Whitelist updating method, device, electronic device and storage medium

By accessing the key port to verify the legitimacy, dynamically switch the whitelist mode and upgrade the business software, the problems of high operation and maintenance costs and security risks in the whitelist update are solved, and a safe and controllable whitelist update is achieved.

CN116055124BActive Publication Date: 2025-09-05BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211656877.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-22
Publication Date
2025-09-05
Estimated Expiration
2042-12-22

AI Technical Summary

Technical Problem

The existing whitelist mechanism has high operation and maintenance costs and lack of control over operation permissions during updates, resulting in frequent false interception and protection of vacuums, and increased security risks.

Method used

Verify the legitimacy by accessing the key port, dynamically switch the whitelist mode to the audit mode, upgrade the business software and add new information to the whitelist, and restore the protection mode after the key port is disconnected.

Benefits of technology

Improve the controllability of the whitelist protection function, reduce error interception, ensure update safety, and reduce operation and maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116055124B_ABST
    Figure CN116055124B_ABST
Patent Text Reader

Abstract

The embodiments of the present invention disclose a whitelist updating method, device, electronic device, and storage medium, and relate to the field of communication technology. The method includes: in response to receiving a key access request input by a key port, determining whether the key port ID to be authenticated in the key access request matches the legal key port ID obtained by the terminal; if the key port ID to be authenticated matches the legal key port ID, switching the current whitelist mode on the terminal from a protection mode to an audit mode; the protection mode indicates that the whitelist function on the terminal has been enabled for protection, and the audit mode indicates that the whitelist function on the terminal has been suspended for protection; upgrading the service software to be upgraded on the terminal, and adding the newly added information generated during the upgrade to the whitelist to update the whitelist.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to a whitelist updating method, device, electronic device and storage medium. Background Art

[0002] A whitelist is the opposite of a blacklist. A protection system pre-populates a set of trusted entities with their characteristics. The core of the whitelist protection mechanism is that, during system operation, only those entities on the whitelist are allowed to execute or perform actions, while actions taken by entities outside the whitelist are blocked. The whitelist mechanism is a very strict and effective protection strategy, particularly effective against unknown threats and attacks. It is commonly used on terminals such as industrial computers, workstations, and specialized equipment.

[0003] However, there are certain problems when using whitelists: First, the operation and maintenance costs are too high. Some terminals with whitelist protection enabled require frequent operations, especially daily upgrades, installation of new programs, file changes, and other operations, which may cause business files that are not included in the whitelist to be mistakenly intercepted, affecting system use, and the cost of frequent changes to whitelist operations is high; second, there is a lack of control over the operating permissions of the whitelist protection function. Users sometimes turn off the whitelist protection function for convenience, and the function is usually turned off without management and control, resulting in a protection vacuum in the terminal and increased security risks.

[0004] Therefore, there is an urgent need for a whitelist processing mechanism that can facilitate users to update the content in the whitelist while ensuring the security of the update. Summary of the Invention

[0005] In view of this, embodiments of the present invention provide a whitelist updating method, apparatus, electronic device, and storage medium to solve the problem of low iteration efficiency when updating the existing whitelist sample database.

[0006] In a first aspect, an embodiment of the present invention provides a whitelist updating method, applied to a terminal, the method comprising:

[0007] In response to receiving a key access request input by a key port, determining whether the key port ID to be authenticated in the key access request matches the legitimate key port ID obtained by the terminal;

[0008] When the key port ID to be authenticated matches the legal key port ID, the whitelist mode on the current terminal is switched from protection mode to audit mode; the protection mode indicates that the whitelist function on the terminal has enabled protection, and the audit mode indicates that the whitelist function on the terminal has suspended protection;

[0009] The service software to be upgraded on the terminal is upgraded, and the newly added information generated during the upgrade is added to the whitelist to update the whitelist.

[0010] Optionally, the whitelist includes: a file whitelist, a link address whitelist and an external device whitelist.

[0011] Optionally, the key port to be authenticated in the key access request is Ukey.

[0012] Optionally, the key access request also includes a password entered by the user;

[0013] When the key port ID to be authenticated matches the legal key port ID, switching the current whitelist mode on the terminal from the protection mode to the audit mode includes:

[0014] If the key port ID to be authenticated matches the legal key port ID, determining whether the password input by the user matches the obtained key port password; the key port password corresponds to the legal key port ID;

[0015] If a match is found, the whitelist mode on the current terminal is switched from protection mode to audit mode.

[0016] Optionally, the method further includes:

[0017] One or more of the files, link addresses, and external devices newly added by the terminal during the period when the whitelist mode is the audit mode are added to the whitelist to update the whitelist.

[0018] Optionally, the method further includes:

[0019] Monitor whether the currently connected key port is disconnected;

[0020] If the currently connected key port is disconnected, switch the whitelist mode on the current terminal from audit mode to protection mode to perform protection according to the updated whitelist.

[0021] Optionally, when the key port ID to be authenticated does not match the legal key port ID, the method further includes:

[0022] Generate and output alarm information.

[0023] In a second aspect, an embodiment of the present invention provides a whitelist updating device, the device comprising:

[0024] The access unit, in response to receiving a key access request input by a key port, determines whether the key port ID to be authenticated in the key access request matches the legal key port ID obtained by the terminal;

[0025] The processing unit switches the current whitelist mode on the terminal from a protection mode to an audit mode when the key port ID to be authenticated matches the legal key port ID; the protection mode indicates that the whitelist function on the terminal has enabled protection, and the protection mode indicates that the whitelist function on the terminal has suspended protection;

[0026] The upgrading unit upgrades the service software to be upgraded on the terminal, and adds the newly added information generated during the upgrading to the white list to update the white list.

[0027] In a third aspect, an embodiment of the present disclosure further provides an electronic device, comprising: a housing, a processor, a memory, a circuit board, and a power supply circuit, wherein the circuit board is placed inside the space enclosed by the housing, and the processor and the memory are arranged on the circuit board; a power supply circuit for supplying power to various circuits or devices of the above-mentioned electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the whitelist update method described in the first aspect above.

[0028] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, which stores one or more programs, and the one or more programs can be executed by one or more processors to implement the whitelist update method described in the first aspect.

[0029] The embodiments of the present invention provide a whitelist updating method, device, electronic device and storage medium, which dynamically control the whitelist to achieve terminal protection by determining whether the key port ID to be authenticated in the key access request matches the legitimate key port ID obtained by the terminal. This verification mode can improve the controllability of the operation of the whitelist protection function, reduce the whitelist protection function being stopped due to improper operation by the user, and thus facilitate users to update the content in the whitelist while ensuring the security of the update. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0031] Figure 1 A flowchart of a whitelist updating method provided by an embodiment of the present invention;

[0032] Figure 2 A schematic structural diagram of a whitelist updating device provided by an embodiment of the present invention;

[0033] Figure 3 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0034] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0035] It should be understood that the embodiments described are only a portion of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without creative work are within the scope of protection of the present invention.

[0036] The following is combined with Figure 1 , the solution provided by the embodiment of the present invention is described in detail, Figure 1 This is a flow chart of a whitelist update method provided by an embodiment of the present invention. In this embodiment of the present invention, the implementation subject is a terminal. The terminal can be a terminal device, such as a personal computer, a desktop computer, etc. The terminal can also be a server. Figure 1 As shown, the method of this embodiment specifically includes the following steps:

[0037] Step 110: In response to receiving a key access request input by a key port, determine whether the key port ID to be authenticated in the key access request matches the legal key port ID obtained by the terminal.

[0038] In this application, the key port can be understood as a port device that can be directly connected to the user's computer and has password verification function, network data interaction function and storage function, specifically a UKey device.

[0039] A key access request is a port access request generated by a terminal after it detects a key insertion. The key access request includes the key port ID to be authenticated. When a terminal receives a key access request, it indicates that the user wants to authenticate the updateable whitelist using the access key.

[0040] The key port ID and corresponding key port password can be pre-authenticated by the user management center and then issued to the corresponding terminal. The terminal receives the key port ID and corresponding key port password corresponding to the terminal. Alternatively, the key port password can be issued by the terminal after accessing the key port.

[0041] The whitelist mode in this application includes audit mode and protection mode. Before receiving a key access request, the terminal needs to initialize its whitelist. After completing the whitelist initialization, the terminal needs to enable protection mode and determine whether to intercept the access object based on the current whitelist of the terminal.

[0042] Protection mode indicates that the whitelist function on this terminal has been enabled. Correspondingly, audit mode indicates that the whitelist function on this terminal has been suspended.

[0043] Specifically, when protection mode is enabled, the terminal will intercept non-whitelisted objects, including but not limited to blocking the launch of non-whitelisted files, blocking access to non-whitelisted links, and blocking access to non-whitelisted peripherals. When audit mode is enabled, the terminal will not perform interception or blocking operations, but will automatically add new files, links, and external devices to the local whitelist and update the local whitelist data.

[0044] Preferably, the whitelist in this application includes but is not limited to: a file whitelist, a link address whitelist and an external device whitelist.

[0045] Step 120: When the key port ID to be authenticated matches the legal key port ID, the whitelist mode on the current terminal is switched from the protection mode to the audit mode.

[0046] After accessing the key, the terminal needs to verify the key identity to determine whether the key is a legal and authenticated port device, that is, to determine whether the key port ID to be authenticated matches the legal key port ID. If they match, it means that the currently accessed key has been authenticated; if they do not match, it means that the currently accessed key has not been authenticated and is illegal.

[0047] Preferably, the present application can also adopt a dual authentication verification mode, namely device authentication and password authentication. The key access request also includes the password entered by the user. When the key port ID to be authenticated matches the legal key port ID, the terminal will generate a password authentication password and receive the password entered by the user to determine whether the password entered by the user matches the obtained key port password. If they match, it means that the dual authentication is successful, the whitelist can be updated according to the currently accessed key, and the whitelist mode on the current terminal can be switched from protection mode to audit mode; if they do not match, it means that the dual authentication has failed, the whitelist cannot be updated according to the currently accessed key, and the protection mode is not switched.

[0048] Step 130: Upgrade the service software to be upgraded on the terminal, and add the newly added information generated during the upgrade to the whitelist to update the whitelist.

[0049] If the key port ID to be authenticated matches the legitimate key port ID, the upgrade package is downloaded from the user management center and used for the service software to be upgraded on the terminal. The newly added information generated during the upgrade is added to the whitelist so that the terminal can intercept according to the latest whitelist. In other words, one or more files, link addresses, and external devices newly added to the terminal while the whitelist mode is in audit mode are added to the whitelist to update the whitelist.

[0050] Preferably, after updating the terminal's whitelist according to the whitelist to be updated, the terminal monitors whether the currently connected key port is disconnected. If the currently connected key port is disconnected, indicating that the update operation has been completed and the user has removed the key, the terminal disables the audit mode and re-enables the protection mode, and determines whether to intercept the access object based on the updated whitelist.

[0051] Preferably, when the key port ID to be authenticated does not match the legal key port ID, the terminal generates and outputs an alarm message, prompting the user that the whitelist update has failed, so that the user can re-operate according to the content of the alarm message.

[0052] An embodiment of the present invention provides a whitelist update method that dynamically controls the whitelist to achieve terminal protection by determining whether the key port ID to be authenticated in the key access request matches the legitimate key port ID obtained by the terminal. This verification mode can improve the controllability of the operation of the whitelist protection function, reduce the whitelist protection function being stopped due to improper operation by the user, and thus facilitate users to update the content in the whitelist while ensuring the security of the update.

[0053] Correspondingly, an embodiment of the present application also provides a whitelist updating device for implementing the above steps 110-130. Figure 2 A schematic diagram of the structure of a whitelist updating device provided in an embodiment of the present application is shown as follows: Figure 2 As shown, the whitelist updating device of this embodiment may include:

[0054] The access unit 210, in response to receiving a key access request input by a key port, determines whether the key port ID to be authenticated in the key access request matches the legitimate key port ID obtained by the terminal;

[0055] The processing unit 220 switches the current whitelist mode on the terminal from a protection mode to an audit mode when the key port ID to be authenticated matches the valid key port ID; the protection mode indicates that the whitelist function on the terminal has enabled protection, and the audit mode indicates that the whitelist function on the terminal has suspended protection;

[0056] The upgrading unit 230 upgrades the service software to be upgraded on the terminal, and adds the newly added information generated during the upgrade to the whitelist to update the whitelist.

[0057] Optionally, the whitelist includes: a file whitelist, a link address whitelist and an external device whitelist.

[0058] Optionally, the key port to be authenticated in the key access request is Ukey.

[0059] Optionally, the key access request also includes a password entered by the user;

[0060] When the key port ID to be authenticated matches the legal key port ID, switching the current whitelist mode on the terminal from the protection mode to the audit mode includes:

[0061] If the key port ID to be authenticated matches the legal key port ID, determining whether the password input by the user matches the obtained key port password; the key port password corresponds to the legal key port ID;

[0062] If a match is found, the whitelist mode on the current terminal is switched from protection mode to audit mode.

[0063] Optionally, the device is further used for:

[0064] One or more of the files, link addresses, and external devices newly added by the terminal during the period when the whitelist mode is the audit mode are added to the whitelist to update the whitelist.

[0065] Optionally, the device is further used for:

[0066] Monitor whether the currently connected key port is disconnected;

[0067] If the currently connected key port is disconnected, switch the whitelist mode on the current terminal from audit mode to protection mode to perform protection according to the updated whitelist.

[0068] Optionally, when the key port ID to be authenticated does not match the legal key port ID, the apparatus is further configured to:

[0069] Generate and output alarm information.

[0070] The device of this embodiment can be used to perform Figure 1 The technical solution of the method embodiment shown has similar implementation principles and technical effects, which will not be repeated here.

[0071] Accordingly, the whitelist updating device provided by the embodiment of the present invention may also be implemented using another structure. Figure 3 A schematic diagram of the structure of an electronic device embodiment provided by the present invention can implement the present invention Figure 1 The process of the embodiment shown is as follows: Figure 3 As shown, the electronic device may include: a housing 31, a processor 32, a memory 33, a circuit board 34, and a power supply circuit 35. The circuit board 34 is placed within the space enclosed by the housing 31, and the processor 32 and memory 33 are disposed on the circuit board 34. The power supply circuit 35 is used to supply power to various circuits or components of the electronic device. The memory 33 is used to store executable program code. The processor 32 reads the executable program code stored in the memory 33 to run a program corresponding to the executable program code, thereby executing the method described in the aforementioned embodiment.

[0072] For details on the specific execution process of the above steps by the processor 32 and the steps further executed by the processor 32 by running the executable program code, please refer to the present invention. Figure 1 The description of the illustrated embodiment will not be repeated here.

[0073] This electronic device: a device that provides computing services. The electronic device consists of a processor, hard disk, memory, system bus, etc. The electronic device is similar to the general computer architecture, but because it needs to provide highly reliable services, it has higher requirements in terms of processing power, stability, reliability, security, scalability, manageability, etc.

[0074] It should be noted that, in this document, terms such as "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0075] Each embodiment in this specification is described in a related manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments.

[0076] In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0077] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable storage medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable storage medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0078] More specific examples (a non-exhaustive list) of computer-readable storage media include the following: an electrical connection with one or more wires (electronic device), a portable computer disk cartridge (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable storage medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.

[0079] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware or a combination thereof.

[0080] In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having logic gate circuits for implementing logic functions on data signals, an application-specific integrated circuit having suitable combinational logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0081] Those skilled in the art will understand that all or part of the steps in the method of the above embodiment can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.

[0082] For the convenience of description, the above device is described as being divided into various units / modules based on their functions. Of course, when implementing the present invention, the functions of each unit / module can be implemented in the same or multiple software and / or hardware.

[0083] From the above description of the embodiments, it can be seen that those skilled in the art can clearly understand that the present invention can be implemented by means of software plus the necessary general-purpose hardware platform. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various embodiments of the present invention or certain parts of the embodiments.

Claims

1. A whitelist updating method, characterized in that: Applied to a terminal, the method includes: In response to receiving a key access request input by a key port, determining whether the key port ID to be authenticated in the key access request matches a valid key port ID obtained by the terminal; When the key port ID to be authenticated matches the legal key port ID, the whitelist mode on the terminal is switched from the protection mode to the audit mode; the protection mode indicates that the whitelist function on the terminal has enabled protection, and the audit mode indicates that the whitelist function on the terminal has suspended protection; wherein, the key access request also includes a password input by the user; when the key port ID to be authenticated matches the legal key port ID, the whitelist mode on the terminal is switched from the protection mode to the audit mode, including: when the key port ID to be authenticated matches the legal key port ID, determining whether the password input by the user matches the obtained key port password; the key port password corresponds to the legal key port ID; if they match, the whitelist mode on the terminal is switched from the protection mode to the audit mode; The service software to be upgraded on the terminal is upgraded, and the newly added information generated during the upgrade is added to the whitelist to update the whitelist.

2. The method according to claim 1, characterized in that The whitelist includes: a file whitelist, a link address whitelist and an external device whitelist.

3. The method according to claim 1, characterized in that The key port to be authenticated in the key access request is Ukey.

4. The method according to claim 1, wherein The method further comprises: One or more of the files, link addresses, and external devices newly added by the terminal during the period when the whitelist mode is the audit mode are added to the whitelist to update the whitelist.

5. The method according to any one of claims 1 to 4, characterized in that The method then further comprises: Monitor whether the currently connected key port is disconnected; If the currently connected key port is disconnected, switch the whitelist mode on the current terminal from audit mode to protection mode to perform protection according to the updated whitelist.

6. The method according to claim 1, characterized in that In the case that the key port ID to be authenticated does not match the legal key port ID, the method further includes: Generate and output alarm information.

7. A whitelist updating device, characterized in that: The device comprises: The access unit, in response to receiving a key access request input by the key port, determines whether the key port ID to be authenticated in the key access request matches the legal key port ID obtained by the terminal; The processing unit switches the whitelist mode on the terminal from the protection mode to the audit mode when the key port ID to be authenticated matches the legal key port ID; the protection mode indicates that the whitelist function on the terminal has enabled protection, and the protection mode indicates that the whitelist function on the terminal has suspended protection; wherein the key access request also includes a password input by the user; the switching of the whitelist mode on the terminal from the protection mode to the audit mode when the key port ID to be authenticated matches the legal key port ID includes: when the key port ID to be authenticated matches the legal key port ID, determining whether the password input by the user matches the obtained key port password; the key port password corresponds to the legal key port ID; if they match, switching the whitelist mode on the terminal from the protection mode to the audit mode; The upgrading unit upgrades the service software to be upgraded on the terminal, and adds the newly added information generated during the upgrading to the white list to update the white list.

8. An electronic device, characterized in that: The electronic device includes: a housing, a processor, a memory, a circuit board and a power supply circuit, wherein the circuit board is placed inside the space enclosed by the housing, and the processor and the memory are arranged on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute any method described in claims 1-6.

9. A computer-readable storage medium storing one or more programs, wherein the one or more programs can be executed by one or more processors to implement the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Industrial control white list management system and method based on SGX software protection extension instruction

    CN110222485A

  • Function upgrading and verification method and device based on white list, equipment and medium

    CN114389948A