Resource access method, device, equipment, medium and product

By introducing a man-in-the-middle module into the gateway device to parse and perform security checks on encrypted resources, the problem of insufficient security checks on encrypted resources in existing technologies is solved, thereby improving the security of accessing encrypted resources.

CN116015893BActive Publication Date: 2025-10-28CHINA UNIONPAY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211692604.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-27
Publication Date
2025-10-28
Estimated Expiration
2042-12-27

AI Technical Summary

Technical Problem

In existing technologies, it is difficult to effectively perform security checks on encrypted resources, which leads to reduced security when accessing encrypted resources.

Method used

A man-in-the-middle module is set up in the gateway device. This module impersonates a client to send access requests to encrypted resource points and performs security checks on the parsed encrypted resources. Only after the checks pass are the requests sent to devices within the domain.

Benefits of technology

It enables effective security detection of encrypted resources, improving the security of devices within the domain accessing encrypted resources outside the domain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015893B_ABST
    Figure CN116015893B_ABST
Patent Text Reader

Abstract

This application discloses a resource access method, apparatus, device, medium, and product. The resource access method is applied to a gateway device, which includes a man-in-the-middle module. The method includes: receiving an access request from a first device within a domain for a first resource point outside the domain; if the first resource point is an encrypted resource point, forwarding the access request to the man-in-the-middle module, which then sends the access request to the first resource point; if the first resource point accepts the access request, the man-in-the-middle module parses the encrypted resource obtained from the first resource point and performs a security check on the parsed encrypted resource to obtain a check result; if the check result is successful, the man-in-the-middle module sends the encrypted resource to the first device. According to the embodiments of this application, the security of accessing encrypted resources can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application pertains to computer technology, and particularly relates to a resource access method, apparatus, device, medium, and product. Background Technology

[0002] When applications within a domain access external resources, it is usually necessary to perform security checks on the resources to ensure that the accessed resources are secure.

[0003] For outbound encrypted traffic scenarios, that is, when an application within the domain accesses an external encrypted resource, such as an HTTPS site or other SSL (Secure Sockets Layer) or TSL (Transport Layer Security) services, it is difficult to perform security detection because the server is an external resource.

[0004] Thus, the lack of effective security detection methods for encrypted resources in the relevant technologies for secure operations reduces the security when accessing encrypted resources. Summary of the Invention

[0005] This application provides a resource access method, apparatus, device, medium, and product that can improve the security of accessing encrypted resources.

[0006] In a first aspect, embodiments of this application provide a resource access method applied to a gateway device, the gateway device including a man-in-the-middle module, the method comprising:

[0007] Receive an access request sent by the first device within the domain for the first resource point outside the domain;

[0008] If the first resource point is an encrypted resource point, the access request is forwarded to the man-in-the-middle module, and the man-in-the-middle module sends the access request to the first resource point.

[0009] When the first resource point accepts the access request, the man-in-the-middle module parses the encrypted resource obtained from the first resource point and performs a security test on the parsed encrypted resource to obtain the test result.

[0010] If the detection result is a pass, the man-in-the-middle module sends the encrypted resources to the first device.

[0011] Secondly, embodiments of this application provide a resource access device configured in a gateway device, the gateway device including a man-in-the-middle module, the device comprising:

[0012] The request receiving module is used to receive access requests sent by the first device within the domain for the first resource point outside the domain;

[0013] The request forwarding module is used to forward the access request to the man-in-the-middle module when the first resource point is an encrypted resource point, and the man-in-the-middle module sends the access request to the first resource point.

[0014] The resource detection module is used to, when the first resource point accepts the access request, have the man-in-the-middle module parse the encrypted resource obtained from the first resource point, and perform security detection on the parsed encrypted resource to obtain the detection result;

[0015] The resource sending module is used to send the encrypted resource to the first device by the man-in-the-middle module when the detection result is that the detection is passed.

[0016] Thirdly, embodiments of this application provide an electronic device, which includes: a processor and a memory storing computer program instructions;

[0017] When the processor executes the computer program instructions, it implements the steps of the resource access method as described in any embodiment of the first aspect.

[0018] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer program instructions that, when executed by a processor, implement the steps of the resource access method as described in any embodiment of the first aspect.

[0019] Fifthly, embodiments of this application provide a computer program product in which instructions, when executed by a processor of an electronic device, cause the electronic device to perform the steps of the resource access method as described in any embodiment of the first aspect.

[0020] The resource access method, apparatus, device, medium, and product in this application embodiment, by setting a man-in-the-middle module in the gateway device, when the gateway device receives an access request from a first device within the domain for a first resource point outside the domain, and if the first resource point is an encrypted resource point, the gateway device can forward the access request to the man-in-the-middle module. The man-in-the-middle module then impersonates the first device and sends the access request to the first resource point. After the first resource point accepts the access request, the man-in-the-middle module can parse the encrypted resource obtained from the first resource point and perform a security check on the parsed encrypted resource. If the check result is successful, the man-in-the-middle module impersonates the first resource point and sends the encrypted resource to the first device. In this way, effective security checks on encrypted resources can be achieved in the gateway device, improving the security when devices within the domain access encrypted resources outside the domain. Attached Figure Description

[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0022] Figure 1 This is a flowchart illustrating a resource access method provided in one embodiment of this application;

[0023] Figure 2 This is a schematic diagram illustrating the access to encrypted resource points provided in this application;

[0024] Figure 3 This is a schematic diagram illustrating the access to unencrypted resource points provided in this application;

[0025] Figure 4 This is a schematic diagram of the structure of a resource access device provided in one embodiment of this application;

[0026] Figure 5 This is a schematic diagram of the structure of an electronic device provided in one embodiment of this application. Detailed Implementation

[0027] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.

[0028] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.

[0029] To address the problems of the prior art, embodiments of this application provide a resource access method, apparatus, device, medium, and product. This resource access method can be applied to scenarios where devices within a domain access resources outside the domain. The resource access method provided in this application embodiment is described below.

[0030] Figure 1 This is a flowchart illustrating a resource access method provided in one embodiment of this application. This resource access method can be applied to a gateway device, which may include a man-in-the-middle module. This module can impersonate a resource point when facing devices within the domain, and impersonate a client when facing a resource point. The man-in-the-middle module enables the parsing and security detection of encrypted resources. Additionally, the gateway device can be a device providing NAT (Network Address Translation) gateway services. A NAT gateway is a public network gateway used to provide network address translation capabilities for devices within a private network, enabling multiple services within a subnet (i.e., within a domain) to share IP addresses and a unified access point. This embodiment of the application implements man-in-the-middle hijacking on the gateway device.

[0031] like Figure 1 As shown, this resource access method may specifically include the following steps:

[0032] S110, Receive an access request sent by the first device within the domain for the first resource point outside the domain;

[0033] S120. If the first resource point is an encrypted resource point, the access request is forwarded to the man-in-the-middle module, and the man-in-the-middle module sends the access request to the first resource point.

[0034] S130. When the access request is received at the first resource point, the man-in-the-middle module parses the encrypted resource obtained from the first resource point and performs a security test on the parsed encrypted resource to obtain the test result.

[0035] S140. If the detection result is that the detection is passed, the man-in-the-middle module sends the encrypted resources to the first device.

[0036] Therefore, by setting up a man-in-the-middle module in the gateway device, when the gateway device receives an access request from a first device within the domain for a first resource point outside the domain, and if the first resource point is an encrypted resource point, the gateway device can forward the access request to the man-in-the-middle module. The man-in-the-middle module then impersonates the first device and sends the access request to the first resource point. After the first resource point accepts the access request, the man-in-the-middle module can parse the encrypted resource obtained from the first resource point and perform a security check on the parsed encrypted resource. If the check passes, the man-in-the-middle module impersonates the first resource point and sends the encrypted resource back to the first device. In this way, effective security checks on encrypted resources can be implemented in the gateway device, improving the security of domain-internal devices accessing encrypted resources outside the domain.

[0037] The specific implementation methods for each of the above steps are described below.

[0038] In some implementations, in S110, the first device can be any host device within the domain, and the first resource point can be any resource point outside the domain. The first resource point can be an encrypted resource point or an unencrypted resource point.

[0039] For example, if a first device within a domain needs to access a first resource point outside the domain, the first device may send an access request for the first resource point outside the domain to a gateway device, which will then forward the access request.

[0040] In some specific examples, if the address of the first resource point is http: / / 116.116.116.116:443, the first device can send the access request to the NAT gateway, which will then forward the access request to the address http: / / 116.116.116.116:443 outside the domain.

[0041] In some implementations, in S120, the gateway device can identify encrypted resource points by setting a special tag. In this way, it can be determined whether the first resource point to be accessed is an encrypted resource point by judging whether the first resource point has the tag of an encrypted resource point.

[0042] For example, if the first resource point has a label of an encrypted resource point, then the first resource point can be determined to be a pre-labeled encrypted resource point; otherwise, the first resource point can be determined not to be a pre-labeled encrypted resource point.

[0043] In some examples, if it is determined that the first resource point requested by the first device is an encrypted resource point, the NAT gateway can forward the access request to a man-in-the-middle module. The man-in-the-middle module then impersonates the client corresponding to the first device and sends the access request to the first resource point. Specifically, this impersonation could involve sending an access request carrying a first encryption certificate to the first resource point. Here, the first encryption certificate can be a certificate used to identify the first device's access rights to the encrypted resource at the first resource point.

[0044] In some implementations, in S130, after receiving an access request, if the first resource point accepts the request, it can return the encrypted resource requested by the first device to the man-in-the-middle module. Upon receiving the encrypted resource, the man-in-the-middle module at the gateway can use the decryption algorithm provided by the first device to parse the encrypted resource and obtain the plaintext. Based on this, the man-in-the-middle module can perform security checks and other business processes on the plaintext to determine whether the resource has any security vulnerabilities and obtain a detection result. If no security vulnerabilities exist, the detection result is "detection passed"; if security vulnerabilities exist, the detection result is "detection failed".

[0045] In some implementations, in S140, the man-in-the-middle module only sends the encrypted resource to the NAT gateway if the detection result is successful, and the NAT gateway then forwards it to the first device. Here, the man-in-the-middle module can impersonate the first resource point to send the encrypted resource to the first device.

[0046] In some specific examples, such as Figure 2 As shown, when the first device 21 accesses the first resource point 24 (address: http: / / 116.116.116.116:443), which has been marked as an encrypted resource point, the first device 21 can first send an access request to the NAT gateway 22. When the NAT gateway 22 recognizes the first resource point 24 as an encrypted resource point, it can forward the access request to the man-in-the-middle module 23. The man-in-the-middle module 23 then impersonates a client and sends the access request to the encrypted resource point. Subsequently, after receiving the encrypted resource returned by the first resource point 24, the man-in-the-middle module 23 can parse the encrypted resource and perform a security check on the plaintext resource obtained after parsing. If the check passes, it impersonates the resource point and sends the encrypted resource to the NAT gateway 22, which then forwards the encrypted resource back to the corresponding first device 21.

[0047] In addition, to enable monitoring of encrypted resources, in some embodiments, the gateway device may further include an encrypted resource detection module. After S110, the resource access method provided in this application embodiment may further include:

[0048] If the first resource point is not a pre-marked encrypted resource point, an access request is sent to the first resource point, and the encrypted resource detection module detects whether the resource obtained from the first resource point is an encrypted resource.

[0049] If the resource obtained from the first resource point is an encrypted resource, mark the first resource point as an encrypted resource point.

[0050] In some specific examples, such as Figure 3 As shown, when the first device 31 accesses the first resource point 34 (address: http: / / 116.116.116.116:443) which is not marked as an encrypted resource point, firstly, the first device 31 within the domain can send an access request to the NAT gateway 32. If the NAT gateway 32 recognizes that the first resource point 34 is not a pre-marked encrypted resource point, the NAT gateway 32 can forward the access request to the first resource point 34 outside the domain after address translation. At the same time, the encrypted resource detection module 33 can continuously monitor the incoming and outgoing information through bypass technology to determine whether the resource obtained from the first resource point 34 is an encrypted resource. If it is detected that the resource obtained by the NAT gateway 32 from the first resource point 34 is an encrypted resource, the encrypted resource detection module 33 can send a notification to the NAT gateway 32, informing it that the first resource point 34 is an encrypted resource point, and the NAT gateway 32 can mark the first resource point 34 as an encrypted resource point.

[0051] Based on this, in order to further improve the security of accessing encrypted resources, in some embodiments, when the resource obtained from the first resource point is an encrypted resource, the resource access method provided in this application embodiment may further include:

[0052] Block the access connection between the first device and the first resource point.

[0053] Here, since the gateway will not call the man-in-the-middle module to perform security checks on encrypted resources if the first resource point is not marked as an encrypted resource point, the access process may have security risks if the first resource point is actually an encrypted resource point. Based on this, if the first resource point is actually an encrypted resource point but has not been marked as an encrypted resource point by the gateway, the current access connection can be blocked. When the access is initiated again next time, the man-in-the-middle module will be called to perform security checks based on the marked resource point, so as to eliminate security risks and further improve the security of access to encrypted resources.

[0054] In addition, after marking the first resource point as an encrypted resource point, the resource access method provided in this application embodiment may further include:

[0055] Get the target time of the most recent access to the first resource point by any device within the domain;

[0056] If the time interval between the system time and the target time is greater than a preset threshold, delete the marker of the encrypted resource point corresponding to the first resource point.

[0057] In this embodiment, the markers for encrypted resource points do not need to be fixed. A marker invalidation strategy can be set. For example, a threshold for the time interval between unaccessed accesses can be set. Specifically, if the time interval between the target time of the most recent access to the first resource point by any device within the domain and the current system time exceeds the preset threshold, the encrypted resource point marker for that first resource point can be determined to be invalid. For instance, if the first resource point has not been accessed within the last 30 minutes, the encrypted resource point marker corresponding to that first resource point can be deleted.

[0058] In addition, the marking of encrypted resource points can be manually maintained, that is, the marking of external encrypted resource points can be actively marked by humans and the expiration period of the marking can be managed to obtain a better user experience.

[0059] Furthermore, in dual-certificate scenarios (i.e., scenarios where both the client device within the domain and the resource point outside the domain hold encryption certificates), the first device needs to upload the encryption certificate held by the client to the gateway at the same time as sending the access request or before sending the access request, so that the gateway can carry the encryption certificate when forwarding the access request to the corresponding resource point. Based on this, in some embodiments, before the above S110, the resource access method provided in this application embodiment may further include:

[0060] Receive a registration request for a first resource point sent by a first device, the registration request including a first encryption certificate;

[0061] In response to the registration request, the first encryption certificate is stored in the man-in-the-middle module.

[0062] Accordingly, the step in S120 above, in which the man-in-the-middle module sends an access request to the first resource point, may specifically include:

[0063] The man-in-the-middle module sends an access request carrying the first encryption certificate to the first resource point, so that the first resource point can authenticate the first device based on the first encryption certificate and accept the access request if the authentication is successful.

[0064] For example, before accessing the first resource point, the first device may first send a registration request to the gateway device to pre-save the first encryption certificate in the man-in-the-middle module of the gateway device. Of course, the first device may also send a registration request to the gateway device at the same time as sending an access request for the first resource point; this is not limited here.

[0065] In this way, after the first encryption certificate is stored in the man-in-the-middle module, when the first device in the domain accesses the first resource point outside the domain, the man-in-the-middle module can carry the first encryption certificate and impersonate the first device to access the first resource point.

[0066] In addition, to facilitate the management of encryption certificates, the gateway device can issue alternative certificates that are actually used within the domain. In some implementations, before storing the first encryption certificate in the man-in-the-middle module, the resource access method provided in this application embodiment may further include:

[0067] The man-in-the-middle module generates a second encryption certificate and sends the second encryption certificate to the first device.

[0068] Accordingly, the step of saving the first encryption certificate in the man-in-the-middle module can specifically include:

[0069] The first and second encryption certificates are associated and stored in the man-in-the-middle module.

[0070] Here, if a client certificate for a specific encrypted resource point exists in a device within the domain, the gateway device can perform a one-to-one re-signature of the client certificate when the device within the domain registers the client certificate with the gateway.

[0071] For example, if the encrypted access is in dual-certificate mode, that is, both the client and the server participating in the access need to hold encryption certificates, then the man-in-the-middle module needs to re-certify the client certificate of the device in the domain (that is, issue a replacement certificate, such as a regenerated second encryption certificate) and record the correspondence between the re-certified certificate and the client encryption certificate.

[0072] Based on this, in some implementations, the above-mentioned S110 may specifically include:

[0073] Receive an access request sent by the first device within the domain to a first resource point outside the domain, carrying a second encrypted certificate;

[0074] Before the step described above whereby the man-in-the-middle module sends an access request carrying the first encryption certificate to the first resource point, the resource access method provided in this application embodiment may further include:

[0075] The man-in-the-middle module authenticates the first device based on the second encryption certificate. If the authentication is successful, it queries and retrieves the first encryption certificate that is associated with the second encryption certificate.

[0076] Here, the first device can use an alternative certificate, namely the second encryption certificate, when interacting with the gateway device. When the man-in-the-middle module acts as a proxy, it can select the client certificate, namely the first encryption certificate, for communicating with the first resource point outside the domain, based on the alternative certificate used by the first device within the domain during the session. This allows the man-in-the-middle module to use the first encryption certificate to communicate with the first resource point.

[0077] It should be noted that the application scenarios described in the above embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0078] Based on the same inventive concept, this application also provides a resource access device. (Specifically combined with...) Figure 4 Please provide a detailed explanation.

[0079] Figure 4 This is a schematic diagram of a resource access device provided in one embodiment of this application. The resource access device can be configured in a gateway device, which may include a man-in-the-middle module.

[0080] like Figure 4 As shown, the resource access device 400 may include:

[0081] The request receiving module 401 is used to receive the access request sent by the first device within the domain for the first resource point outside the domain;

[0082] The request forwarding module 402 is used to forward the access request to the man-in-the-middle module when the first resource point is an encrypted resource point, and the man-in-the-middle module sends the access request to the first resource point.

[0083] The resource detection module 403 is used to, when the first resource point accepts the access request, have the man-in-the-middle module parse the encrypted resource obtained from the first resource point, and perform security detection on the parsed encrypted resource to obtain the detection result;

[0084] The resource sending module 404 is used to send the encrypted resource to the first device by the man-in-the-middle module when the detection result is that the detection is passed.

[0085] The resource access device 400 described above will be explained in detail below:

[0086] In some embodiments, the gateway device further includes an encrypted resource detection module;

[0087] The aforementioned resource access device 400 also includes:

[0088] An encryption detection module is used to send the access request to the first resource point after receiving an access request for the first resource point outside the domain from the first device within the domain, if the first resource point is not a pre-marked encrypted resource point, and the encryption resource detection module detects whether the resource obtained from the first resource point is an encrypted resource.

[0089] The resource marking module is used to mark the first resource point as an encrypted resource point if the resource obtained from the first resource point is an encrypted resource.

[0090] In some embodiments, the resource access device 400 further includes:

[0091] The connection blocking module is used to block the access connection between the first device and the first resource point if the resource obtained from the first resource point is an encrypted resource.

[0092] In some embodiments, the resource access device 400 further includes:

[0093] The time acquisition module is used to acquire the target time of the most recent access to the first resource point by any device in the domain after the first resource point is marked as an encrypted resource point.

[0094] The marker deletion module is used to delete the marker of the encrypted resource point corresponding to the first resource point when the time interval between the system time and the target time is greater than a preset threshold.

[0095] In some embodiments, the resource access device 400 further includes:

[0096] The certificate registration module is used to receive a registration request for the first resource point sent by the first device outside the domain before receiving an access request for the first resource point sent by the first device within the domain. The registration request includes a first encryption certificate.

[0097] A certificate storage module is used to store the first encrypted certificate in the man-in-the-middle module in response to the registration request;

[0098] The request forwarding module 402 is specifically used for:

[0099] The man-in-the-middle module sends an access request carrying the first encryption certificate to the first resource point, so that the first resource point can authenticate the first device based on the first encryption certificate and accept the access request if the authentication is successful.

[0100] In some embodiments, the resource access device 400 further includes:

[0101] The certificate issuance module is used to generate a second encryption certificate by the man-in-the-middle module before the first encryption certificate is stored in the man-in-the-middle module, and to issue the second encryption certificate to the first device.

[0102] The certificate storage module is specifically used for:

[0103] The first encryption certificate and the second encryption certificate are associated and stored in the man-in-the-middle module.

[0104] In some embodiments, the request receiving module 401 is specifically used for:

[0105] Receive an access request sent by the first device within the domain to a first resource point outside the domain, carrying the second encryption certificate;

[0106] Resource access device 400 also includes:

[0107] The certificate acquisition module is used to authenticate the first device based on the second encryption certificate before the man-in-the-middle module sends an access request carrying the first encryption certificate to the first resource point, and to query and obtain the first encryption certificate associated with the second encryption certificate if the authentication is successful.

[0108] Therefore, by setting up a man-in-the-middle module in the gateway device, when the gateway device receives an access request from a first device within the domain for a first resource point outside the domain, and if the first resource point is an encrypted resource point, the gateway device can forward the access request to the man-in-the-middle module. The man-in-the-middle module then impersonates the first device and sends the access request to the first resource point. After the first resource point accepts the access request, the man-in-the-middle module can parse the encrypted resource obtained from the first resource point and perform a security check on the parsed encrypted resource. If the check passes, the man-in-the-middle module impersonates the first resource point and sends the encrypted resource back to the first device. In this way, effective security checks on encrypted resources can be implemented in the gateway device, improving the security of domain-internal devices accessing encrypted resources outside the domain.

[0109] Figure 5 This is a schematic diagram of the structure of an electronic device provided in one embodiment of this application.

[0110] The electronic device 500 may include a processor 501 and a memory 502 storing computer program instructions.

[0111] Specifically, the processor 501 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.

[0112] Memory 502 may include mass storage for data or instructions. For example, and not limitingly, memory 502 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 502 may include removable or non-removable (or fixed) media. Where appropriate, memory 502 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 502 is non-volatile solid-state memory.

[0113] In certain embodiments, the memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Thus, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to one aspect of this application.

[0114] The processor 501 implements any of the resource access methods described in the above embodiments by reading and executing computer program instructions stored in the memory 502.

[0115] In some examples, the electronic device 500 may also include a communication interface 503 and a bus 510. For example, Figure 5 As shown, the processor 501, memory 502, and communication interface 503 are connected through bus 510 and complete communication with each other.

[0116] The communication interface 503 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.

[0117] Bus 510 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not as a limitation, bus 510 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 510 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.

[0118] For example, the electronic device 500 can be a mobile phone, tablet computer, laptop computer, handheld computer, in-vehicle electronic device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc.

[0119] The electronic device 500 can execute the resource access method in the embodiments of this application, thereby achieving the combination Figure 1 and Figure 4 The resource access methods and apparatus described.

[0120] Furthermore, in conjunction with the resource access methods in the above embodiments, this application embodiment can provide a computer-readable storage medium for implementation. This computer-readable storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the resource access methods in the above embodiments. Examples of computer-readable storage media include non-transitory computer-readable storage media, such as portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, etc.

[0121] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.

[0122] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.

[0123] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0124] The aspects of this application have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by dedicated hardware performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0125] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.

Claims

1. A resource access method, characterized in that, Applied to a gateway device, the gateway device including a man-in-the-middle module and an encrypted resource detection module, the method includes: Receive an access request sent by the first device within the domain for the first resource point outside the domain; If the first resource point is an encrypted resource point, the access request is forwarded to the man-in-the-middle module, and the man-in-the-middle module impersonates the first device to send the access request to the first resource point; When the first resource point accepts the access request, the man-in-the-middle module parses the encrypted resource obtained from the first resource point and performs a security test on the parsed encrypted resource to obtain the test result. If the detection result is a pass, the man-in-the-middle module impersonates the first resource point and sends the encrypted resource to the first device. If the first resource point is not a pre-marked encrypted resource point, the access request is sent to the first resource point, and the encrypted resource detection module detects whether the resource obtained from the first resource point is an encrypted resource. If the resource obtained from the first resource point is an encrypted resource, the first resource point is marked as an encrypted resource point; Block the access connection between the first device and the first resource point.

2. The method according to claim 1, characterized in that, After marking the first resource point as an encrypted resource point, the method further includes: Obtain the target time of the most recent access to the first resource point by any device within the domain; If the time interval between the system time and the target time is greater than a preset threshold, the marker of the encrypted resource point corresponding to the first resource point is deleted.

3. The method according to claim 1, characterized in that, Before receiving an access request for a first resource point outside the domain sent by a first device within the domain, the method further includes: Receive a registration request for the first resource point sent by the first device, wherein the registration request includes a first encryption certificate; In response to the registration request, the first encryption certificate is stored in the man-in-the-middle module; The step of the man-in-the-middle module impersonating the first device to send the access request to the first resource point includes: The man-in-the-middle module sends an access request carrying the first encryption certificate to the first resource point, so that the first resource point can authenticate the first device based on the first encryption certificate and accept the access request if the authentication is successful.

4. The method according to claim 3, characterized in that, Before saving the first encryption certificate in the man-in-the-middle module, the method further includes: The man-in-the-middle module generates a second encryption certificate and sends the second encryption certificate to the first device; Saving the first encryption certificate in the man-in-the-middle module includes: The first encryption certificate and the second encryption certificate are associated and stored in the man-in-the-middle module.

5. The method according to claim 4, characterized in that, The receipt of the access request for the first resource point outside the domain sent by the first device within the domain includes: Receive an access request sent by the first device within the domain to a first resource point outside the domain, carrying the second encryption certificate; Before the man-in-the-middle module sends an access request carrying the first encryption certificate to the first resource point, the method further includes: The man-in-the-middle module authenticates the first device based on the second encryption certificate, and if the authentication is successful, queries and retrieves the first encryption certificate that is associated with and saved with the second encryption certificate.

6. A resource access device, characterized in that, Configured in a gateway device, the gateway device includes a man-in-the-middle module and an encrypted resource detection module, the device comprising: The request receiving module is used to receive access requests sent by the first device within the domain for the first resource point outside the domain; The request forwarding module is used to forward the access request to the man-in-the-middle module when the first resource point is an encrypted resource point, and the man-in-the-middle module impersonates the first device to send the access request to the first resource point. The resource detection module is used to, when the first resource point accepts the access request, have the man-in-the-middle module parse the encrypted resource obtained from the first resource point, and perform security detection on the parsed encrypted resource to obtain the detection result; The resource sending module is used to send the encrypted resource to the first device by the man-in-the-middle module, which is disguised as the first resource point, when the detection result is that the detection is passed. An encryption detection module is used to send the access request to the first resource point when the first resource point is not a pre-marked encryption resource point, and the encryption resource detection module detects whether the resource obtained from the first resource point is an encryption resource. The resource marking module is used to mark the first resource point as an encrypted resource point when the resource obtained from the first resource point is an encrypted resource. The connection blocking module is used to block the access connection between the first device and the first resource point.

7. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the steps of the resource access method as described in any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that, when executed by a processor, implement the steps of the resource access method as described in any one of claims 1-5.

9. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device causes the electronic device to perform the steps of the resource access method as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Data security detection method and device, storage medium and electronic equipment

    CN111541682A

  • Resource access method and device and electronic equipment

    CN114157485A