Access control method and system
By obtaining target information from the controller for authorization when a user accesses a server protected by a firewall, the resource consumption problem in multi-firewall collaboration is solved, and more efficient access control is achieved.
Patent Information
- Application Number
- CN202310091824.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-09
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2043-02-09
AI Technical Summary
In multi-firewall collaboration scenarios, the proactive transmission of user information between firewalls leads to resource consumption and reduces firewall efficiency.
User information is stored in the controller, and when a user accesses a server protected by the firewall, the target firewall obtains the target information from the controller for authorization, thus avoiding the proactive information exchange between firewalls.
It improved the firewall's efficiency, reduced resource waste, and enabled more precise access control.
Smart Images

Figure CN116170195B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of firewalls, in particular to an access control method and system. BACKGROUND
[0002] Enterprises sometimes use devices such as firewalls to control and prevent users (e.g. employees of a company) from accessing unauthorized resources. For example, all users can be prohibited from accessing a particular server or resource. Access can also be granted more granularly, for example, allowing certain users or user groups to access a particular application while prohibiting other users / groups from accessing it. However, with the increasing variety and number of terminal devices, and the increasing variety and number of enterprise application resources, it is difficult to efficiently and accurately authorize users and implement fine-grained policy control, such as Zero Trust Network Access (ZTNA), in enterprise networks using devices such as firewalls.
[0003] In a multi-firewall collaboration scenario, each firewall needs to perform fine-grained access control on users based on relevant information about the users, while also maintaining the efficiency and performance of the firewall. However, in related technologies, firewalls often actively transfer information about all users to share relevant information about the users, so that each firewall can perform effective access control, resulting in excessive resource usage by both the firewall sending the user information and the firewall receiving the user information, thereby reducing the efficiency of the firewall.
[0004] To address the above problems, no effective solutions have been proposed so far. SUMMARY
[0005] Embodiments of the present application provide an access control method and system to at least solve the technical problem of excessive resource usage by firewalls and reduced efficiency of the firewall when multiple firewalls actively transfer user information to each other during access control in related technologies.
[0006] According to an aspect of an embodiment of the present application, an access control system is provided, comprising: a plurality of firewalls, each firewall configured to respond to an access request of a target object to a server protected by the firewall, query a controller for target information of the target object based on the access request, receive the target information fed back by the controller, and perform a first authorization on the target object based on a first authorization rule and the target information, and determine whether to allow the target object to access the server requested to be accessed in the access request based on an authorization result, wherein the authorization result is used to represent whether the first authorization on the target object is successful; and the controller, connected to the plurality of firewalls, configured to store information required for authorization by the plurality of firewalls, respond to the query of the firewall and feed back the target information to the firewall, wherein the information required for authorization includes the target information of the target object.
[0007] Further, the plurality of firewalls comprises a first firewall directly connected with the target terminal held by the target object, and the first firewall collects target information based on a connection request sent by the target terminal before the target firewall responds to the access request of the target object, and sends the target information to the controller, wherein the target firewall is a firewall in the plurality of firewalls.
[0008] Further, the controller collects target information based on a connection request sent by the target terminal held by the target object before the target firewall responds to the access request of the target object, and controls the target terminal to connect with the first firewall, wherein the first firewall is a firewall in the plurality of firewalls for directly connecting with the target terminal, and the target firewall is a firewall in the plurality of firewalls.
[0009] Further, the first firewall responds to an access request sent by the target object to any one of the servers, performs a second authorization on the target object based on a second authorization rule and the target information, and sends the access request to the target firewall if the target object passes the second authorization.
[0010] Further, each firewall inquires the controller whether the target information is updated when receiving a next access request of the target object to a server protected by the firewall, and obtains reply information fed back by the controller, and acquires updated target information from the controller if it is determined based on the reply information that the target information is updated.
[0011] Further, each firewall inquires the controller whether the target information is updated according to a first time period, and obtains reply information fed back by the controller, and acquires updated target information from the controller if it is determined based on the reply information that the target information is updated.
[0012] Further, the controller stores a target relationship table, the target relationship table is used to record at least one second firewall that inquires the controller about the target information, the controller is used to acquire updated target information sent by the target terminal held by the target object, determine at least one second firewall corresponding to the updated target information based on the target relationship table, and send the updated target information to the at least one second firewall.
[0013] According to another aspect of the embodiments of the present application, there is further provided an access control method applied to the access control system as described above, comprising: a target firewall in the plurality of firewalls responding to an access request of a target object to a target server, obtaining target information of the target object from a controller, wherein each firewall in the plurality of firewalls is configured to protect at least one server, the target firewall is configured to protect the target server, and the controller is configured to store information required for authorization of the plurality of firewalls; the target firewall performing first authorization on the target object based on first authorization rules and the target information; and the target firewall allowing the target object to access the target server in a case where the first authorization on the target object is successful.
[0014] Further, the plurality of firewalls comprises a first firewall directly connected with a target terminal held by the target object, and the first firewall, before the target firewall responds to the access request of the target object to the target server, responds to a connection request sent by the target terminal, collects the target information based on the connection request, and sends the target information to the controller.
[0015] Further, the controller, before the target firewall responds to the access request of the target object to the target server, responds to a connection request sent by the target terminal held by the target object, collects the target information based on the connection request, and controls the target terminal to connect with the first firewall, wherein the first firewall is a firewall directly connected with the target terminal.
[0016] Further, the first firewall, before the target firewall responds to the access request of the target object to the target server, responds to the access request, performs second authorization on the target object based on second authorization rules and the target information, and sends the access request to the target firewall if the target object passes the second authorization.
[0017] Further, the access control method further comprises: after the target firewall performs the first authorization on the target object based on the first authorization rules and the target information, the target firewall, in a case where the target firewall receives a next access request of the target object to a server protected by the target firewall, responds to the next access request, inquires the controller whether the target information is updated, and the target firewall, in a case where the target firewall receives feedback information from the controller indicating that the target information is updated, obtains updated target information.
[0018] Further, the access control method further comprises: after the target firewall performs the first authorization on the target object based on the first authorization rules and the target information, the target firewall inquires the controller whether the target information is updated according to a first time period, and the target firewall, in a case where the target firewall receives feedback information from the controller indicating that the target information is updated, obtains updated target information.
[0019] Further, the controller acquires updated target information after the target firewall performs the first authorization on the target object based on the first authorization rule and the target information, determines at least one second firewall corresponding to the updated target information, and sends the updated target information to the at least one second firewall, wherein the at least one second firewall is a firewall that has acquired the target information from the controller.
[0020] According to another aspect of the embodiments of the present application, an access control apparatus is also provided, which comprises: a first acquisition module, configured to acquire target information of a target object from a controller in response to an access request of the target object to a target server, wherein each of a plurality of firewalls is configured to protect at least one server, a target firewall is configured to protect the target server, and the controller is configured to store information required by the plurality of firewalls for authorization; an authentication module, configured to perform a first authorization on the target object based on a first authorization rule and the target information; and a processing module, configured to allow the target object to access the target server in a case where the first authorization on the target object is successful.
[0021] According to another aspect of the embodiments of the present application, a computer readable storage medium is also provided, which stores a computer program, wherein the computer program is configured to execute the access control method when running.
[0022] According to another aspect of the embodiments of the present application, an electronic device is also provided, which comprises one or more processors, and a memory configured to store one or more programs, which, when executed by the one or more processors, cause the one or more processors to implement a program configured to execute the access control method when running.
[0023] In the embodiments of the present application, in the case where a user accesses a server protected by a firewall, the firewall acquires target information of the user, the target firewall of the plurality of firewalls acquires target information of a target object from a controller in response to an access request of the target object to a target server, and then performs a first authorization on the target object based on a first authorization rule and the target information, so as to allow the target object to access the target server in a case where the first authorization on the target object is successful. Wherein each of the plurality of firewalls is configured to protect at least one server, the target firewall is configured to protect the target server, and the controller is configured to store information required by the plurality of firewalls for authorization.
[0024] In the above process, the target firewall for protecting the target server acquires the target information of the target object from the controller only when the target object accesses the target server, avoiding the waste of resources of the firewall sending the related information and the occupation of resources of the other firewall due to the storage of too much unnecessary information in the related art, thereby effectively improving the working efficiency of the firewall.
[0025] Therefore, the scheme provided in the present application achieves the purpose of acquiring the target information of the user only when the user accesses the server protected by the firewall, thereby achieving the technical effect of improving the working efficiency of the firewall, and further solving the technical problem of occupying the resources of the firewall system due to the active transmission of user information between the firewalls in the related art when the access control is performed, thereby reducing the working efficiency of the firewall. BRIEF DESCRIPTION OF DRAWINGS
[0026] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and together with the description serve to explain the application. In the drawings:
[0027] Figure 1 is a schematic diagram of an optional access control system according to an embodiment of the present application;
[0028] Figure 2 is a working schematic diagram of an optional access control system collecting target information according to an embodiment of the present application;
[0029] Figure 3 is a working schematic diagram of an optional access control system collecting target information according to an embodiment of the present application;
[0030] Figure 4 is a working schematic diagram of an optional access control system performing access control according to an embodiment of the present application;
[0031] Figure 5 is a working schematic diagram of an optional access control system synchronously updating the target information according to an embodiment of the present application;
[0032] Figure 6 is a schematic diagram of an optional target relationship table according to an embodiment of the present application;
[0033] Figure 7 is a working schematic diagram of an optional access control system according to an embodiment of the present application;
[0034] Figure 8 is a working schematic diagram of another optional access control system according to an embodiment of the present application;
[0035] Figure 9 is a schematic diagram of an optional access control method according to an embodiment of the present application;
[0036] Figure 10 is a schematic diagram of an optional access control device according to an embodiment of the present application. DETAILED DESCRIPTION
[0037] In order to make the personnel in the art better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should belong to the scope of protection of the present application.
[0038] It should be noted that the terms "first", "second", and the like in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0039] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for display, analyzed data, etc.) involved in the present disclosure are all information and data authorized by the user or authorized by all parties.
[0040] Embodiment 1
[0041] According to an embodiment of the present application, an embodiment of an access control system is provided, Figure 1 is a schematic diagram of an optional access control system according to an embodiment of the present application, as Figure 1 shown, the system comprises:
[0042] The plurality of firewalls are each configured to, in response to an access request of a target object to a server protected by the firewall, inquire the controller for target information of the target object based on the access request, receive the target information fed back by the controller, and perform first authorization on the target object based on a first authorization rule and the target information, and determine whether to allow the target object to access the server requested to be accessed in the access request based on an authorization result, wherein the authorization result is used to represent whether the first authorization on the target object is successful.
[0043] The controller is connected with the plurality of firewalls and is configured to store information required for authorization by the plurality of firewalls, and to respond to the inquiry of the firewalls and feed back the target information to the firewalls, wherein the information required for authorization includes the target information of the target object.
[0044] Optionally, in the embodiment, the plurality of firewalls are configured to protect a plurality of servers, i.e., to perform access control on access requests to the plurality of servers, wherein each firewall is configured to protect at least one server, and the access request is generated and initiated by the target object through a target terminal held by the target object. Figure 1 As shown in Figure 1 , the plurality of firewalls include a firewall A and a firewall B, the firewall A is configured to protect a server A, and the firewall B is configured to protect a server B. Figure 1 As shown in , each firewall in the plurality of firewalls is connected with the controller.
[0045] In the multi-firewall scenario, when a user (i.e., the aforementioned target object) wants to access a resource on a server, the access request of the user is first sent to a firewall for protecting the server. The access request includes a server identifier to be accessed by the user and a username, and the firewall can inquire the controller for target information of the user based on the username in the access request of the user, and then the controller responds to the inquiry of the firewall, finds the corresponding target information based on the username, and feeds back the target information to the firewall. The aforementioned controller is configured to store information required for authorization by the plurality of firewalls, i.e., to store target information of each user, and the target information of each user at least includes the target information of the target object.
[0046] Further, the firewall can receive the target information of the target object fed back by the controller, wherein the target information includes identity information of the target object, device information of a target terminal held by the target object, and a mapping relationship between the identity information and the device information, the identity information includes a username, a group to which the user belongs (e.g., a first group, a second group, etc.), a role type of the user (e.g., a group leader, a group member, etc.), etc., and the device information includes a device IP address, a geographic location, a device number, an operating system, whether an antivirus software is installed, etc.
[0047] In related technologies, the information transmitted between firewalls may only include IP information, and each firewall can only perform access control based on IP information. However, in this application, by sending target information containing the identity information and device information of the target object to the firewall, the firewall can obtain richer information content, thereby enabling more precise access control by adopting a more granular policy for the target object.
[0048] Furthermore, in this embodiment, the firewall only obtains the target information of a user when the user wants to access a server protected by the firewall. For example, if the controller stores the target information of 10,000 users, and only ten of them want to access such a server... Figure 1 The resources on server B shown below, in this case, Figure 1 The firewall B shown only actively queries the controller for the target information of these ten users, thus significantly saving resources on firewall B and ensuring high performance. In related technologies, if... Figure 1 If firewall A, as shown in the diagram, obtains information about 10,000 users, then firewall A will synchronize all of these users' information to... Figure 1 The firewall B shown in the image causes resource consumption on both firewall A and firewall B.
[0049] Furthermore, after the firewall obtains the target information of the target object, it can grant initial authorization to the target object based on the initial authorization rule and the target information to determine whether the target object meets the access conditions to access the target server. Each of the multiple firewalls can store at least one initial authorization rule. The initial authorization rules used by each firewall can be the same or different. In addition, each firewall can use the same initial authorization rule for at least one server it protects, or it can use different initial authorization rules for different servers.
[0050] Furthermore, if the authorization result is one of the following: successful first authorization for the target object or failure of first authorization for the target object, the firewall can determine that the target object has passed the first authorization if the authorization result is successful, and thus send the target object's access request to the server that the access request is to access, and allow the target object to communicate with the server. Conversely, if the authorization result is failed, the firewall can determine that the target object has not passed the first authorization, and thus block the target object's access request to prohibit the target object from accessing the server, thereby achieving access control over the target object.
[0051] It is easily noticed that in the above process, the target information of the target object is obtained from the controller by the firewall for protecting the server in the case that the target object accesses the server, avoiding the waste of a lot of resources of the firewall for sending the related information for sending operation and the occupation of the resources of the other firewall for storing too much unnecessary information in the related art, so as to effectively improve the working efficiency of the firewall.
[0052] Therefore, the scheme provided in the application achieves the purpose that the target information of the user is obtained by the firewall in the case that the user accesses the server protected by the firewall, so as to realize the technical effect of improving the working efficiency of the firewall, and further solve the technical problem of the occupation of the resources of the firewall system caused by the active transmission of the user information between the firewalls in the related art when the access control is performed, and further reduce the working efficiency of the firewall.
[0053] In an optional embodiment, a method for collecting target information is described in the application. Optionally, the first firewall directly connected with the target terminal held by the target object is included in the multiple firewalls, the first firewall collects the target information based on the connection request sent by the target terminal in response to the connection request before the target firewall responds to the access request of the target object, and sends the target information to the controller, wherein the target firewall is the firewall in the multiple firewalls.
[0054] It is to be noted that multiple first firewalls can exist in the multiple firewalls, and different first firewalls can be connected with different target terminals held by different target objects. Specifically, when the target terminal held by the user is powered on, the target terminal will automatically send a connection request to a certain firewall in the multiple firewalls according to a preset connection rule to connect the firewall. In this embodiment, the target terminal held by the user is directly connected with the firewall A in the multiple firewalls, that is, the firewall A in the multiple firewalls is equivalent to the first firewall. Figure 2 is a working schematic diagram of an optional access control system for collecting target information according to an embodiment of the application, as shown in Figure 2 the target terminal is directly and automatically connected with the firewall A in the multiple firewalls, that is, the firewall A in the multiple firewalls is equivalent to the first firewall. Figure 2 Figure 2
[0055] Further, the login information of the user is included in the connection request, the login information includes a username and a password of the user, the target terminal can determine the login information sent to the firewall according to the preset information of the user before sending the connection request to the first firewall, or can request the user to provide the corresponding login information before sending the connection request to the first firewall. When the first firewall obtains the connection request, the first firewall can perform identity authentication on the user based on the login information in the connection request. If the username and the password match, it is determined that the identity authentication is successful. If the username and the password do not match, it is determined that the identity authentication fails.
[0056] Further, after the identity authentication is successful, the first firewall can query identity information corresponding to the username from a preset database according to the username, and simultaneously sends a request for obtaining device information to the target terminal to obtain the device information sent by the target terminal, and establishes a mapping relationship between the identity information and the device information after obtaining the device information, so as to realize collection of the target information corresponding to the user. The database stores the correspondence between the username and the identity information, which can be created by a staff in advance.
[0057] Optionally, after the first firewall completes the collection of the target information of the user, the first firewall can send the target information to a controller for storage, so as to facilitate other firewalls to obtain the target information of the user subsequently. Figure 2 As shown in the figure, the first firewall can send the target information to a controller for storage, so as to facilitate other firewalls to obtain the target information of the user subsequently.
[0058] It should be noted that the target information is collected by the first firewall when the connection request sent by the target terminal held by the target object is obtained, which realizes the advance acquisition of the target information, thereby improving the efficiency of the access control of the firewall on the target object when the target object actually accesses the server.
[0059] In an optional embodiment, another method for collecting target information is described. Optionally, the controller responds to the connection request sent by the target terminal held by the target object before the target firewall responds to the access request of the target object, collects the target information based on the connection request, and controls the target terminal to connect with the first firewall, wherein the first firewall is a firewall in the plurality of firewalls for directly connecting with the target terminal, and the target firewall is a firewall in the plurality of firewalls.
[0060] Specifically, Figure 3 is a working schematic diagram of another optional access control system for collecting target information according to an embodiment of the application. When the target terminal held by the user is powered on, the target terminal sends a connection request to the first firewall,Figure 3 As shown by the No. 1 connection line in FIG. 6, the target terminal automatically sends a connection request to the controller to connect to the controller. The connection request includes login information of the user, and the login information includes a username and a password of the user. Before sending the connection request to the controller, the target terminal can determine the login information to be sent to the controller according to preset information of the user, or the target terminal can request the user to provide the corresponding login information before sending the connection request to the controller. After the controller obtains the connection request, the controller can perform identity authentication on the user based on the login information in the connection request. If the username and the password match, it is determined that the identity authentication is successful. If the username and the password do not match, it is determined that the identity authentication fails.
[0061] Further, after the identity authentication is successful, the controller can query identity information corresponding to the username from a preset database according to the username, and send a request for obtaining device information to the target terminal to obtain the device information sent by the target terminal. After obtaining the device information, the controller establishes a mapping relationship between the identity information and the device information, so as to collect the target information corresponding to the user. The database stores a correspondence between the username and the identity information, and the correspondence can be created by a staff in advance.
[0062] Further, after the controller completes the collection of the target information of the user, the controller can control the target terminal to be connected to a firewall in the plurality of firewalls based on a preset connection rule. In this embodiment, as shown by the No. 2 connection line in FIG. 6, after the controller completes the collection of the target information of the user, the controller controls the target terminal to be connected to the firewall A, that is, the firewall A corresponds to the first firewall. Figure 3 As shown by the No. 2 connection line in FIG. 6, after the controller completes the collection of the target information of the user, the controller controls the target terminal to be connected to the firewall A, that is, the firewall A corresponds to the first firewall. During the process in which the controller controls the target terminal to be connected to the first firewall, the controller can send login information of the target terminal to the first firewall to realize login of the target object at the first firewall.
[0063] It should be noted that the controller collects the target information when obtaining the connection request sent by the target terminal held by the target object, so that the target information is obtained in advance, thereby improving the efficiency of access control of the target object by the firewall when the target object actually accesses the server.
[0064] In an optional embodiment, the working process of the first firewall when the user accesses the server is described. Optionally, the first firewall responds to an access request for any one of the servers sent by the target object, performs second authorization on the target object based on the second authorization rule and the target information, and sends the access request to the target firewall if the target object passes the second authorization.
[0065] Optionally, Figure 4is a working schematic diagram of access control performed by an optional access control system according to an embodiment of the present application. When a target object sends an access request for any one of the servers through a target terminal, for example, as shown by the dashed line path in Figure 4 , when a user sends an access request for server B through a target terminal, a first firewall (i.e., firewall A in Figure 4 ) directly connected to the target terminal in the access control system will first obtain the access request sent by the target object. Then, the first firewall queries the corresponding target information from the controller based on the username in the access request, and then performs second authorization on the target object based on the second authorization rule and the target information, to realize initial authorization of the target object. The second authorization rule is different from the first authorization rule, and at least one second authorization rule can be preset in each firewall. When a firewall becomes the first firewall, it can use the second authorization rule to perform second authorization. The second authorization rules preset in each firewall can be the same or different. The firewall can authorize the target information corresponding to the access request for accessing all servers based on one second authorization rule, or the firewall can authorize the target information corresponding to the access request for accessing different servers based on different second authorization rules.
[0066] Further, if the first firewall determines that the target object passes the second authorization, the first firewall can send the access request to the firewall corresponding to the server requested to be accessed in the access request (i.e., the target firewall), as shown by the dashed line path in Figure 4 . Firewall A sends the access request to firewall B corresponding to server B in the case of successful second authorization.
[0067] Optionally, as shown in Figure 4 , after obtaining the access request, the target firewall (i.e., firewall B in Figure 4 ) queries the corresponding target information from the controller, obtains the target information fed back by the controller, and performs first authorization on the target object based on the first authorization rule and the target information, so as to send the access request to server B in the case of successful first authorization. If the first firewall is the same as the firewall corresponding to the server requested to be accessed in the access request, the first firewall can automatically perform first authorization after successful second authorization.
[0068] It should be noted that by performing double authorization on the target object based on the first firewall and the firewall for protecting the server accessed by the target object, more accurate access control of the access request of the target object is realized, thereby improving the accuracy of access control.
[0069] In an alternative embodiment, a method for synchronizing updated target information is described. In response to a next access request from a target object to a server protected by the firewall, each firewall can query the controller to determine whether the target information has been updated, and obtain feedback information from the controller. If the feedback information indicates that the target information has been updated, the updated target information can be obtained from the controller.
[0070] Alternatively, when the user's identity information or the device information of the target terminal held by the user changes, for example, the antivirus software expires, the target terminal can actively upload the changed information to the first firewall, and then send the changed information to the controller. Alternatively, the target terminal can actively send the changed information directly to the controller. Alternatively, the target terminal can upload the changed identity information to the preset database, and upload the changed device information to the controller, and then the preset database can transmit the changed identity information to the controller. In this way, the updated target information can be stored in the controller in real time.
[0071] Further, Figure 5 is a working schematic diagram of an alternative access control system for synchronizing updated target information according to an embodiment of the present application, as shown in Figure 5 In response to a next access request from a target object to a server protected by the firewall, each firewall can query the controller to determine whether the target information has been updated, and obtain feedback information from the controller. If the feedback information indicates that the target information has been updated, the updated target information can be obtained from the controller.
[0072] It should be noted that by querying the controller to determine whether the target information has been updated after obtaining a next access request from a target object, the dynamic synchronization between the firewall and the target information of the user is ensured when the target information changes, and the problem of low accuracy of access control caused by the firewall using historical target information for authorization is avoided.
[0073] In an alternative embodiment, when the first firewall receives a next access request from a target object to any server, the first firewall can query the controller to determine whether the target information of the user has been updated, and obtain feedback information from the controller. If the feedback information indicates that the target information of the user has been updated, the updated target information can be obtained from the controller. In this way, the dynamic synchronization between the first firewall and the target information of the user is ensured.
[0074] In an alternative embodiment, the method for synchronizing the updated target information is described. Alternatively, each firewall inquires the controller whether the target information is updated according to a first time period, and obtains the reply information fed back by the controller. In the case that the target information is determined to be updated based on the reply information, the updated target information is obtained from the controller.
[0075] Alternatively, when the identity information of the user or the device information of the target terminal held by the user is changed, for example, the antivirus software is found to be expired, the target terminal can actively upload the changed information to the first firewall, and then send the changed information to the controller through the first firewall. Alternatively, the target terminal can actively send the changed information to the controller directly. Alternatively, the target terminal can upload the changed identity information to the preset database, and upload the changed device information to the controller. Then, the changed identity information is transmitted to the controller by the preset database. In this way, the updated target information can be stored in the controller in real time.
[0076] Further, as shown in Figure 5 each firewall can inquire the controller whether the target information of the target object stored in the firewall is updated according to a first time period, so that the updated target information is obtained from the controller after the controller feeds back the information indicating that the target information of the target object is updated.
[0077] It should be noted that the firewall inquires the controller whether the target information of the target object is updated, which ensures that the target information is dynamically synchronized between the firewall and the user when the target information is changed, and avoids the problem of low accuracy of access control caused by the authorization of the firewall based on the historical target information.
[0078] In an alternative embodiment, the method for synchronizing the updated target information is described. Alternatively, each firewall inquires the controller whether the target information is updated according to a first time period, and obtains the reply information fed back by the controller. In the case that the target information is determined to be updated based on the reply information, the updated target information is obtained from the controller.
[0079] Optionally, when the identity information of the user or the device information of the target terminal held by the user changes, for example, it is found that the antivirus software is expired, etc., the target terminal can actively upload the changed information to the first firewall, and then send the changed information to the controller through the first firewall, or the target terminal can also actively send the changed information directly to the controller, or the target terminal can also upload the changed identity information to the preset database and upload the changed device information to the controller, and then the preset database transmits the changed identity information to the controller again. Real-time storage of updated target information in the controller is realized.
[0080] Optionally, Figure 6 is an optional target relationship table according to an embodiment of the present application, as shown in Figure 6 The target relationship table can store the target information corresponding to each target object uploaded by each firewall (such as the username, IP address, device number, etc. shown in Figure 6 ), and the target information corresponding to each target object is inquired by which firewall. When the controller obtains the updated target information corresponding to a target object, the controller can actively push the updated target information to all other firewalls (that is, at least one second firewall) that have inquired the target information corresponding to the target object, thereby realizing dynamic synchronization of the updated target information and avoiding the problem of low access control accuracy caused by authorization by the firewall based on historical target information.
[0081] Optionally, for the application scenario in which the target terminal is directly connected to the firewall, an embodiment of the present application is described. As shown in Figure 1 In the case of multiple firewalls, the user first connects to firewall A, at this time, firewall A first performs identity authentication on the user, and collects target information in the case of successful identity authentication, and then firewall A uploads the collected target information to the controller. After that, when the user wants to access the resources on server B behind firewall B, the access request of the user reaches firewall B through firewall A, firewall B actively inquires the target information of the user from the controller, and obtains the target information sent by the controller, so as to complete fine control of the access right of the user based on the obtained target information. In the process of the access request of the user reaching firewall B through firewall A, firewall A can authorize the access request, and send the access request to firewall B after authorization, or firewall A can directly forward the access request without authorization.
[0082] Optionally, for the application scenario in which the target terminal is directly connected to the controller, an embodiment of the present application is described. Figure 7 is an optional working schematic diagram of an access control system according to an embodiment of the present application, as shown inFigure 7 As shown in connection number 1, the user first connects to the controller. The controller then authenticates the user and, if authentication is successful, collects target information, and then proceeds as follows: Figure 7 As shown in line 2, the target terminal held by the control user is connected to firewall A. When the user wants to access resources on server A behind firewall A, the user's access request reaches firewall A. Firewall A actively queries the controller for the user's target information and obtains the target information sent by the controller, thereby completing fine-grained control over the user's access permissions based on the obtained target information.
[0083] Optionally, one implementation method of this embodiment will be described for application scenarios where the target terminal is directly connected to the cloud access point. Figure 8 This is a schematic diagram of the operation of another optional access control system according to an embodiment of the present invention, such as... Figure 8 As shown, when there are multiple access points in the cloud (such as...) Figure 8 The diagram shows access points A, B, and C. Multiple access points form a distributed firewall in the cloud, which can be viewed as firewall A. In this scenario, users first connect directly to the nearest cloud access point A. Upon connection, access point A authenticates the user and, if authentication is successful, collects target information and sends it to the controller. Later, when a user wants to access resources on server B behind firewall B (connected to access point C), the user's access request passes through access points A and C to reach firewall B. Firewall B proactively queries the controller for the user's target information and obtains the target information sent by the controller, thereby enabling fine-grained control over user access permissions based on the obtained target information. Firewall B proactively queries the controller for the user's information.
[0084] Therefore, the solution provided in this application achieves the goal of obtaining the user's target information only when the user accesses the server protected by the firewall, thereby improving the working efficiency of the firewall. It also solves the technical problem in related technologies where multiple firewalls actively transmit user information to each other during access control, which causes the firewall system resources to be occupied and thus reduces the working efficiency of the firewall.
[0085] Example 2
[0086] According to an embodiment of the present invention, an embodiment of an access control method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0087] Figure 9 is a schematic diagram of an optional access control method according to an embodiment of the present application, as Figure 9 shown, the method is applied to the access control system described above, and comprises the following steps:
[0088] In step S901, a target firewall of a plurality of firewalls acquires target information of a target object from a controller in response to an access request of the target object to a target server, wherein each firewall of the plurality of firewalls is configured to protect at least one server, the target firewall is configured to protect the target server, and the controller is configured to store information required for authorization of the plurality of firewalls.
[0089] Optionally, in the embodiment, the access control method described above is executed by a target firewall in the access control system, and the target firewall is any one of the plurality of firewalls. In the embodiment, a plurality of firewalls are configured to protect a plurality of servers, i.e., to perform access control on access requests to the plurality of servers, wherein each firewall is configured to protect at least one server, and the access request is generated and initiated by a target object through a target terminal held by the target object. As Figure 1 shown, in Figure 1 , the plurality of firewalls include firewall A and firewall B, the firewall A is configured to protect server A, and the firewall B is configured to protect server B. As Figure 1 shown, each firewall of the plurality of firewalls is connected to the controller.
[0090] In the multi-firewall scenario, when a user (i.e., the target object described above) wants to access resources on a server, the access request of the user is first sent to a firewall configured to protect the server. The access request contains the server identifier to be accessed by the user and the username. In the embodiment, the target firewall can query the target information of the user from the controller based on the username in the access request of the user, and then receive the target information of the target object fed back by the controller. The controller is configured to store information required for authorization of the plurality of firewalls, i.e., to store target information of each user, and the target information of each user at least contains the target information of the target object. The target information includes identity information of the target object, device information of a target terminal held by the target object, and a mapping relationship between the identity information and the device information. The identity information includes a username, a group to which the user belongs (e.g., a first group, a second group, etc.), a role type of the user (e.g., a group leader, a group member, etc.), etc. The device information includes a device IP address, a geographic location, a device number, an operating system, whether an antivirus software is installed, etc.
[0091] In the related art, the information transmitted between the firewalls can only include IP information, and the firewalls can only perform access control based on the IP information. In this application, the target information including the identity information and the device information of the target object is sent to the firewall, so that the firewall can obtain more abundant information content, and more accurate access control is realized by using a more fine-grained strategy on the target object.
[0092] It should be noted that the target firewall for protecting the target server obtains the target information of the target object from the controller only in the case that the target object accesses the target server, which avoids the waste of resources of the firewall sending the related information in the related art, and the occupation of resources of the other firewalls due to the storage of too much unnecessary information, thereby effectively improving the working efficiency of the firewall.
[0093] In step S902, the target firewall performs first authorization on the target object based on the first authorization rule and the target information.
[0094] In step S902, after the target firewall obtains the target information of the user, the target firewall can perform first authorization on the target object based on the first authorization rule and the target information, to determine whether the target object meets the access condition of accessing the target server. Each firewall in the multiple firewalls can store at least one first authorization rule, and the first authorization rules used by each firewall in the multiple firewalls can be the same or different. In addition, each firewall can use the same first authorization rule to protect at least one server, or use different first authorization rules to protect different servers.
[0095] In step S903, the target firewall allows the target object to access the target server in the case that the first authorization on the target object is successful.
[0096] In step S903, the target firewall can determine that the target object passes the first authorization in the case that the first authorization on the target object is successful, so as to send the access request of the target object to the target server, and allow the target object to communicate with the target server. Otherwise, the target firewall determines that the target object fails to pass the first authorization in the case that the first authorization on the target object fails, so as to intercept the access request of the target object, to prohibit the target object from accessing the target server, thereby realizing the access control on the target object.
[0097] Based on the scheme defined in steps S901 to S903, it can be known that, in the embodiment of the application, the target firewall in the multiple firewalls acquires the target information of the target object from the controller in response to the access request of the target object to the target server, and then performs the first authorization on the target object based on the first authorization rule and the target information, so as to allow the target object to access the target server in the case that the first authorization on the target object is successful. Each firewall in the multiple firewalls is used to protect at least one server, the target firewall is used to protect the target server, and the controller is used to store information required by the multiple firewalls for authorization.
[0098] It is easy to note that, in the above process, the target firewall for protecting the target server acquires the target information of the target object from the controller only in the case that the target object accesses the target server, which avoids the waste of a large amount of resources of the firewall for sending the related information and the occupation of resources of the other firewalls for receiving the related information due to the active transmission of the related information of each object by a certain firewall in the multiple firewalls to the other firewalls, and thus the working efficiency of the firewall can be effectively improved.
[0099] Therefore, the scheme provided in the application achieves the purpose that the firewall acquires the target information of the user only in the case that the user accesses the server protected by the firewall, thereby achieving the technical effect of improving the working efficiency of the firewall, and further solving the technical problem that the occupation of the resources of the firewall system caused by the active transmission of the user information between the firewalls in the related art reduces the working efficiency of the firewall.
[0100] In an optional embodiment, a method for collecting target information is described. Optionally, the multiple firewalls include a first firewall directly connected with a target terminal held by the target object, and the first firewall collects the target information based on a connection request sent by the target terminal before the target firewall responds to the access request of the target object to the target server, and sends the target information to the controller.
[0101] Among the multiple firewalls, there is a first firewall that is directly connected to the target terminal held by the target object. It should be noted that there can be multiple first firewalls among the multiple firewalls, and different first firewalls can connect to different target terminals held by the target object. Specifically, when the target terminal held by the user is powered on, the target terminal will automatically send a connection request to one of the multiple firewalls according to preset connection rules to connect to that firewall. In this embodiment, for example... Figure 2 As shown, the target terminal connects directly and automatically. Figure 2 Firewall A in the middle, i.e. Figure 2 Firewall A in the text is equivalent to the first firewall mentioned above.
[0102] Furthermore, the connection request includes the user's login information, which includes the user's username and password. The target terminal can determine the login information to send to the first firewall based on the user's preset information before sending the connection request, or it can request the user to provide the corresponding login information before sending the connection request to the firewall. When the first firewall receives the connection request, it can authenticate the user based on the login information in the connection request. If the username and password match, authentication is successful; if they do not match, authentication fails.
[0103] Furthermore, after successful authentication, the first firewall can retrieve the corresponding identity information from a pre-set database based on the username. Simultaneously, it sends a device information retrieval request to the target terminal to obtain the device information sent by the target terminal. After obtaining the device information, it establishes a mapping relationship between identity information and device information, thereby achieving the collection of target information corresponding to the user. The aforementioned database stores the mapping relationship between usernames and identity information, which can be pre-created by staff.
[0104] Optionally, after the first firewall completes the collection of the user's target information, such as Figure 2 As shown, the first firewall (i.e. Figure 2 Firewall A) can send target information to the controller for storage, facilitating subsequent acquisition of the user's target information by other firewalls. Furthermore, after sending the collected target information to the controller, the first firewall can also delete the user's target information stored within itself to reduce resource consumption.
[0105] It should be noted that by collecting target information when the first firewall receives a connection request from the target terminal held by the target object, the firewall can obtain the target information in advance, thereby improving the efficiency of the firewall's access control over the target object when the target object actually accesses the server.
[0106] In an optional embodiment, another method for collecting target information in this application is described. Optionally, before the target firewall responds to the target object's access request to the target server, the controller responds to the connection request sent by the target terminal held by the target object, collects target information based on the connection request, and controls the target terminal to connect to the first firewall, wherein the first firewall is a firewall for direct connection with the target terminal.
[0107] Specifically, when the target terminal held by the user is powered on, such as Figure 3 As shown in connection line 1, the target terminal automatically sends a connection request to the controller to connect. The connection request includes the user's login information, including the username and password. The target terminal can determine the login information to send to the controller based on preset user information before sending the connection request, or it can request the user to provide the corresponding login information before sending the connection request. Once the controller receives the connection request, it can authenticate the user based on the login information in the connection request. If the username and password match, authentication is successful; if they do not match, authentication fails.
[0108] Furthermore, after successful authentication, the controller can retrieve the corresponding identity information from a pre-set database based on the username. Simultaneously, it sends a device information retrieval request to the target terminal to obtain the device information sent by the target terminal. After obtaining the device information, a mapping relationship between the identity information and the device information is established, thereby achieving the collection of target information corresponding to the user. The aforementioned database stores the mapping relationship between usernames and identity information, which can be pre-created by staff.
[0109] Furthermore, after the controller completes the collection of the user's target information, it can control the target terminal to connect to one of multiple firewalls based on preset connection rules. In this embodiment, for example... Figure 3 As shown by connection number 2, after the controller completes the collection of the user's target information, the controller controls the target terminal to connect to firewall A, meaning firewall A is equivalent to the aforementioned first firewall. During the process of the controller controlling the connection between the target terminal and the first firewall, the controller can send the target terminal's login information to the first firewall to enable the target to log in at the first firewall.
[0110] It should be noted that the target information is collected by the controller when the connection request sent by the target terminal held by the target object is acquired, so that the target information is acquired in advance, and thus the efficiency of the access control of the target object by the firewall when the target object actually accesses the server can be improved.
[0111] In an optional embodiment, the working process of the first firewall when the user accesses the server is described. Optionally, the first firewall responds to the access request before the target firewall responds to the access request of the target object to the target server, performs the second authorization on the target object based on the second authorization rule and the target information, and if the target object passes the second authorization, sends the access request to the target firewall.
[0112] Optionally, when the target object sends an access request to any one of the servers through the target terminal, for example, as shown by the dashed line path in Figure 4 , when the user sends an access request to the server B through the target terminal, the first firewall (i.e., the firewall A in Figure 4 ) directly connected to the target terminal in the access control system acquires the access request sent by the target object first. Then, the first firewall queries the corresponding target information from the controller based on the username in the access request, and then performs the second authorization on the target object based on the second authorization rule and the target information, so as to realize the initial authorization of the target object. The second authorization rule is different from the first authorization rule, and at least one second authorization rule can be preset in each firewall. When a firewall becomes the first firewall, the second authorization rule can be used for the second authorization. The second authorization rules preset in each firewall can be the same or different. The firewall can authorize the target information corresponding to the access request for accessing all servers based on one second authorization rule, or the firewall can authorize the target information corresponding to the access request for accessing different servers based on different second authorization rules.
[0113] Further, if the first firewall determines that the target object passes the second authorization, the first firewall can send the access request to the firewall corresponding to the server requested to be accessed in the access request (i.e., the target firewall described above), for example, as shown by the dashed line path in Figure 4 , the firewall A sends the access request to the firewall B corresponding to the server B in the case that the second authorization is successful.
[0114] Optionally, as shown in Figure 4 , the target firewall (i.e., the firewall B in Figure 4Firewall B, upon receiving an access request, queries the controller for the corresponding target information, obtains the target information returned by the controller, and performs first authorization on the target object based on the first authorization rule and the target information. If the first authorization is successful, the access request is sent to server B. If the first firewall is the same as the firewall corresponding to the server requested in the access request, then the first firewall can automatically perform the first authorization after the second authorization is successful.
[0115] It should be noted that by performing dual authorization on the target object based on the first firewall and the firewall of the server used to protect the target object's access, more precise access control of the target object's access requests is achieved, thereby improving the accuracy of access control.
[0116] In an optional embodiment, a method for synchronizing updated target information according to this application is described. Optionally, after the target firewall performs a first authorization on the target object based on the first authorization rule and the target information, when the target firewall receives the next access request from the target object to the server protected by the firewall, it responds to the next access request by querying the controller whether the target information has been updated, and thus, upon receiving information from the controller indicating that the target information has been updated, it obtains the updated target information.
[0117] Optionally, when a user's identity information or the device information of the target terminal held by the user changes—for example, when antivirus software is found to be expired—the target terminal can proactively upload the changed information to the first firewall, which then sends it to the controller. Alternatively, the target terminal can proactively send the changed information directly to the controller. Or, the target terminal can upload the changed identity information to the aforementioned preset database and the changed device information to the controller, which then transmits the changed identity information back to the controller. This allows the controller to store updated target information in real time.
[0118] Furthermore, such as Figure 5 As shown, the target firewall (i.e. Figure 5 Firewall B in the configuration can respond to a user's next access request to the server protected by the firewall, and proactively inquire with the controller whether the user's target information has been updated. After the controller reports an update indicating that the user's target information has been updated, the firewall can retrieve the updated target information from the controller. The firewall protected by the target firewall includes at least the target server.
[0119] It should be noted that the target firewall inquires the controller whether the target information of the target object is updated after obtaining the next access request of the target object, so that the dynamic synchronization between the target firewall and the target information of the user is ensured when the target information is changed, and the problem of low access control accuracy caused by the authorization of the target firewall based on the historical target information is avoided.
[0120] In an optional embodiment, when the target object sends a next access request to any one of the servers, the first firewall can respond to the next access request of the target object to the server and actively inquire the controller whether the target information of the user is updated, so that the updated target information is obtained from the controller after the controller feeds back the information indicating that the target information of the user is updated. Therefore, the dynamic synchronization between the first firewall and the target information of the user is ensured.
[0121] In an optional embodiment, the synchronization method of the updated target information in another embodiment of the application is described. Optionally, after the target firewall performs the first authorization on the target object based on the first authorization rule and the target information, the target firewall inquires the controller whether the target information is updated according to the first time period, so that the updated target information is obtained when the controller feeds back the information indicating that the target information is updated.
[0122] Optionally, when the identity information of the user or the device information of the target terminal held by the user is changed, for example, the antivirus software is found to be expired, the target terminal can actively upload the changed information to the first firewall, and then send the changed information to the controller through the first firewall, or the target terminal can actively send the changed information to the controller, or the target terminal can upload the changed identity information to the preset database and upload the changed device information to the controller, and then the preset database transmits the changed identity information to the controller again. The real-time storage of the updated target information in the controller is realized.
[0123] Further, as shown in Figure 5 the target firewall can inquire the controller whether the target information of the target object stored in the firewall is updated according to the first time period, so that the updated target information is obtained from the controller after the controller feeds back the information indicating that the target information of the target object is updated.
[0124] It should be noted that the target firewall inquires the controller whether the target information of the target object is updated according to the first time period, so that the dynamic synchronization between the target firewall and the target information of the user is ensured when the target information is changed, and the problem of low access control accuracy caused by the authorization of the target firewall based on the historical target information is avoided.
[0125] In an alternative embodiment, a method for synchronizing updated target information is described. After the target firewall performs the first authorization on the target object based on the first authorization rule and the target information, the controller obtains the updated target information, determines at least one second firewall corresponding to the updated target information, and sends the updated target information to the at least one second firewall, wherein the at least one second firewall is the firewall that has obtained the target information from the controller.
[0126] Optionally, when the identity information of the user or the device information of the target terminal held by the user changes, for example, the antivirus software is found to be expired, the target terminal can actively upload the changed information to the first firewall, and then send the changed information to the controller through the first firewall, or the target terminal can actively send the changed information directly to the controller, or the target terminal can upload the changed identity information to the preset database and upload the changed device information to the controller, and then the preset database transmits the changed identity information to the controller. In this way, the updated target information can be stored in the controller in real time.
[0127] Optionally, the controller stores a target relationship table, which is used to record at least one second firewall that has inquired the target information from the controller, as shown in Figure 6 The target relationship table can store the target information corresponding to each target object uploaded by each firewall (for example, the username, IP address, and device number shown in Figure 6 ), and the target information corresponding to each target object has been inquired by which firewalls (not shown in Figure 6 ). After the controller obtains the updated target information corresponding to a target object, the controller can actively push the updated target information to all other firewalls (that is, the at least one second firewall) that have inquired the target information corresponding to the target object, thereby achieving dynamic synchronization of the updated target information and avoiding the problem of low accuracy of access control caused by authorization of the firewall based on historical target information.
[0128] Optionally, for the application scenario in which the target terminal is directly connected to the firewall, an embodiment of the present embodiment is described. As shown in Figure 1As shown, in the multi-firewall case, the user first connects to firewall A, at this time, firewall A first performs identity authentication on the user, and collects target information in the case of successful identity authentication, and then firewall A uploads the collected target information to the controller. After that, when the user wants to access the resources on server B behind firewall B, the user's access request reaches firewall B through firewall A, firewall B actively inquires the target information of the user from the controller, and obtains the target information sent by the controller, so as to complete the fine control of the access right of the user based on the obtained target information. Wherein, in the process of the access request of the user reaching firewall B through firewall A, firewall A can authorize the access request, and send the access request to firewall B after authorization, or firewall A can directly forward the access request without authorization.
[0129] Optionally, for the application scenario that the target terminal is directly connected with the controller, an embodiment of the present embodiment is described. As shown in No. 1 connection line in Figure 7 , the user first connects to the controller, the controller first performs identity authentication on the user, and collects target information in the case of successful identity authentication, and then as shown in No. 2 connection line in Figure 7 , the target terminal held by the user is connected with firewall A. When the user wants to access the resources on server A behind firewall A, the access request of the user reaches firewall A, firewall A actively inquires the target information of the user from the controller, and obtains the target information sent by the controller, so as to complete the fine control of the access right of the user based on the obtained target information.
[0130] Optionally, for the application scenario that the target terminal is directly connected with the cloud access point, an embodiment of the present embodiment is described. As shown in Figure 8 , when there are multiple access points on the cloud (such as access point A, access point B, and access point C shown in Figure 8 ), the multiple access points form a cloud distributed firewall, which can be regarded as firewall A as a whole. In this case, the user first directly connects to the cloud access point A nearby, when the user connects to the access point A, the access point A first performs identity authentication on the user, and collects target information in the case of successful identity authentication, and then uploads the target information to the controller. After that, when the user wants to access the resources on server B behind firewall B connected with access point C, the access request of the user reaches firewall B through access point A and access point C, firewall B actively inquires the target information of the user from the controller, and obtains the target information sent by the controller, so as to complete the fine control of the access right of the user based on the obtained target information. Firewall B actively inquires the user from the controller.
[0131] Therefore, the scheme provided in the application achieves the purpose that the target information of the user is acquired by the firewall only when the user accesses the server protected by the firewall, thereby achieving the technical effect of improving the working efficiency of the firewall, and further solving the technical problem that the firewall system resources are occupied due to the active transmission of user information between the firewalls when the multiple firewalls perform access control, thereby reducing the working efficiency of the firewall.
[0132] Embodiment 3
[0133] According to the embodiment of the application, an embodiment of an access control device is provided, wherein, Figure 10 is a schematic diagram of an optional access control device according to the embodiment of the application, as Figure 10 shown, the device comprises:
[0134] The first acquisition module 1001 is configured to acquire target information of a target object from a controller in response to an access request of the target object to a target server, wherein each of the multiple firewalls is configured to protect at least one server, the target firewall is configured to protect the target server, and the controller is configured to store information required by the multiple firewalls for authorization.
[0135] The authentication module 1002 is configured to perform first authorization on the target object based on the first authorization rule and the target information.
[0136] The processing module 1003 is configured to allow the target object to access the target server in a case where the first authorization on the target object is successful.
[0137] Optionally, the access control device can be the target firewall as described above, that is, the target firewall can comprise the first acquisition module, the authentication module and the processing module. In this embodiment, multiple firewalls are configured to protect multiple servers, that is, to perform access control on access requests for accessing the multiple servers, wherein each of the firewalls is configured to protect at least one server, and the access request is generated and initiated by the target object through a target terminal held by the target object. As Figure 1 shown, in Figure 1 , the multiple firewalls comprise a firewall A and a firewall B, the firewall A is configured to protect a server A, and the firewall B is configured to protect a server B. As Figure 1 shown, each of the multiple firewalls is connected to the controller.
[0138] In the multi-firewall scenario, when a user (i.e., the aforementioned target object) wants to access a resource on a server, the user's access request is first sent to the firewall for protecting the server. The access request contains the server identifier to be accessed by the user and the username. In this embodiment, the target firewall can query the controller for the target information of the user based on the username in the user's access request, and then receive the target information of the target object fed back by the controller. The aforementioned controller is used to store information required by multiple firewalls for authorization, i.e., to store the target information of each user, and the target information of each user at least contains the target information of the target object. The target information includes the identity information of the target object, the device information of the target terminal held by the target object, and the mapping relationship between the aforementioned identity information and device information. The aforementioned identity information includes the username, the group to which the user belongs (e.g., the first group, the second group, etc.), the role type of the user (e.g., the group leader, the group member, etc.), etc. The aforementioned device information includes the device IP address, the geographic location, the device number, the operating system, whether there is an installed antivirus software, etc.
[0139] In the related art, the information transmitted between the firewalls can only include IP information, and the firewalls can only perform access control based on the IP information. In this application, by sending the target information containing the identity information and the device information of the target object to the firewall, the firewall can obtain more abundant information content, thereby realizing more accurate access control on the target object by using a more fine-grained strategy.
[0140] It should be noted that the target firewall for protecting the target server obtains the target information of the target object from the controller only in the case where the target object accesses the target server, thereby avoiding the waste of resources of the firewall sending the related information in the related art, in which a firewall in multiple firewalls actively transmits the related information of each object to other firewalls after obtaining the related information of each object, and the other firewalls occupy resources due to storing too much unnecessary information, thereby effectively improving the working efficiency of the firewall.
[0141] After the authentication module obtains the target information of the user, the authentication module can perform first authorization on the target object based on the first authorization rule and the target information to determine whether the target object meets the access condition for accessing the target server. Each firewall in the multiple firewalls can store at least one first authorization rule, and the first authorization rule adopted by each firewall in the multiple firewalls can be the same or different. In addition, each firewall can adopt the same first authorization rule for at least one server protected by the firewall, or different first authorization rules for different servers.
[0142] Further, the processing module can determine that the target object passes the first authorization in a case that the first authorization of the target object succeeds, and thus send the access request of the target object to the target server and allow information communication between the target object and the target server. Otherwise, the processing module can determine that the target object fails to pass the first authorization in a case that the first authorization of the target object fails, and thus intercept the access request of the target object to prohibit the target object from accessing the target server, thereby realizing access control of the target object.
[0143] It is easily noticed that in the above process, the target firewall for protecting the target server acquires the target information of the target object from the controller only in a case that the target object accesses the target server, which avoids the waste of a large amount of resources of a sending firewall in sending operation and the occupation of resources of other firewalls in storing excessive unnecessary information caused by the active transmission of user information between the firewalls in the related art, thereby effectively improving the working efficiency of the firewall.
[0144] It can be seen that the scheme provided in the present application achieves the purpose of acquiring target information of a user only in a case that the user accesses a server protected by a firewall, thereby realizing the technical effect of improving the working efficiency of the firewall, and further solving the technical problem of occupying resources of a firewall system caused by the active transmission of user information between firewalls in the related art when the firewalls perform access control, thereby reducing the working efficiency of the firewall.
[0145] It should be noted that the first acquisition module 1001, the authentication module 1002 and the processing module 1003 correspond to steps S901 to S903 in the above embodiment, and the three modules have the same examples and application scenarios as the corresponding steps, but are not limited to the content disclosed in the above embodiment 1.
[0146] Optionally, the multiple firewalls include a first firewall directly connected with a target terminal held by the target object, and the first firewall responds to a connection request sent by the target terminal before the target firewall responds to the access request of the target object to the target server, collects target information based on the connection request, and sends the target information to the controller.
[0147] Among the multiple firewalls, there is a first firewall that is directly connected to the target terminal held by the target object. It should be noted that there can be multiple first firewalls among the multiple firewalls, and different first firewalls can connect to different target terminals held by the target object. Specifically, when the target terminal held by the user is powered on, the target terminal will automatically send a connection request to one of the multiple firewalls according to preset connection rules to connect to that firewall. In this embodiment, for example... Figure 2 As shown, the target terminal connects directly and automatically. Figure 2 Firewall A in the middle, i.e. Figure 2 Firewall A in the text is equivalent to the first firewall mentioned above.
[0148] Furthermore, the connection request includes the user's login information, which includes the user's username and password. The target terminal can determine the login information to send to the first firewall based on the user's preset information before sending the connection request, or it can request the user to provide the corresponding login information before sending the connection request to the firewall. When the first firewall receives the connection request, it can authenticate the user based on the login information in the connection request. If the username and password match, authentication is successful; if they do not match, authentication fails.
[0149] Furthermore, after successful authentication, the first firewall can retrieve the corresponding identity information from a pre-set database based on the username. Simultaneously, it sends a device information retrieval request to the target terminal to obtain the device information sent by the target terminal. After obtaining the device information, it establishes a mapping relationship between identity information and device information, thereby achieving the collection of target information corresponding to the user. The aforementioned database stores the mapping relationship between usernames and identity information, which can be pre-created by staff.
[0150] Optionally, after the first firewall completes the collection of the user's target information, such as Figure 2 As shown, the first firewall (i.e. Figure 2 Firewall A) can send target information to the controller for storage, facilitating subsequent acquisition of the user's target information by other firewalls. Furthermore, after sending the collected target information to the controller, the first firewall can also delete the user's target information stored within itself to reduce resource consumption.
[0151] It should be noted that by collecting target information when the first firewall receives a connection request from the target terminal held by the target object, the firewall can obtain the target information in advance, thereby improving the efficiency of the firewall's access control over the target object when the target object actually accesses the server.
[0152] Optionally, before the target firewall responds to the target object's access request to the target server, the controller responds to the connection request sent by the target terminal held by the target object, collects target information based on the connection request, and controls the target terminal to connect to the first firewall, wherein the first firewall is a firewall used for direct connection with the target terminal.
[0153] Specifically, when the target terminal held by the user is powered on, such as Figure 3 As shown in connection line 1, the target terminal automatically sends a connection request to the controller to connect. The connection request includes the user's login information, including the username and password. The target terminal can determine the login information to send to the controller based on preset user information before sending the connection request, or it can request the user to provide the corresponding login information before sending the connection request. Once the controller receives the connection request, it can authenticate the user based on the login information in the connection request. If the username and password match, authentication is successful; if they do not match, authentication fails.
[0154] Furthermore, after successful authentication, the controller can retrieve the corresponding identity information from a pre-set database based on the username. Simultaneously, it sends a device information retrieval request to the target terminal to obtain the device information sent by the target terminal. After obtaining the device information, a mapping relationship between the identity information and the device information is established, thereby achieving the collection of target information corresponding to the user. The aforementioned database stores the mapping relationship between usernames and identity information, which can be pre-created by staff.
[0155] Furthermore, after the controller completes the collection of the user's target information, it can control the target terminal to connect to one of multiple firewalls based on preset connection rules. In this embodiment, for example... Figure 3 As shown by connection number 2, after the controller completes the collection of the user's target information, the controller controls the target terminal to connect to firewall A, meaning firewall A is equivalent to the aforementioned first firewall. During the process of the controller controlling the connection between the target terminal and the first firewall, the controller can send the target terminal's login information to the first firewall to enable the target to log in at the first firewall.
[0156] It should be noted that the target information is collected by the controller when the connection request sent by the target terminal held by the target object is acquired, so that the target information is acquired in advance, and thus the efficiency of the firewall in controlling the target object in accessing the server can be improved.
[0157] Optionally, the first firewall responds to the access request before the target firewall responds to the access request of the target object to the target server, and performs second authorization on the target object based on the second authorization rule and the target information, and if the target object passes the second authorization, the access request is sent to the target firewall.
[0158] Optionally, the access control device further comprises a first inquiry module configured to inquire the controller whether the target information is updated in response to a next access request of the target object to the server protected by the firewall; and a second acquisition module configured to acquire the updated target information in response to information fed back by the controller and indicating that the target information is updated.
[0159] Optionally, the access control device further comprises a second inquiry module configured to inquire the controller whether the target information is updated according to a first time period; and a third acquisition module configured to acquire the updated target information in response to information fed back by the controller and indicating that the target information is updated.
[0160] Optionally, the controller acquires the updated target information after the target firewall performs the first authorization on the target object based on the first authorization rule and the target information, determines at least one second firewall corresponding to the updated target information, and sends the updated target information to the at least one second firewall, wherein the at least one second firewall is a firewall that has acquired the target information from the controller.
[0161] Embodiment 4
[0162] According to another aspect of the embodiments of the present application, a computer readable storage medium is also provided, and the computer readable storage medium stores a computer program, wherein the computer program is configured to execute the access control method when running.
[0163] Embodiment 5
[0164] According to another aspect of the embodiments of the present application, an electronic device is also provided, and the electronic device comprises one or more processors, and a memory configured to store one or more programs, and the one or more programs are configured to enable the one or more processors to implement a program for running when executed, wherein the program is configured to execute the access control method when running.
[0165] The above-mentioned embodiment numbers of the present application are only for description, and do not represent the advantages and disadvantages of the embodiments.
[0166] In the above-described embodiments of the present application, the description of each embodiment focuses on different aspects, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0167] In several embodiments provided in the present application, it should be understood that the disclosed technical contents can be implemented by other manners. Among them, the above-described device embodiments are only schematic, for example, the division of units can be a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or modules shown or discussed can be indirect coupling or communication connection through some interfaces, and can be electrical or other forms.
[0168] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed to multiple units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.
[0169] In addition, each functional unit in each embodiment of the present application can be integrated in a processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0170] If the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the whole or part of the technical solutions that essentially contribute to the prior art can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the embodiments of the present application. The foregoing storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0171] The above merely is the preferred embodiment of the present application, it should be pointed out that, for ordinary skilled in the art, without departing from the principles of the present application, can also make a number of improvements and refinements, these improvements and refinements should also be considered as the protection scope of the present application.
Claims
1. An access control system, characterized in that, The method comprises the following steps: a plurality of firewalls, each firewall is used for inquiring the target information of the target object from the controller based on an access request of the target object to a server protected by the firewall, receiving the target information fed back by the controller, and first authorizing the target object based on a first authorization rule and the target information, and determining whether to allow the target object to access the server requested to be accessed in the access request based on an authorization result, wherein the authorization result is used to represent whether the first authorization of the target object is successful; the controller, connected with the plurality of firewalls, is used for storing information required by the plurality of firewalls during authorization, responding to the inquiry of the firewall and feeding back the target information to the firewall, wherein the information required during authorization includes the target information of the target object.
2. The system of claim 1, wherein, The first firewall directly connected with the target terminal held by the target object is included in the plurality of firewalls, and the first firewall responds to a connection request sent by the target terminal before a target firewall responds to the access request of the target object, collects the target information based on the connection request, and sends the target information to the controller, wherein the target firewall is a firewall in the plurality of firewalls.
3. The system of claim 1, wherein, The controller responds to a connection request sent by a target terminal held by a target object before a target firewall responds to an access request of the target object, collects the target information based on the connection request, and controls the target terminal to be connected with a first firewall, wherein the first firewall is a firewall in the plurality of firewalls for directly connecting with the target terminal, and the target firewall is a firewall in the plurality of firewalls.
4. The system of claim 2 or 3, wherein, The first firewall responds to an access request of any one server sent by the target object, performs second authorization on the target object based on a second authorization rule and the target information, and sends the access request to the target firewall in the case that the target object passes the second authorization.
5. The system of claim 1, wherein, Each firewall inquires whether the target information is updated from the controller in response to a next access request of the target object to a server protected by the firewall, and obtains reply information fed back by the controller, and obtains updated target information from the controller in the case that it is determined that the target information is updated based on the reply information.
6. An access control method characterized by, The access control method is applied to the access control system in any one of claims 1 to 5, and comprises: a target firewall in a plurality of firewalls acquires target information of a target object from a controller in response to an access request of the target object to a target server, wherein each firewall in the plurality of firewalls is used for protecting at least one server, the target firewall is used for protecting the target server, and the controller is used for storing information required by the plurality of firewalls during authorization; the target firewall performs first authorization on the target object based on a first authorization rule and the target information; The target firewall allows the target object to access the target server if the first authorization to the target object is successful.
7. The method of claim 6, wherein, The first firewall among the multiple firewalls is directly connected with a target terminal held by the target object, and the first firewall collects the target information based on a connection request sent by the target terminal and sends the target information to the controller before the target firewall responds to an access request of the target object to the target server.
8. The method of claim 6, wherein, The controller collects the target information based on a connection request sent by a target terminal held by the target object and controls the target terminal to connect with the first firewall before the target firewall responds to an access request of the target object to the target server, wherein the first firewall is a firewall directly connected with the target terminal.
9. The method according to claim 7 or 8, characterized in that, The first firewall performs a second authorization to the target object based on a second authorization rule and the target information in response to the access request before the target firewall responds to the access request of the target object to the target server, and sends the access request to the target firewall if the target object passes the second authorization.
10. The method of claim 6, wherein, After the target firewall performs the first authorization to the target object based on the first authorization rule and the target information, the method further comprises: The target firewall inquires the controller whether the target information is updated in response to a next access request of the target object to a server protected by the firewall if the next access request is received; The target firewall acquires updated target information if the controller feeds back information indicating that the target information is updated.
Citation Information
Patent Citations
Method and system for allowing remote procedure calls through a network firewall
US5828833A
Firewall opening processing method and apparatus, server, system and readable storage medium
WO2022095367A1