Device access method and device, computer-readable storage medium, electronic device

By obtaining and verifying the temporary addresses generated by external devices in the home network, and creating access control lists and firewall address translation rules, the problems of low security of device access and inaccessibility of external devices are solved, achieving higher security and convenience.

CN115987591BActive Publication Date: 2025-06-10CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211616636.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-15
Publication Date
2025-06-10
Estimated Expiration
2042-12-15

AI Technical Summary

Technical Problem

The prior art has low security in the home network or external devices cannot access internal devices of the home gateway, resulting in limited security risks and business development.

Method used

By responding to external devices' access to intranet devices, obtain the temporary address generated by external devices and verify it. When the verification is passed, create access control lists and firewall address conversion rules to realize the access of external devices to intranet devices.

Benefits of technology

Improves the security of access to intranet devices, allowing external devices to access intranet devices without the need for a five-tuple security policy, and improves the convenience of device access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115987591B_ABST
    Figure CN115987591B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a device access method, a device, a computer-readable storage medium, and an electronic device, and pertains to the field of information security technologies. The method includes: in response to an external device accessing an internal network device, obtaining a temporary address generated by the external device and associated with the internal network device, and verifying the temporary address; when the verification of the temporary address passes, creating an access control list and a firewall address translation rule according to the temporary address; and implementing the access of the external device to the internal network device through the access control list and the firewall address translation rule. The present disclosure improves the security and convenience of device access.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] IPv6 (Internet Protocol Version 6) is the next generation IP (Internet Protocol) protocol designed by the Internet Engineering Task Force to replace IPv4. The use of IPv6 can not only solve the problem of the number of network address resources, but also solve the obstacles for various access devices to connect to the Internet.

[0003] After IPv6 is applied to the current home network, there are generally two access strategies. One is to completely open up external access to IPv6 addresses. When external access to IPv6 addresses is completely opened up, the public network characteristics of IPv6 can be fully utilized to provide innovative services, but it brings security risks. The other is to apply a stateful firewall. When a stateful firewall is applied, only connections are allowed to be initiated from within the home network. This has higher security, but it limits the development of services.

[0004] Therefore, a new device access method needs to be provided.

[0005] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention

[0006] The purpose of the present disclosure is to provide a device access method, a device access apparatus, a computer-readable storage medium and an electronic device, thereby at least to a certain extent overcoming the problem of low device access security or inability of external devices to access internal devices of a home gateway due to limitations and defects of related technologies.

[0007] According to one aspect of the present disclosure, a device access method is provided, including:

[0008] In response to an external device accessing an intranet device, obtaining a temporary address associated with the intranet device generated by the external device, and verifying the temporary address;

[0009] When the temporary address is verified, creating an access control list and a firewall address translation rule according to the temporary address;

[0010] The access of the external device to the internal network device is achieved through the access control list and the firewall address conversion rules.

[0011] In an exemplary embodiment of the present disclosure, obtaining a temporary address associated with the intranet device generated by the external device and verifying the temporary address includes:

[0012] Obtain the real address of the internal network device, and generate a verification address associated with the internal network device according to the real address;

[0013] Verify the temporary address according to the verification address.

[0014] In an exemplary embodiment of the present disclosure, obtaining the real address of the internal network device and generating a verification address associated with the internal network device according to the real address includes:

[0015] Obtain the MAC address in the real address of the internal network device, the current access time of the external device, and a preset key;

[0016] Perform a hash calculation on the MAC address in the real address, the current access time, and the preset key to obtain a calculation result;

[0017] Obtain a verification address associated with the internal network device according to the first 16 bits of the calculation result.

[0018] In an exemplary embodiment of the present disclosure, performing a hash calculation on the MAC address in the real address, the current access time, and the preset key to obtain a calculation result includes:

[0019] Obtain a preset time window;

[0020] Based on the current access time, determine a conversion time corresponding to the current access time, and obtain a target time according to the conversion time and the preset time window;

[0021] Perform a hash calculation on the MAC address, the target time, and the preset key to obtain the calculation result.

[0022] In an exemplary embodiment of the present disclosure, the temporary address generated by the external device and associated with the internal network device is calculated by the external device according to the real address of the internal network device, the preset key, and the current access time of the external device.

[0023] In an exemplary embodiment of the present disclosure, before verifying the temporary address, the device access method further includes:

[0024] Determine whether there is a connection between the external device and the internal device;

[0025] When there is a connection, allow the external device to access the internal network device;

[0026] When there is no connection, verify the temporary address.

[0027] In an exemplary embodiment of the present disclosure, creating an access control list and a firewall address translation rule according to the temporary address includes:

[0028] Establishing a mapping relationship between the real address and the temporary address, and obtaining the firewall address translation rule through the mapping relationship;

[0029] Creating an access control list according to the real address of the internal network device and the real address of the external device, and allowing the network traffic between the external device and the internal device to pass through.

[0030] According to one aspect of the present disclosure, there is provided a device access apparatus, including:

[0031] An address verification module, configured to respond to an access of an external device to an internal network device, obtain a temporary address generated by the external device and associated with the internal network device, and verify the temporary address;

[0032] An address translation module, configured to create an access control list and a firewall address translation rule according to the temporary address when the temporary address passes the verification;

[0033] An external device access module, configured to implement the access of the external device to the internal network device through the access control list and the firewall address translation rule.

[0034] According to one aspect of the present disclosure, there is provided a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processing unit, the device access method described in any of the above exemplary embodiments is implemented.

[0035] According to one aspect of the present disclosure, there is provided an electronic device, including:

[0036] A processing unit; and

[0037] A storage unit, configured to store executable instructions of the processing unit;

[0038] Wherein, the processor is configured to execute the device access method described in any of the above exemplary embodiments by executing the executable instructions.

[0039] An equipment access method provided by an embodiment of the present disclosure responds to the access of an external device to an internal network device, obtains a temporary address generated by the external device and associated with the internal network device, and verifies the temporary address; when the temporary address passes the verification, an access control list and a firewall address translation rule are created according to the temporary address; through the access control list and the firewall address translation rule, the access of the external device to the internal network device is realized. On the one hand, when an external device accesses an internal network device, the home gateway obtains a temporary address generated by the external device and associated with the internal device, and verifies the obtained temporary address. When the verification passes, the external device is allowed to access the internal device of the home gateway. Among them, the access address when the external device accesses the internal device is a temporarily generated address, so that the external device cannot effectively probe, collect information and attack the internal device in the home gateway, improving the security of the internal device being accessed; on the other hand, when an external device accesses an internal device in the home gateway, only the temporary address generated by the external device needs to be verified, and it is not necessary to implement a five-tuple security policy, that is, it is not necessary to bind the IP address of the external device, nor to bind the access of a specific device, improving the convenience of device access.

[0040] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0042] Figure 1 Schematically shows a flowchart of an equipment access method according to an exemplary embodiment of the present disclosure.

[0043] Figure 2 Schematically shows a block diagram of an equipment access system according to an exemplary embodiment of the present disclosure.

[0044] Figure 3 Schematically shows a flowchart of a method for obtaining a temporary address generated by an external device and associated with an internal network device and verifying the temporary address according to an exemplary embodiment of the present disclosure.

[0045] Figure 4 Schematically shows a flowchart of a method for obtaining the real address of an internal network device and generating a verification address associated with the internal network device according to the real address according to an exemplary embodiment of the present disclosure.

[0046] Figure 5 Schematically shows a flowchart of a method for performing a hash calculation on a MAC address, a current access time, and a preset key in a real address to obtain a calculation result according to an exemplary embodiment of the present disclosure.

[0047] Figure 6 Schematically shows a flowchart of a device access method before verifying a temporary address according to an exemplary embodiment of the present disclosure.

[0048] Figure 7 Schematically shows a flowchart of a method for creating an access control list and a firewall address translation rule according to a temporary address according to an exemplary embodiment of the present disclosure.

[0049] Figure 8 Schematically shows a flowchart of a device access method according to an exemplary embodiment of the present disclosure.

[0050] Figure 9 Schematically shows a block diagram of a device access device according to an exemplary embodiment of the present disclosure.

[0051] Figure 10 Schematically shows an electronic device for implementing the above device access method according to an exemplary embodiment of the present disclosure. Detailed implementation manners

[0052] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the exemplary embodiments to those skilled in the art. The described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present disclosure. However, those skilled in the art will realize that one or more of the specific details can be omitted, or other methods, components, devices, steps, etc. can be used. In other cases, well-known technical solutions are not shown or described in detail to avoid obscuring the various aspects of the present disclosure.

[0053] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0054] When the devices within the home gateway are assigned IPv6 addresses, without configuring firewall policies, by default, the devices within the home gateway are exposed to the public network and are vulnerable to external scans and targeted attacks. When firewall policies are configured within the home gateway, only connections initiated from within the home gateway are allowed, which provides a high level of security but restricts the development of services.

[0055] Based on one or more of the above problems, in the present exemplary embodiment, a device access method is first provided, and this method can run in a home gateway; of course, those skilled in the art can also run the method of the present invention on other platforms according to requirements, and no special limitation is made in this exemplary embodiment. Refer to Figure 1 As shown, the device access method may include steps S110 - step S130:

[0056] Step S110. In response to an external device's access to an internal network device, obtain the temporary address generated by the external device and associated with the internal network device, and verify the temporary address;

[0057] Step S120. When the temporary address verification passes, create an access control list and a firewall address translation rule according to the temporary address;

[0058] Step S130. Through the access control list and the firewall address translation rule, enable the external device to access the internal network device.

[0059] The above device access method responds to the access of an external device to an internal network device, obtains a temporary address generated by the external device and associated with the internal network device, and verifies the temporary address; when the temporary address passes the verification, an access control list and a firewall address translation rule are created according to the temporary address; through the access control list and the firewall address translation rule, the access of the external device to the internal network device is realized. On the one hand, when an external device accesses an internal network device, the home gateway obtains a temporary address generated by the external device and associated with the internal device, and verifies the obtained temporary address. When the verification passes, the external device is allowed to access the internal device of the home gateway. Among them, the access address when the external device accesses the internal device is a temporarily generated address, so that the external device cannot effectively probe, collect information, and attack the internal devices in the home gateway, improving the security of the internal devices being accessed; on the other hand, when an external device accesses an internal device in the home gateway, only the temporary address generated by the external device needs to be verified, and there is no need to implement a five-tuple security policy, that is, there is no need to bind the IP address of the external device, nor to bind the access of specific devices, improving the convenience of device access.

[0060] Next, each step involved in the device access method of the exemplary embodiment of the present disclosure will be explained and described in detail.

[0061] First, the application scenario and purpose of the exemplary embodiment of the present disclosure will be explained and described. Specifically, the exemplary embodiment of the present disclosure can be applied to a home gateway, and mainly studies how to improve the security of internal network devices being accessed and the convenience of external device access when an external device accesses an internal network device in the home gateway.

[0062] In the present disclosure, when an external device needs to access an internal device of a home gateway, the external device generates a temporary address associated with the internal network device according to the address of the internal network device to be accessed, and sends the temporary address to the home gateway. The home gateway verifies the received temporary address. When the verification passes, the external device is allowed to access the internal network device in the home gateway, improving the convenience of external device access.

[0063] Secondly, the device access system involved in the present disclosure will be further explained and described. Refer to Figure 2As described above, the device access system may include: a home gateway 210, a home internal network 220, and an external device 230. Among them, the home gateway 210 includes an address verification module 211, a connection status management module 212, a firewall policy management module 213, and a stateful firewall 214; the home internal network 220 may include multiple internal network devices 221. Specifically, the external device 230 can access the internal network devices 221 included in the home internal network 220. When the external device 230 accesses the internal network device 221, first, a temporary address associated with the internal network device 221 is generated and sent to the address verification module 211 in the home gateway 210. The address verification module 211 verifies the temporary address generated by the external device. When the verification passes, the firewall policy management module 213 generates an IPv6 address translation rule and an access control list for the internal network device, and the stateful firewall 214 allows the external device 230 to pass according to the access control list, allowing the external device 230 to access the internal network device 221. The connection status management module 212 is used to manage the connection information between the external device and the internal network device, including the external device's IPv6 address, the internal network device's temporary IPv6 address, the internal network device's real IPv6 address, the internal network device's MAC address, and the start time of the connection between the external device and the internal network device.

[0064] Hereinafter, steps S110 - S130 will be explained and described in detail in conjunction with Figure 2 this.

[0065] In step S110, in response to the external device's access to the internal network device, the temporary address generated by the external device and associated with the internal network device is obtained, and the temporary address is verified.

[0066] In this exemplary embodiment, when the external device needs to access the internal network device within the home gateway, the external device generates a temporary address associated with the internal network device according to the MAC address of the internal network device to be accessed; the home gateway responds to the access to the internal network device, obtains the temporary address generated by the external device and associated with the internal network device, and verifies the obtained temporary address.

[0067] Refer to Figure 3 As shown, obtaining the temporary address generated by the external device and associated with the internal network device and verifying the temporary address may include:

[0068] Step S310. Obtain the real address of the internal network device, and generate a verification address associated with the internal network device according to the real address;

[0069] Step S320. Verify the temporary address according to the verification address.

[0070] The following will further explain and illustrate steps S310 and S320. Specifically, when the home gateway responds to an external device's access to an internal network device within the home gateway, it can obtain the temporary address generated by the external device and associated with the internal network device, and verify the obtained temporary address. When the address verification module of the home gateway verifies the temporary address, the home gateway can generate a verification address based on the external device's access to the internal network device and the real address of the internal network device, and verify the obtained temporary address through the verification address. Among them, the real address of the internal network device obtained by the home gateway is the MAC address of the internal network device.

[0071] Further, referring to Figure 4 as shown, obtaining the real address of the internal network device and generating a verification address associated with the internal network device according to the real address may include:

[0072] Step S410. Obtain the MAC address in the real address of the internal network device, the current access time of the external device, and a preset key;

[0073] Step S420. Perform a hash calculation on the MAC address in the real address, the current access time, and the preset key to obtain a calculation result;

[0074] Step S430. Obtain a verification address associated with the internal network device according to the first 16 bits of the calculation result.

[0075] The following will further explain and illustrate steps S410 - S430. Specifically, the home gateway obtains the MAC address in the real address of the internal network device, the current access time when the external device accesses the internal network device, and a key preset in advance by both parties before the external device accesses the internal network device; when the home gateway obtains the MAC address, the current access time, and the preset key, the home gateway performs a hash calculation on the MAC address of the internal network device, the current access time, and the preset key to obtain a result; since the address of a device in IPv6 is a total of 128 bits, the first 64 bits are the network address used for routing and addressing and cannot be dynamically changed. Among the remaining 64 bits, the first 48 bits are the MAC address of the device used to identify the device, and the remaining 16 bits are used to encode the device. Therefore, the first 16 bits of the calculation result can be taken, and a verification address of the internal network device can be generated through the first 16 bits of the calculation result. Among them, the verification address of the internal network device includes a 64-bit network address, a 48-bit MAC address, and a 16-bit calculation result.

[0076] Still further, referring to Figure 5 as shown, performing a hash calculation on the MAC address in the real address, the current access time, and the preset key to obtain a calculation result may include:

[0077] Step S510. Obtain a preset time window;

[0078] Step S520. Based on the current access time, determine a conversion time corresponding to the current access time, and obtain a target time according to the conversion time and the preset time window;

[0079] Step S530. Perform a hash calculation according to the MAC address, the target time, and the preset key to obtain the calculation result.

[0080] Hereinafter, steps S510 to S530 will be further explained and described. Specifically, when the home gateway calculates according to the MAC address of the internal network device, the current access time, and the preset key, first, it is necessary to obtain a preset time window. The preset time window can be 30 seconds or 45 seconds. In this exemplary embodiment, the preset time window is not specifically limited; then, based on the obtained current access time of the external device accessing the internal network device, determine a conversion time corresponding to the current access time. The conversion time can be UNIX time, and UNIX time is the total number of seconds from 00:00:00 on January 1, 1970, Coordinated Universal Time to the current access time. According to the UNIX time corresponding to the current access time and the preset time window, obtain the target time corresponding to the current access time, where the target time = [UNIX time of the current access time / time window]; finally, perform encryption and hash calculation on the MAC address of the internal network device, the target time, and the preset key to obtain the calculation result, where the calculation result = take the first 16 bits (Hash(Encrypt(MAC address + key + target time))), and Encrypt() is to perform an encryption calculation on the MAC address of the internal network device, the target time, and the key.

[0081] In this exemplary embodiment, the temporary address associated with the internal network device generated by the external device is calculated by the external device according to the real address of the internal network device, the preset key, and the current access time of the external device.

[0082] Specifically, when an external device accesses an internal network device within a home gateway, the external device can know the MAC address of the internal network device. Therefore, the external device can calculate a temporary address associated with the internal network device based on the MAC address in the real address of the internal network device, the current access time when it accesses the internal network device, and a pre-set key between the two parties before accessing the internal network device. Among them, when calculating, it is necessary to convert the current access time into UNIX time, obtain the target time through the UNIX time of the current access time and the pre-set time window, encrypt and perform a hash calculation on the target time, the MAC address of the internal network device, and the pre-set key to obtain a calculation result, take the first 16 bits of the calculation result, and obtain the temporary address through the network address, MAC address of the internal network device, and the first 16-bit calculation result obtained.

[0083] In this exemplary embodiment, by obtaining the verification address of the internal network device through the pre-set time window, it is achieved that the home gateway is only valid for accessing specific external devices within a short period of time, preventing the external devices from performing effective information collection and attack behaviors, and improving the security of the internal network device being accessed.

[0084] In this exemplary embodiment, referring to Figure 6 as shown, before verifying the temporary address, the device access method may further include:

[0085] Step S610. Determine whether there is a connection between the external device and the internal device;

[0086] Step S620. When there is a connection, allow the external device to access the internal network device;

[0087] Step S630. When there is no connection, verify the temporary address.

[0088] Hereinafter, steps S610 - S630 will be further explained and described. Specifically, before the address verification module of the home gateway verifies the received temporary address, the connection status management module searches in the connection information to determine whether there is a connection between the external device and the internal network device. When there is a connection record between the external device and the internal network device in the connection information, the stateful firewall in the home gateway allows the external device to access the internal network device. When there is no connection record in the connection information, the address verification module in the home gateway verifies the received temporary address.

[0089] In step S120, when the temporary address verification passes, create an access control list and a firewall address translation rule according to the temporary address.

[0090] In this exemplary embodiment, the address verification module in the home gateway compares the received temporary address with the verification address generated by itself to complete the verification of the received temporary address. After the address verification module passes the verification of the temporary address, the firewall policy management module in the home gateway creates an access control list and a firewall address translation rule according to the temporary address.

[0091] Reference Figure 7 As shown, creating an access control list and a firewall address translation rule according to the temporary address may include:

[0092] Step S710. Establish a mapping relationship between the real address and the temporary address, and obtain the firewall address translation rule through the mapping relationship;

[0093] Step S720. Create an access control list according to the real address of the internal network device and the real address of the external device, and allow the network traffic between the external device and the internal device to pass through.

[0094] Hereinafter, steps S710 and S720 will be further explained and described. Specifically, the firewall policy management module of the home gateway creates a mapping relationship between the real address of the internal network device and the temporary address according to the real IP address of the internal network device and the temporary address generated by the received external device, and generates a firewall address translation rule according to the mapping relationship; and, the firewall policy management module can also create an access control list according to the real address of the internal network device and the real address of the external device accessing the internal network device, and allow the external device to access the internal network device through the access control list.

[0095] In step S130, the access of the external device to the internal network device is realized through the access control list and the firewall address translation rule.

[0096] In this exemplary embodiment, the stateful firewall in the home gateway allows the network traffic between the external device and the internal network device to pass through according to the firewall address translation rule and the access control list, that is, realizes the access of the external device to the internal network device. After the network traffic between the external device and the internal network device passes through the stateful firewall, the connection state management module adds the connection between the external device and the internal network device to the connection record and manages the connection record.

[0097] The device access method provided by the exemplary embodiments of the present disclosure has at least the following advantages: On the one hand, when an external device accesses an internal network device, the generated temporary address is a temporarily generated address, which is only valid for a specific source within a short period of time, and it is impossible for other external devices to collect information about the internal network device and launch attacks; on the other hand, when an external device accesses an internal network device, there is no need to perform a five-tuple security policy based on network addresses. Only the temporary address associated with the internal network device generated by the external device needs to be verified. When the verification passes, the external device is allowed to access the internal network device, which improves the convenience of the external device accessing the internal network device and is conducive to supporting the deployment and protection of new IPv6 services.

[0098] The following will further explain and illustrate the device access method of the exemplary embodiments of the present disclosure in conjunction with Figure 8 The device access method may include the following steps:

[0099] Step S810. The external device obtains the MAC address of the internal network device, generates a temporary address based on the MAC address of the internal network device, and accesses the internal network device according to the temporary address;

[0100] Step S820. The home gateway responds to the access of the external device;

[0101] Step S830. Determine whether the connection record includes the connection record of the external device and the internal network device;

[0102] Step S840. When it exists, allow the external device to access the internal network device;

[0103] Step S850. When it does not exist, the home gateway verifies the received temporary address;

[0104] Step S860. When the verification passes, create a firewall address translation rule and an access control list;

[0105] Step S870. Add the connection between the external device and the internal network device to the connection record;

[0106] Step S880. When the verification fails, end the access to the internal network device.

[0107] The exemplary embodiments of the present disclosure also provide a device access apparatus. Referring to Figure 9 as shown, it may include: an address verification module 910, an address translation module 920, and an external device access module 930.

[0108] Among them:

[0109] An address verification module 910, which is configured to respond to an access from an external device to an intranet device, obtain a temporary address generated by the external device and associated with the intranet device, and verify the temporary address;

[0110] An address conversion module 920, which is configured to create an access control list and a firewall address conversion rule according to the temporary address when the temporary address passes the verification;

[0111] An external device access module 930, which is configured to implement the access of the external device to the intranet device through the access control list and the firewall address conversion rule.

[0112] The specific details of each module in the above device access device have been described in detail in the corresponding device access method, so they will not be elaborated here.

[0113] In an exemplary embodiment of the present disclosure, obtaining the temporary address generated by the external device and associated with the intranet device, and verifying the temporary address includes:

[0114] Obtaining the real address of the intranet device, and generating a verification address associated with the intranet device according to the real address;

[0115] Verifying the temporary address according to the verification address.

[0116] In an exemplary embodiment of the present disclosure, obtaining the real address of the intranet device, and generating a verification address associated with the intranet device according to the real address includes:

[0117] Obtaining the MAC address in the real address of the intranet device, the current access time of the external device, and a preset key;

[0118] Performing a hash calculation on the MAC address in the real address, the current access time, and the preset key to obtain a calculation result;

[0119] Obtaining a verification address associated with the intranet device according to the first 16 bits of the calculation result.

[0120] In an exemplary embodiment of the present disclosure, performing a hash calculation on the MAC address in the real address, the current access time, and the preset key to obtain a calculation result includes:

[0121] Obtaining a preset time window;

[0122] Based on the current access time, determining a conversion time corresponding to the current access time, and obtaining a target time according to the conversion time and the preset time window;

[0123] Perform a hash calculation based on the MAC address, the target time, and the preset key to obtain the calculation result.

[0124] In an exemplary embodiment of the present disclosure, the temporary address generated by the external device and associated with the internal network device is calculated by the external device based on the real address of the internal network device, the

[0125] preset key, and the current access time of the external device.

[0126] In an exemplary embodiment of the present disclosure, before verifying the temporary address, the device access method further includes:

[0127] Determine whether there is a connection between the external device and the internal device; when there is a connection, allow the external device to access the internal network device;

[0128] When there is no connection, verify the temporary address.

[0129] In an exemplary embodiment of the present disclosure, creating an access control list and a firewall address translation rule based on the temporary address includes:

[0130] Establish a mapping relationship between the real address and the temporary address, and obtain the firewall address translation rule through the mapping relationship;

[0131] Create an access control list based on the real address of the internal network device and the real address of the external device, and allow network traffic between the external device and the internal device to pass through.

[0132] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of the two or more modules or units described above can be embodied in one module

[0133] or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0134] In addition, although the steps of the method in the present disclosure are described in a specific order in the drawings,

[0135] however, this does not require or imply that these steps must be executed in this specific order, or that all the steps shown must be executed to achieve the desired result. Additionally or alternatively,

[0136] Omit certain steps, combine multiple steps into one step for execution, and / or decompose one step into multiple steps for execution, etc.

[0137] In an exemplary embodiment of the present disclosure, there is also provided an electronic device capable of implementing the above method.

[0138] Those skilled in the art can understand that various aspects of the present disclosure can be implemented as a system, a method, or a program product. Therefore, various aspects of the present disclosure can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuit", "module", or "system" here.

[0139] Refer to the following Figure 10 to describe the electronic device 1000 according to this embodiment of the present disclosure. Figure 10 The electronic device 1000 shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0140] As Figure 10 shown, the electronic device 1000 is presented in the form of a general-purpose computing device. The components of the electronic device 1000 may include, but are not limited to: at least one of the above-mentioned processing units 1010, at least one of the above-mentioned storage units 1020, a bus 1030 connecting different system components (including the storage unit 1020 and the processing unit 1010), and a display unit 1040.

[0141] Among them, the storage unit stores program codes, and the program codes can be executed by the processing unit 1010, so that the processing unit 1010 executes the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of this specification. For example, the processing unit 1010 can execute steps S110 as shown in Figure 1 : In response to an external device's access to an intranet device, obtain a temporary address generated by the external device and associated with the intranet device, and verify the temporary address; S120: When the temporary address verification passes, create an access control list and a firewall address translation rule according to the temporary address; S130: Through the access control list and the firewall address translation rule, implement the external device's access to the intranet device.

[0142] The storage unit 1020 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 10201 and / or a cache storage unit 10202, and may further include a read-only storage unit (ROM) 10203.

[0143] The storage unit 1020 may also include a program / utilities 10204 having a set (at least one) of program modules 10205. Such program modules 10205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0144] The bus 1030 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus structures.

[0145] The electronic device 1000 may also communicate with one or more external devices 1100 (such as a keyboard, a pointing device, a Bluetooth device, etc.), and may also communicate with one or more devices that enable a user to interact with the electronic device 1000, and / or communicate with any device that enables the electronic device 1000 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication may be carried out through the input / output (I / O) interface 1050. Moreover, the electronic device 1000 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 1060. As shown in the figure, the network adapter 1060 communicates with other modules of the electronic device 1000 through the bus 1030. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 1000, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0146] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software, or can be implemented by the way of software combined with necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0147] In an exemplary embodiment of the present disclosure, there is also provided a computer-readable storage medium, on which a program product capable of implementing the above methods in this specification is stored. In some possible implementation manners, various aspects of the present disclosure can also be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to cause the terminal device to execute the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of this specification.

[0148] The program product for implementing the above method according to an embodiment of the present disclosure may be a portable compact disc read-only memory (CD-ROM) and includes program code, and can run on a terminal device, such as a personal computer. However, the program product of the present disclosure is not limited thereto. In this document, the readable storage medium may be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device.

[0149] The program product may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0150] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium may also be any readable medium other than the readable storage medium, and the readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device.

[0151] The program code contained on the readable medium can be transmitted by any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the above.

[0152] Program code for performing the operations of the present disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).

[0153] In addition, the above-mentioned drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present disclosure, rather than for limiting purposes. It is easy to understand that the processes shown in the above-mentioned drawings do not indicate or limit the chronological order of these processes. Additionally, it is also easy to understand that these processes can be executed, for example, synchronously or asynchronously in multiple modules.

[0154] Other embodiments of the present disclosure will be readily apparent to those skilled in the art after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed herein. The specification and embodiments are to be considered exemplary only, and the true scope and spirit of the present disclosure are pointed out by the claims.

Claims

1. A device access method, characterized in that, comprising: responding to an access from an external device to an internal network device, obtaining the MAC address in the real address of the internal network device, the current access time of the external device, and a preset key; performing a hash calculation on the MAC address in the real address, the current access time, and the preset key to obtain a calculation result; obtaining a verification address associated with the internal network device according to the first 16 bits of the calculation result; verifying the temporary address associated with the internal network device according to the verification address; when the temporary address verification passes, creating an access control list and a firewall address translation rule according to the temporary address; realizing the access of the external device to the internal network device through the access control list and the firewall address translation rule.

2. The device access method according to claim 1, characterized in that, performing a hash calculation on the MAC address in the real address, the current access time, and the preset key to obtain a calculation result, comprising: obtaining a preset time window; determining a conversion time corresponding to the current access time based on the current access time, and obtaining a target time according to the conversion time and the preset time window; performing a hash calculation on the MAC address, the target time, and the preset key to obtain the calculation result.

3. The device access method according to claim 2, characterized in that, the temporary address generated by the external device and associated with the internal network device is calculated by the external device according to the real address of the internal network device, the preset key, and the current access time of the external device.

4. The device access method according to claim 1, characterized in that, before verifying the temporary address, the device access method further comprises: judging whether there is a connection between the external device and the internal network device; when there is a connection, allowing the external device to access the internal network device; when there is no connection, verifying the temporary address.

5. The device access method according to claim 1, characterized in that, creating an access control list and a firewall address translation rule according to the temporary address, comprising: establishing a mapping relationship between the real address and the temporary address, and obtaining the firewall address translation rule through the mapping relationship; creating an access control list according to the real address of the internal network device and the real address of the external device, and allowing the network traffic between the external device and the internal network device to pass.

6. A device access device, characterized in that, comprising: an address verification module, configured to respond to an access from an external device to an internal network device, and obtain the MAC address in the real address of the internal network device, the current access time of the external device, and a preset key; Perform a hash calculation on the MAC address in the real address, the current access time, and the preset key to obtain a calculation result; obtain a verification address associated with the internal network device according to the first 16 bits of the calculation result; verify the temporary address associated with the internal network device according to the verification address; An address conversion module, configured to create an access control list and a firewall address conversion rule according to the temporary address when the temporary address verification is passed; An external device access module, configured to implement the access of the external device to the internal network device through the access control list and the firewall address conversion rule.

7. A computer storage medium, on which a computer program is stored, characterized in that, when the computer program is executed by a processing unit, the device access method according to any one of claims 1-5 is implemented.

8. An electronic device, characterized in that, comprising: a processing unit; and a storage unit, configured to store executable instructions of the processing unit; wherein, the processing unit is configured to execute the device access method according to any one of claims 1-5 by executing the executable instructions.

Citation Information

Patent Citations

  • Method for insuring user's anonymous and its wireless local network system

    CN1489339A

  • Method, system and apparatus for monitoring and controlling data transfer in communication networks

    CN1666477A