service network corresponding to the target connection item.

[0041] In a sixth aspect, an embodiment of the present application provides a secure access service device, applied to a SASE portable device, the SASE portable device being in communication connection with a terminal device and a SASE access server respectively, and the secure access service device comprising a receiving module and a tunnel establishment module.

[0042] The receiving module is configured to receive a tunnel establishment request sent by the terminal device; wherein the tunnel establishment request is sent by the terminal device when a user selects a target connection item on the SASE connection service; and the SASE connection service is started by the SASE application when the terminal device receives a start instruction sent by a SASE controller.

[0043] The tunnel establishment module is configured to establish a data tunnel about a target service network with the SASE access server based on tunnel verification information; wherein the target service network is a data service network corresponding to the target connection item, and the data service network is in communication connection with the SASE access server.

[0044] In a seventh aspect, an embodiment of the present application provides an electronic device, comprising a processor and a memory, the memory storing a computer program capable of being executed by the processor, and the processor being capable of executing the computer program to implement the secure access service method according to the second aspect or the third aspect.

[0045] In an eighth aspect, an embodiment of the present application provides a computer readable storage medium, having a computer program stored thereon, the computer program being executed by a processor to implement the secure access service method according to the second aspect or the third aspect.

[0046] The security access service method and system provided by the embodiment of the present application, after the terminal device receives the starting instruction sent by the SASE controller, the SASE connection service is started through the SASE application program installed by the terminal device, so that the terminal device can send a tunnel establishment request to the SASE portable device according to the target connection selected by the user on the SASE access server, and the SASE portable device establishes a data tunnel of the data service network corresponding to the target connection item based on the tunnel verification information and the SASE access server after receiving the tunnel establishment request sent by the terminal device, so that the terminal device can access the target service network through the data tunnel between the SASE portable device and the SASE access server, that is, any terminal device only needs to install a unified SASE application program, and then any data tunnel can be established between the SASE portable device and the SASE access server, so that the terminal devices of different operating systems can access the security cloud network by using a relatively unified technology, and the development and maintenance cost of the security cloud network is greatly reduced.

[0047] In order to make the above objectives, characteristics and advantages of the present application more apparent, the following preferred embodiments are specifically described below, and the accompanying drawings are referred to, and the detailed description is as follows. BRIEF DESCRIPTION OF DRAWINGS

[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments, and it should be understood that the following drawings only show some embodiments of the present application, and should not be regarded as a limitation to the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.

[0049] Figure 1 The block schematic diagram of the security access service system provided by the embodiment of the present application is shown.

[0050] Figure 2 The flow schematic diagram of the security access service method provided by the embodiment of the present application is shown.

[0051] Figure 3 The flow schematic diagram of the security access service method provided by the embodiment of the present application is shown.

[0052] Figure 4 The flow schematic diagram of the security access service method provided by the embodiment of the present application is shown.

[0053] Figure 5 The flow schematic diagram of the part of the sub-steps of step S16 in the method for establishing a security access service is shown. Figures 1-4

[0054] Figure 6 ​Fig. 4 shows a flowchart of a method for providing secure access service according to an embodiment of the present application.

[0055] Figure 7 Fig. 5 shows a flowchart of a method for providing secure access service according to an embodiment of the present application.

[0056] Figure 8 Fig. 6 shows a flowchart of a method for providing secure access service according to an embodiment of the present application.

[0057] Figure 9 Fig. 7 shows a block diagram of an electronic device according to an embodiment of the present application.

[0058] Fig. 8 shows a block diagram of a secure access service system according to an embodiment of the present application. DETAILED DESCRIPTION

[0059] The technical solutions in the embodiments of the present application will be clearly and completely described with reference to the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all of the embodiments of the present application. The components of the embodiments of the present application described and shown in the accompanying drawings can be arranged and designed in various different configurations.

[0060] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present application.

[0061] It should be noted that the relational terms such as first and second and the like are used only to distinguish one entity or operation from another, and do not necessarily require or imply that these entities or operations exist in any such actual relationship or order. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or apparatus including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such a process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus including the element.

[0062] Secure Access Service Edge (SASE) can integrate software-defined wide area network (SD-WAN) and security into cloud services, thus ensuring to simplify WAN deployment, improve efficiency and security, and provide appropriate bandwidth for each application. In simple terms, SASE provides users with an access service, and users can access a secure cloud network at any time and anywhere, in which users can access the Internet and enterprise intranet services in a protected manner, and can enjoy network acceleration brought by SD-WAN technology.

[0063] For each user, SASE can adjust the implemented security policy according to the following four factors: the identity of the connection entity; real-time context (the health and behavior of the device, and the sensitivity of the accessed resource); enterprise security / compliance policy; and continuous assessment of wind direction / trusted services throughout the session.

[0064] The current SASE security cloud network mainly uses the VPN or Proxy technology provided by the operating system to lead the user traffic by deploying the corresponding SASE application on the user's PC, tablet or mobile phone, so that the user traffic is accessed to the SASE security cloud network. Among them, the SASE application mainly includes the following functions: completing the identity authentication of the user; communicating with the control machine in the SASE security cloud network to obtain the control instruction of the user terminal; calling the network function of the terminal device operating system to complete the access to the SASE security cloud network, and establishing a data channel for accessing the Internet and user intranet services.

[0065] However, due to the diversity of user terminal device operating systems, it is difficult to use relatively unified technology to achieve access to the security cloud network. For example, SASE can control the bandwidth of user access to the Internet or enterprise intranet services, and such functions need to call the network function of the underlying operating system of the user terminal. The mechanisms provided by different operating systems are very different, and in the android and ios systems, there is even no support mechanism related to the network level, resulting in high development and maintenance cost of SASE.

[0066] In addition, with the increasing attention of each operating system to its own security, the network operation, VPN and Proxy functions required by SASE access are greatly limited, and the functions of SASE cannot be fully exerted. For example, in the scenario where the user needs to access the Internet and enterprise intranet services at the same time, the user terminal needs to establish two data channels for Internet access and enterprise intranet service access, but in the android / ios / macos system, only one VPN tunnel or WebProxy can be established, which cannot meet the functions of this scenario.

[0067] Based on the above considerations, the embodiment of the present application provides a secure access service method, which can improve the high development and maintenance cost of the existing SASE and the problem of the limitation of the full play of the function of the operating system of the terminal device to the SASE. Next, the secure access service method is introduced.

[0068] The secure access service method provided by the embodiment of the present application can be applied to a secure access server system in Figure 1 , the secure access server system 100 includes a terminal device 110, a SASE controller 120, a SASE portable device 130 and a SASE access server 140, the terminal device 110 can be connected with the SASE controller 120 through a network, the terminal device 110 can also be connected with the SASE portable device 130 through a wireless connection mode such as Bluetooth and wifi, the SASE portable terminal can be connected with the SASE access server 140 through a network, the SASE access server 140 is connected with a Fuliemo data service network. In addition, the terminal device 110 is installed with a SASE application program.

[0069] The terminal device 110 is used for starting the SASE connection service through the SASE application program when receiving the starting instruction sent by the SASE controller 120, and sending a tunnel establishment request to the portable device according to the target connection item selected by the user on the SASE connection service. The SASE connection service includes a plurality of connection items, and each connection item corresponds to a data service network.

[0070] The portable device is used for establishing a data tunnel about the target service network with the SASE access server 140 based on the tunnel verification information when receiving the tunnel establishment request. The target service network is the data service network corresponding to the target connection item.

[0071] The terminal device 110 includes but is not limited to a personal computer, a tablet computer, a notebook computer, a mobile phone and a wearable terminal device 110, etc. The data service network includes but is not limited to the Internet and an enterprise internal service network.

[0072] In other embodiments, the terminal device 110 can be connected with the SASE portable device 130 through a wired connection mode such as USB.

[0073] In a possible embodiment, the embodiment of the present application provides a secure access server method, which can include the following steps. In the embodiment, the method is applied to the secure access service system 100 in Figure 2 . Figure 1

[0074] ​S12, when the terminal device receives the starting instruction sent by the SASE controller, starting the SASE connection service through the SASE application.

[0075] It should be noted that the terminal device 110 runs the SASE application in response to the starting instruction, and the SASE connection service interface is displayed on the terminal device 110. The SASE connection service includes a plurality of connection items, and each connection item corresponds to a data service network.

[0076] S14, the terminal device sends a tunnel establishment request to the portable device according to the target connection item selected by the user on the SASE connection service.

[0077] S16, when the portable device receives the tunnel establishment request, establishes a data tunnel about the target service network with the SASE access server based on the tunnel verification information.

[0078] It should be understood that the target service network is the data service network corresponding to the target connection item.

[0079] When the user needs to perform secure cloud access, the user starts the connection mode such as wifi or Bluetooth to connect the terminal device 110 and the SASE portable device 130. After the terminal device 110 receives the starting instruction sent by the SASE controller 120, the SASE application of the terminal device 110 is run to display the interface of the SASE connection service on the screen of the terminal device 110. The interface of the SASE connection service displays a plurality of connection items, for example, the display mode can be the same as the wifi connection page. After the user selects a target connection item (for example, selects a certain connection item) on the page of the SASE connection service, the terminal device 110 triggers a tunnel establishment request about the data service network corresponding to the connection item, and sends the tunnel establishment request to the SASE portable device 130.

[0080] After the SASE portable device 130 receives the tunnel establishment request, a data tunnel about the data service network corresponding to the connection item is established with the SASE access server 140 based on the tunnel verification information, so that the terminal device 110 can perform secure access / secure communication with the target service network connected by the SASE access server 140 through the data tunnel.

[0081] Compared with a traditional implementation of a secure access service edge, in the secure access service method provided by the embodiment of the present application, any terminal device only needs to be installed with a unified SASE application program, and then an arbitrary data tunnel can be established between the SASE portable device and the SASE access server, so that terminal devices of different operating systems can all access the secure cloud network by using a relatively unified technology, and the development and maintenance costs of the secure cloud network are greatly reduced. Meanwhile, the data tunnel provided by the SASE portable device enables the SASE access to be free from the restriction of the operating system such as android / ios / macos, and the SASE requirement function of the terminal device can be met as much as possible.

[0082] In order to ensure the security of the process of the SASE access of the terminal device, in a possible implementation manner, the secure access service method provided by the embodiment of the present application can further include the following steps. Figure 3

[0083] S10, the terminal device sends identity authentication information to the SASE controller through the SASE application program.

[0084] S11, the SASE controller performs identity authentication based on the identity authentication information when receiving the identity authentication information, and sends a start instruction to the terminal device after the identity authentication is passed.

[0085] When the SASE application program is running, the terminal device 110 can automatically generate the identity authentication information, or the user can input the identity authentication information on the login interface of the SASE application program. After the terminal device 110 obtains the identity authentication information, the terminal device 110 sends the identity authentication information to the SASE controller 120, and sends the identity authentication information to the SASE controller 120.

[0086] In a possible implementation manner, the user record table on the SASE controller 120 can record the identity information of each user. After the SASE controller 120 receives the identity authentication information sent by any terminal device 110, the SASE controller 120 matches the identity authentication information with the identity information in the user record table. If the matching is passed, the SASE controller 120 sends a start instruction to the terminal device 110.

[0087] The SASE controller 120 can also use other verification methods to verify the identity authentication information sent by the terminal device 110, for example, feature verification or other verification methods, which are not limited in the embodiment.

[0088] Further, in order to avoid the exposure of the tunnel authentication information to a certain extent and affect the establishment and security of the data tunnel, with reference to Figure 4 ​The secure access service method provided by the embodiment of the present application can further include steps S13 and S15. Step S11 and step S13 can be performed simultaneously, and step S15 is performed before step S16.

[0089] S13, the SASE controller sends tunnel verification information to the terminal device after the identity verification is passed.

[0090] S15, the terminal device receives the tunnel verification information and sends the tunnel verification information to the SASE portable device.

[0091] The SASE controller 120 verifies the identity verification information sent by the terminal device 110, and after the identity verification is passed, the SASE controller 120 can generate tunnel verification information for the terminal device 110 based on the verification information, and send the tunnel verification information to the terminal device 110.

[0092] It should be noted that the tunnel verification information generated each time can be different, and the SASE controller 120 synchronizes the tunnel verification information to the SASE access server 140 each time the tunnel verification information is generated, so that the SASE access server 140 establishes a data tunnel with the SASE portable device 130 based on the tunnel verification information. In addition, the verification information generation rule can be any one of the verification information generation rules of the communication channel, which is not specifically limited in the present embodiment.

[0093] In another possible embodiment, the SASE controller can pre-store tunnel verification information corresponding to each user, and after the identity verification is passed, the SASE controller can call the tunnel verification information of the user corresponding to the identity verification information and send the tunnel verification information to the terminal device.

[0094] After the terminal device 110 receives the tunnel verification information sent by the SASE controller 120, the tunnel verification information is forwarded to the SASE portable device 130 in communication connection with the terminal device 110, so that step S16 can be implemented, and a data tunnel between the SASE portable device 130 and the SASE access server 140 is established.

[0095] The way of establishing a data tunnel between the SASE portable device 130 and the SASE access server 140 can be flexibly set, for example, a data tunnel can be established according to a preset rule, or a data tunnel can be established according to any communication channel establishment rule, which is not uniquely limited in the present embodiment. It should be understood that the communication protocol used for establishing the data tunnel is different, and the specific implementation of S16 is also different.

[0096] In a possible embodiment, referring to Figure 5The step S16 can be further implemented as the following steps.

[0097] S161, the SASE portable device sends a tunnel establishment request to the SASE access server, and the SASE access server returns a verification request to the SASE portable device upon receiving the tunnel establishment request.

[0098] S162, the SASE portable device extracts target verification information about the target service network from the tunnel verification information upon receiving the verification request, and sends the target verification information to the SASE access server.

[0099] S163, the SASE access server performs tunnel verification based on the target verification information, and establishes a data tunnel about the target service network with the SASE portable device upon passing the tunnel verification.

[0100] The SASE access server 140 stores matching data matching or identical to the tunnel verification information on the SASE portable device 130, and performs verification on the target verification information returned by the SASE portable device 130 based on the matching data upon sending the verification request, and establishes a data tunnel upon passing the verification.

[0101] In order to improve the security of data transmission using the data tunnel, in one possible implementation, the SASE portable device 130 performs verification on the data encryption information returned by the SASE access server 140 based on the matching data stored in the SASE portable device 130. Figure 5 The security access service method provided by the embodiment of the present application further includes a step S164, which is executed after the step S163.

[0102] S164, the SASE access server sends data encryption information about the target service network to the SASE portable device upon passing the tunnel verification.

[0103] The SASE portable device 130 stores the data encryption information sent by the SASE access server 140 and the data tunnel corresponding to the data encryption information in a mapping relationship, so that the data encryption information can be used for encryption or decryption when the data tunnel is used for subsequent data transmission.

[0104] It should be noted that multiple data tunnels can be established between the same SASE portable device 130 and the SASE access server 140, and each data tunnel corresponds to a data service network in communication connection with the SASE access server 140. The SASE portable device 130 distributes the network data sent by the terminal device 110 to the data tunnel corresponding to the destination data service network of the network data based on the preset traction rule, so as to be transmitted to the SASE access server 140 through the data tunnel, and then be transferred to the destination data service network by the SASE access server 140.

[0105] It should be understood that the communication protocol used when establishing the data tunnel is different, the traction rule can also be different, in this embodiment, the traction rule is not limited.

[0106] In a possible implementation, with reference to Figure 6 , the process of network data transmission can include the following steps.

[0107] S17, the terminal device sends an access request to the SASE portable device.

[0108] S18, the SASE portable device determines the data tunnel corresponding to the target service network of the access request based on the traction rule, and sends the access request to the SASE access server through the data tunnel.

[0109] S19, after receiving the access request, the SASE access server transmits the access request to the target service network of the access request.

[0110] For step S18, the SASE portable device 130 can encrypt the access request according to the data encryption information corresponding to the target service network of the access request, and send the encrypted access request to the SASE access server 140. After receiving the encrypted access request, the SASE access server 140 forwards the access request to the data service network corresponding to the data tunnel. The data service network sends the response data corresponding to the access request to the SASE access server 140 in response to the access request, and the SASE access server 140 sends the response data to the SASE portable device 130 through the corresponding data tunnel.

[0111] When the SASE portable device 130 receives the response data returned by the SASE access server 140 from any data tunnel, the data encryption information corresponding to the data tunnel is called to decrypt the response data, and the decrypted response data is transmitted to the terminal device 110, thereby completing a secure access of the terminal device 110 to the data service network.

[0112] In addition, when the SASE access server 140 receives the network data sent by the terminal device 110 from any data tunnel, the SASE access server 140 can also perform SDWAN acceleration on the network data to realize the SASE general function.

[0113] In the application process, the SASE portable device can also realize fine traffic control according to the actual business needs of the user, such as QoS, traffic blocking, etc. In this embodiment, it is not limited. These functions are not limited by the operating system of the terminal device, and are uniformly realized by the SASE portable device, which can further reduce the development and maintenance cost.

[0114] The secure access service method provided by the embodiment of the application introduces a SASE portable device (which can be understood as a portable device similar to a personal hotspot), transfers part of the functions (complicated network operations strongly coupled with the operating system) of the SASE application in the original secure cloud network to the SASE portable device, so that the SASE application installed on the terminal device only needs to complete part of the original functions (such as identity information verification), and the terminal device and the SASE portable device communicate through short-distance communication technologies such as Wi-Fi, Bluetooth or USB, so that the SASE portable device performs functions such as data tunnel establishment, control instruction transmission and network data transmission. Thus, the SASE portable device completes the functions of VPN, QoS, traffic filtering and 4 / 5G network access, bypasses the complex technical solutions and strict security restrictions of different operating systems, enables the SASE functions to be fully utilized, and greatly reduces the development and maintenance costs.

[0115] Based on the inventive concept of the secure access service method, in a possible implementation, the embodiment of the application further provides a secure access service method, which can be applied to the terminal device 110 in Figure 1 , and can include the following steps with reference to Figure 7 .

[0116] S21, when the start instruction sent by the SASE controller is received, starting the SASE connection service through the SASE application.

[0117] The SASE connection service includes a plurality of connection items, and each connection item corresponds to a data service network in communication connection with the SASE access server.

[0118] S22, according to the target connection item selected by the user on the SASE connection service, sending a tunnel establishment request to the portable device.

[0119] The tunnel establishment request is used to prompt the portable device to establish a data tunnel about the target service network with the SASE access server 140 based on the tunnel verification information, so as to realize the secure access service method provided in the above embodiment. The target service network is the data service network corresponding to the target connection item.

[0120] Based on the inventive concept of the secure access service method, in a possible implementation, the embodiment of the application further provides a secure access service method, which can be applied to the SASE portable device 130 in Figure 1 , and can include the following steps with reference to Figure 8 .

[0121] S31, receiving the tunnel establishment request sent by the terminal device.

[0122] For step S31, the tunnel establishment request is issued when the terminal device 110 selects a target connection item on the SASE connection service. The SASE connection service is started by the SASE application when the terminal device 110 receives the start instruction sent by the SASE controller 120.

[0123] S32, based on the tunnel verification information, a data tunnel about the target service network is established with the SASE access server.

[0124] For step S32, the target service network is the data service network corresponding to the target connection item, and the data service network is in communication connection with the SASE access server 140.

[0125] Through the above steps S21-S22 and S31-S32, the terminal devices of different operating systems all use a relatively unified secure cloud network, which greatly reduces the development and maintenance cost of the secure cloud network. At the same time, the data tunnel of SASE provided by the SASE portable device makes the SASE access no longer limited by the operating systems such as android / ios / macos, and can meet the SASE demand function of the terminal device as much as possible.

[0126] For the specific limitations of the secure access service method applied to the terminal device 110 and the SASE portable device 130, refer to the above limitations of the secure access service method applied to the secure access service system 100, which will not be repeated here.

[0127] In one possible implementation, the embodiment of the present application also provides a secure access service device, which can be applied to the terminal device 110 in Figure 1 The secure access service device includes a start module and a request connection module.

[0128] The start module is configured to start the SASE connection service through the SASE application when receiving the start instruction sent by the SASE controller. The SASE connection service includes a plurality of connection items, and each connection item corresponds to a data service network in communication connection with the SASE access server.

[0129] The request connection module is configured to send a tunnel establishment request to the portable device according to the target connection item selected by the user on the SASE connection service. The tunnel establishment request is used to prompt the portable device to establish a data tunnel about the target service network with the SASE access server based on tunnel verification information.

[0130] The target service network is the data service network corresponding to the target connection item.

[0131] In a possible implementation, the embodiment of the present application provides a secure access service device, which can be applied to Figure 1 the SASE portable device 130 in the system, and the secure access service device comprises a receiving module and a tunnel establishing module.

[0132] The receiving module is configured to receive a tunnel establishing request sent by the terminal device.

[0133] The tunnel establishing request is sent by the terminal device 110 when a user selects a target connection item on a SASE connection service. The SASE connection service is started by the SASE application when the terminal device 110 receives a starting instruction sent by the SASE controller 120.

[0134] The tunnel establishing module is configured to establish a data tunnel about a target service network with the SASE access server based on tunnel verification information. The target service network is a data service network corresponding to the target connection item, and the data service network is in communication connection with the SASE access server.

[0135] In the secure access service device, the terminal devices with different operating systems all use a relatively unified secure cloud network, which greatly reduces the development and maintenance costs of the secure cloud network. At the same time, the data tunnel of the SASE provided by the SASE portable device makes the SASE access no longer subject to the restrictions of the operating systems such as android / ios / macos, and can meet the SASE demand functions of the terminal devices as much as possible.

[0136] For specific limitations of the secure access service device applied to the terminal device and the SASE portable device, refer to the limitations of the secure access service method of the secure access service system 100 described above, which will not be repeated here. Each module in the secure access service device can be realized by software, hardware, and a combination thereof in whole or in part. Each module described above can be embedded in or independent of the processor in the electronic device in hardware form, or can be stored in the memory of the electronic device in software form, so as to be called and executed by the processor to perform the operations corresponding to each module.

[0137] In an embodiment, an electronic device 150 is provided, which can be a client, and the internal structure diagram thereof can be as shown in Figure 9As shown in FIG. 15, the electronic device 150 includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the electronic device 150 is used to provide computing and control capabilities. The memory of the electronic device 150 includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The communication interface of the electronic device 150 is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be achieved through WIFI, operator network, near field communication (NFC) or other technologies. The computer program is executed by the processor to implement the secure access service method provided in the above embodiments.

[0138] Figure 9 The structure shown in FIG. 15 is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the electronic device 150 to which the scheme of the present application is applied. Specifically, the electronic device 150 can include more or fewer components than those shown in FIG. 15, or combine certain components, or have a different arrangement of components. Figure 9

[0139] In an embodiment, the secure access service apparatus provided by the present application can be implemented in the form of a computer program, which can run on an electronic device 150 as shown in FIG. 15. The memory of the electronic device 150 can store various program modules constituting the secure access service apparatus, such as the startup module, the request connection module, the receiving module and the tunnel establishment module mentioned above. The computer program constituted by the various program modules causes the processor to perform the steps in the secure access service method described in the specification. Figure 9

[0140] For example, Figure 9 The electronic device 150 as shown in FIG. 15 can execute step S21 through the startup module in the secure access service apparatus. The electronic device 150 can execute step S22 through the request connection module. The electronic device 150 can execute step S31 through the receiving module. The electronic device 150 can execute step S32 through the tunnel establishment module.

[0141] In an embodiment, an electronic device 150 is provided, including a memory and a processor, the memory storing a computer program, and the processor implementing the following steps when executing the computer program: starting a SASE connection service through a SASE application upon receiving a startup instruction sent by a SASE controller; and sending a tunnel establishment request to a portable device according to a target connection item selected by a user on the SASE connection service. Or implementing the following steps: receiving a tunnel establishment request sent by a terminal device; and establishing a data tunnel about a target service network with a SASE access server based on tunnel verification information.​​

[0142] In one embodiment, a storage medium is provided, and the storage medium stores a computer program, and the computer program is executed by a processor to implement the following steps: starting the SASE connection service through the SASE application when receiving the starting instruction sent by the SASE controller; and sending a tunnel establishment request to the portable device according to the target connection item selected by the user on the SASE connection service. Or the following steps are implemented: receiving a tunnel establishment request sent by a terminal device; and establishing a data tunnel about a target service network with a SASE access server based on tunnel verification information.

[0143] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can also be implemented by other means. The apparatus embodiments described above are only schematic, for example, the flowcharts and block diagrams in the drawings show the possible implementation architectures, functions and operations of the apparatus, method and computer program product according to the embodiments of the present application. In this regard, each block in the flowcharts or block diagrams can represent a module, a program segment or a part of code, which contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in a different order than that noted in the drawings. For example, two consecutive blocks can actually be executed substantially in parallel, or they can be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and the combination of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0144] In addition, each functional module in the various embodiments of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0145] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts of the technical solutions that essentially contribute to the prior art or the parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0146] The above only describes the preferred embodiments of the present application and is not intended to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A method of secure access service, characterized by, The method is applied to a secure access service system, the secure access service system comprises a terminal device, a SASE controller, a SASE portable device and a SASE access server, the SASE access server is in communication connection with a plurality of data service networks, the SASE application program is installed on the terminal device, and the method comprises the following steps: When the terminal device receives the starting instruction sent by the SASE controller, the SASE connection service is started through the SASE application program; wherein the SASE connection service comprises a plurality of connection items, and each connection item corresponds to a data service network; The terminal device sends a tunnel establishment request to the portable device according to the target connection item selected by the user on the SASE connection service; When the portable device receives the tunnel establishment request, a data tunnel about the target service network is established with the SASE access server based on the tunnel verification information, comprising: the SASE portable device sends a tunnel establishment request to the SASE access server, the SASE access server returns a verification request to the SASE portable device when receiving the tunnel establishment request; the SASE portable device extracts target verification information about the target service network from the tunnel verification information when receiving the verification request, and sends the target verification information to the SASE access server; the SASE access server performs tunnel verification based on the target verification information, and establishes a data tunnel about the target service network with the SASE portable device after the tunnel verification is passed; wherein the target service network is the data service network corresponding to the target connection item.

2. The secure access service method of claim 1, wherein, The method further comprises: The terminal device sends identity verification information to the SASE controller through the SASE application program; The SASE controller performs identity verification based on the identity verification information when receiving the identity verification information, and sends a starting instruction to the terminal device after the identity verification is passed.

3. The method of claim 2, wherein, The method further comprises: The SASE controller sends tunnel verification information to the terminal device after the identity verification is passed; The terminal device receives the tunnel verification information and sends the tunnel verification information to the SASE portable device.

4. The secure access service method of any of claims 1 to 3, wherein, The method further comprises: The terminal device sends an access request to the SASE portable device, the SASE portable device determines the data tunnel corresponding to the target service network of the access request based on the traction rule, and sends the access request to the SASE access server through the data tunnel; The SASE access server transmits the access request to the target service network of the access request after receiving the access request.

5. The method of claim 1, wherein, After the step of the SASE access server performing tunnel verification based on the target verification information, and establishing a data tunnel about the target service network with the SASE portable device after the tunnel verification is passed, the method further comprises: After the tunnel verification passes, the SASE access server sends data encryption information about the target service network to the SASE portable device.

6. The method of claim 4, wherein the service is a security access service. The step of determining the data tunnel corresponding to the target service network of the access request and sending the access request to the SASE access server through the data tunnel comprises: According to the data encryption information corresponding to the target service network of the access request, the access request is encrypted, and the encrypted access request is sent to the SASE access server.

7. A method of secure access service, characterized by, The method is applied to a terminal device, the terminal device is in communication connection with a SASE controller and a SASE portable device respectively, the SASE portable device is in communication connection with a SASE access server, a SASE application program is installed on the terminal device, and the method comprises: When receiving the starting instruction sent by the SASE controller, starting the SASE connection service through the SASE application program; wherein the SASE connection service comprises a plurality of connection items, each connection item corresponds to a data service network in communication connection with the SASE access server; According to the target connection item selected by the user on the SASE connection service, sending a tunnel establishment request to the portable device; wherein the tunnel establishment request is used to prompt the portable device to establish a data tunnel about the target service network with the SASE access server based on tunnel verification information, which comprises: the SASE portable device sends a tunnel establishment request to the SASE access server, and the SASE access server returns a verification request to the SASE portable device when receiving the tunnel establishment request; the SASE portable device extracts target verification information about the target service network from the tunnel verification information when receiving the verification request, and sends the target verification information to the SASE access server; the SASE access server performs tunnel verification based on the target verification information, and establishes a data tunnel about the target service network with the SASE portable device after the tunnel verification passes; The target service network is the data service network corresponding to the target connection item.

8. A method of secure access service, characterized by, The method is applied to a SASE portable device, the SASE portable device is in communication connection with a terminal device and a SASE access server respectively, and the method comprises: Receiving the tunnel establishment request sent by the terminal device; wherein the tunnel establishment request is sent by the terminal device when the user selects the target connection item on the SASE connection service; the SASE connection service is started through the SASE application program when the terminal device receives the starting instruction sent by the SASE controller; The SASE portable device sends a tunnel establishment request to the SASE access server, the SASE access server returns a verification request to the SASE portable device upon receiving the tunnel establishment request, the SASE portable device extracts target verification information about the target service network from the tunnel verification information upon receiving the verification request, and sends the target verification information to the SASE access server, the SASE access server performs tunnel verification based on the target verification information, and establishes a data tunnel about the target service network with the SASE portable device upon passing the tunnel verification.

9. A secure access service system, characterized by The terminal device, the SASE controller, the SASE portable device and the SASE access server are included, the terminal device is in communication connection with the SASE controller and the SASE portable device respectively, the SASE portable device is in communication connection with the SASE access server, the SASE access server is in communication connection with a plurality of data service networks, and the SASE application program is installed on the terminal device; When the terminal device receives the start instruction sent by the SASE controller, the SASE connection service is started through the SASE application program, and a tunnel establishment request is sent to the portable device according to the target connection item selected by the user on the SASE connection service; wherein the SASE connection service includes a plurality of connection items, and each connection item corresponds to a data service network; The portable device is used for establishing a data tunnel about a target service network with the SASE access server based on tunnel verification information upon receiving a tunnel establishment request; wherein the target service network is a data service network corresponding to the target connection item, including: the SASE portable device sends a tunnel establishment request to the SASE access server, the SASE access server returns a verification request to the SASE portable device upon receiving the tunnel establishment request, the SASE portable device extracts target verification information about the target service network from the tunnel verification information upon receiving the verification request, and sends the target verification information to the SASE access server, the SASE access server performs tunnel verification based on the target verification information, and establishes a data tunnel about the target service network with the SASE portable device upon passing the tunnel verification.

Citation Information

Patent Citations

  • Access control method, device and equipment and readable storage medium

    CN113824791A