A zero-trust-based network security access control method, a gateway system adopting the method, and a storage medium
By introducing secondary data authentication and secondary identity verification into the zero-trust network security access control method, and combining it with gateway systems and instant messaging collaboration functions, the problems of user identity impersonation and improper operation in existing technologies are solved, achieving higher security and convenient deployment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-15
- Publication Date
- 2026-03-27
AI Technical Summary
Existing zero-trust network security access control methods cannot effectively prevent legitimate users from performing improper operations or intruders from impersonating legitimate users to launch attacks, and traditional security architectures cannot cope with advanced persistent attacks and the risk of internal data leaks.
The system employs a combination of data two-factor authentication and identity two-factor verification. It authenticates users' account information, encryption/decryption status, and usage habits through the gateway system, dynamically controls access policies, and notifies administrators to confirm the operation upon first login. It also utilizes instant messaging collaboration functions to achieve dynamic and secure access control.
It improves system security and reliability, prevents user identity from being impersonated or improper operations from being performed, reduces system resource consumption, simplifies system architecture, and improves deployment convenience.
Smart Images

Figure CN116248405B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer networks, and particularly relates to a network security access control method based on zero trust and a gateway system and a storage medium adopting the method. BACKGROUND
[0002] With the continuous development of network technology, the contradiction between network security and network convenience is becoming more and more prominent. External attacks and internal personnel threats are becoming more and more serious. Organized, attack weaponized, advanced persistent attack targeting data and services can still easily find various vulnerabilities to break through the boundaries of enterprises. At the same time, internal personnel leaks are also difficult to prevent. Internal business unauthorized access, employee mistakes, intentional data theft and other internal personnel threats are emerging in an endless stream. In the face of such serious security challenges, more and more security investment is needed, but the security effect is not satisfactory, and security incidents are emerging in an endless stream. The traditional security architecture has failed. The traditional network security boundary-based architecture assumes, to some extent, that the intranet personnel and devices are trustworthy, recognizes that all personnel operations in the intranet are safe and trusted, and believes that security is to protect the enterprise network boundary through firewalls, WAFs, IPSs and other boundary security products / solutions. It has been proved that the network system must have undiscovered vulnerabilities, and internal personnel various WeChat screenshots of enterprise internal communication content may exist the risk of leakage. This completely overturns the traditional network security through network isolation boundary technology method, and the boundary-based network security architecture and solution has been difficult to cope with today's network threats. In view of this, the existing technology also proposes the concept of zero trust network model. Zero trust is a security model that continuously verifies and dynamically authorizes all users based on as many trust elements as possible, such as access subject identity, network environment, terminal state, etc. Zero trust is very different from the traditional security model. The traditional security model assesses entity risk through "one-time verification + static authorization", while zero trust builds the security cornerstone of the enterprise based on the "continuous verification + dynamic authorization" mode. Zero trust has shown its value in practice. At present, the zero trust solution mainly takes the form of SDP terminal + SDP gateway combination. By deploying and installing a zero trust client on the user terminal, the user logs in to the zero trust terminal, and the terminal sends a unique digitally signed UDP packet to the SDP controller. The SDP controller verifies the client identity information and opens the TCP port established by the SSL connection for the legal user IP. Through port hiding, the business system converges the external exposure surface, so it can prevent illegal users from discovering exposed service ports through scanning software and then launching attacks.For example, the prior art patent No. CN202110684351.9, "Zero-trust network security access control method, device and computing equipment", discloses a zero-trust network security access control method, application access gateway and gateway system. The method comprises: when a user initiates access, the application access gateway initiates network connection of a penetration proxy to a secure access gateway to establish a network channel; if the terminal proxy and the application access gateway are not in the same network segment, the access request sent by the terminal proxy is received through the network channel to access the application, and the application feedback request is transmitted to the terminal proxy through the network channel; if they are in the same network segment, the terminal proxy and the application access gateway are directly connected through the secure access gateway according to the same network segment information, the access request sent by the terminal proxy is directly received to access the application, and the application feedback request is directly fed back to the terminal proxy. Through the above-mentioned manner, the application embodiment can deploy applications under the mixed condition of public cloud and private cloud, and realize consistent experience of user access to intranet and extranet. However, in the actual use process, the prior art still has no resistance ability to the user who performs improper operation or the intruder who perfectly disguises as the actual user to use the identity. SUMMARY
[0003] In view of the shortcomings of the prior art, the purpose of the present application is to provide a zero-trust-based network security access control method, which can compensate for the problems existing in the prior art by combining data secondary authentication with identity secondary verification, so as to make it more secure. The present application also relates to a gateway system and a storage medium using the method, which can simplify the zero-trust system as much as possible, so that the architecture is simpler and easier to operate.
[0004] In order to achieve the above-mentioned purpose, the present application comprises the following steps:
[0005] First authentication: authenticate whether the account information of the user is correct, whether the encryption and decryption are normal, and whether the basic information of the user existing in the gateway system can be decrypted, so that the preliminary verification of the user identity is completed to achieve the first authentication;
[0006] Transfer package: the authenticated information is repackaged, encrypted by a proxy, and then forwarded to the zero-trust terminal authentication center;
[0007] Second authentication: terminal information, environment information, secondary verification information and other advanced information are obtained from the encrypted package. Since the transfer package is obtained from the user terminal, these information are contained in the transfer package. The zero-trust terminal authentication center checks the authorization of these information, and the gateway system dynamically controls the access strategy according to the checked results, regulates the operation range of the user and ensures the credibility of the access operation of the user;
[0008] After the final user is authenticated, the user can operate each intranet system in the organization through a general terminal.
[0009] For the first login authentication user: according to the dynamic control access policy indicates the command that the authentication user can perform, after the authentication user confirms, the authentication user is logged out and logged in again; for some based on time limit and management of user identity impersonation, etc., through such operation can avoid the impersonator first login directly after the operation, affect the overall system security.
[0010] For the authentication user who is not the first login, through twice verification can basically ensure its security, at this time through the CLI command line running pipeline, approval process, search OA and other organization website content. So you can easily and conveniently realize the terminal security check and dynamic strategy control access.
[0011] Preferably, the first login authentication user records the information confirmed in the login process when logging out for the first time, and sends the information to the authentication user and his superior manager through the system preset communication mode, and when the authentication user and the superior manager confirm the information, the second login can be realized. The system preset communication mode can be telephone verification or SMS verification and other existing technologies. The key is to inform the manager and the authentication user at the same time, as long as one of them finds the problem, the re-login of the account can be prevented.
[0012] Preferably, the UDP knock package check is performed before the first step authentication, the UDP package of the user is confirmed to be normal and can be decrypted and identified, and after decryption and identification, the basic access control policy can be issued to realize the basic authorization authentication. Port knocking is a special security authentication scheme. However, some people also use this way to send error packages continuously to affect system resources. Through the knock package check, the error knock package can be directly eliminated before authentication, saving resources and avoiding attacks in the authentication process.
[0013] Preferably, the basic information of the user in the first step authentication includes username, login token information, cookie information and other basic authentication data, and after multiple logins, user usage habit information is also generated, and the user usage habit information is verified at the end of the first step authentication.
[0014] Preferably, the usage habit information includes the user's regular login time, regular login device and regular operation steps, when the user usage information is detected to be inconsistent in many places, the operation is recorded, and the record information is sent to the manager, and the user is prohibited from creating, inserting and deleting operations.
[0015] Preferably, in the second step authentication, the environment perception strategy authentication is performed, the terminal device is verified to be trusted through the zero trust terminal authentication center, and the terminal environment is verified to be trusted, and after verification, higher dynamic authorization strategy is executed.
[0016] Preferably, when the user terminal itself has the function of instant messaging cooperation, the function of zero-trust dynamic security access control is realized by using the function of instant messaging cooperation.
[0017] The application also includes a gateway system based on a user terminal and a zero-trust terminal authentication center with a gateway, the zero-trust terminal authentication center scans all the devices installed with the user terminal locally, confirms whether the device has a gateway, for the device with the gateway, sets the zero-trust terminal in the device gateway, the device installed with the user terminal sends the device information to the gateway system, the gateway performs authentication, the user performs the first step authentication based on the default policy verification of the writable switch on the user terminal, and accesses the zero-trust terminal authentication center after passing the first step authentication, and performs the second step authentication of confirming the terminal device and the terminal environment in the gateway of the zero-trust terminal authentication center, and all the communication protocols communicate through the encrypted data of the SM4 algorithm.
[0018] Preferably, when the device does not have a gateway, the SDP zero-trust gateway in the software agent mode is adopted to achieve the deployment of the zero-trust gateway in the form of pure software without hardware.
[0019] The application also includes a computer storage medium, the storage medium stores at least one executable instruction, and the executable instruction makes the processor execute the steps of the zero-trust network security access control method. In this way, the entire system is convenient to carry, save and deploy. The efficiency of system upgrading can also be improved according to the storage medium.
[0020] Compared with the prior art, the zero-trust scheme adopting the technical scheme of the application can further improve the safety factor and avoid improper operation of the operator with a normal identity or identity being used by others. The reliability of the zero-trust system is effectively improved, and the functions are reused by fully utilizing the devices and software in the user terminal, so that the system architecture is as simple as possible, and the system is convenient to deploy. BRIEF DESCRIPTION OF DRAWINGS
[0021] The accompanying drawings illustrate exemplary embodiments of the present disclosure and together with the description, explain the principles of the present disclosure, wherein the drawings are included to provide further understanding of the present disclosure and constitute a part of the specification.
[0022] Figure 1 is a schematic diagram of the prior art zero-trust network security access control method;
[0023] Figure 2 is a schematic diagram of the zero-trust network security access control method provided by the embodiment of the application;
[0024] Figure 3is a flowchart of a security check in a network security access control method of zero trust provided by an embodiment of the present application;
[0025] Figure 4 is a structural block diagram of a gateway system provided by an embodiment of the present application.
[0026] Figure 5 is a schematic diagram of the working principle of a gateway system provided by an embodiment of the present application. DETAILED DESCRIPTION
[0027] The present disclosure will be further described below in conjunction with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related content, and not to limit the present disclosure. In addition, it should be noted that only parts related to the present disclosure are shown in the drawings for ease of description.
[0028] It should be noted that the embodiments and features in the present disclosure can be combined with each other without conflict. The present disclosure will be described in detail below with reference to the drawings and in conjunction with the embodiments. In order to make the purpose, technical scheme and advantages of the present application more clear, the present application will be further described in detail below in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and not to limit the present application.
[0029] As Figure 1The shown is the zero trust solution adopted in the prior art, the combination of SDP terminal + SDP gateway, by deploying and installing a zero trust client on the user terminal, the user logs in through the zero trust terminal. SDP is the full name of Software Defined Perimeter, which is a new generation of network security technology architecture based on the concept of zero trust proposed by the international cloud security alliance CSA in 2013. Zero trust security is a concept, and software defined perimeter SDP is a technical architecture and scheme to practice the concept of zero trust security. The user terminal sends a uniquely digitally signed UDP packet to the SDP controller, UDP is the abbreviation of User Datagram Protocol, the Chinese name is User Datagram Protocol, which is a connectionless transport layer protocol in the OSI (Open System Interconnection) reference model, providing simple transaction-oriented unreliable information transfer service. The SDP controller verifies the client identity information and opens the TCP port for the SSL connection established by the legal user IP. TCP is a connection-oriented communication protocol, which completes the functions specified by the fourth layer of the OSI model in computer network. TCP port is a port that provides services for TCP protocol communication. SSL (Secure Socket Layer) is developed by Netscape to ensure the security of Internet data transmission, which uses data encryption (Encryption) technology to ensure data network.
[0030] The existing technology hides the convergence service system from the external exposure surface through port hiding, so that illegal users can be prevented from discovering exposed service ports through scanning software and then launching attacks. However, we find that such network isolation implementation and zero-trust terminal SDP gateway implementation in the network boundary security of traditional enterprises only switch the SDP gateway to be responsible for forwarding UDP packets after UDP knocking and the subsequent short opening of TCP ports, establishing TCP connections to forward request data packets, and do not verify SDP. The hardware device is responsible for forwarding data packets, resisting DDOS (Distributed Denial of Service) attacks, syn attacks, etc. (syn attacks belong to a kind of DoS attack, which utilizes the defects of TCP protocol to send a large number of half-connection requests to consume CPU and memory resources). When the user terminal is an IM (Instant Messaging) terminal, the IM terminal is only responsible for communication, cooperation, and the IM gateway is only responsible for forwarding message information of the user IM terminal or for forwarding authorization packets of single sign-on operations to assist in completing the single sign-on process. The user terminal information, environment information, and authorization situation are not checked, and the user can operate the corresponding system on the IM workbench as long as he logs in to the IM terminal. The permission granularity is very rough. Criminals can easily bypass the zero-trust system by using the IM terminal.
[0031] In addition, the existing zero-trust cannot avoid personnel with actual operation permissions from performing illegal operations independently, or situations where the real identity is used by someone else. Although the zero-trust technology is relatively mature, criminals have many ways to bypass the zero-trust system.
[0032] In the present application, the technical solutions adopted overcome most known attack methods. As shown in Figure 2 , Figure 3 The present application can check the UDP knocking packet and confirm that the user's UDP packet is normal and can be decrypted and identified. In addition, it can issue basic access control policies and implement basic authorization authentication. This can effectively protect system resources.
[0033] On this basis, the first step of authentication checks whether the user's account information is correct, and whether the encryption and decryption are normal. The user's basic information, including the username, login token information, cookie information, and other basic authentication data, can be decrypted. The gateway system confirms that the basic information of this user already exists in the system, and the first authentication is achieved. The first step of authentication is based on the default policy of the writable switch. Then the gateway's packet can be proxy forwarded to the zero trust terminal authentication center for higher authorization checks of terminal information and environment information. In this process, the gateway located in the user terminal and the zero trust gateway based on the zero trust terminal authentication center are combined to achieve the functions of the user terminal and complete the authentication and authorization of zero trust.
[0034] The zero trust terminal authentication center, also known as the zero trust control center in the prior art, at least includes unified identity authentication, terminal security detection module, access control module, and security audit function modules. It can also improve its functions and use effect through third-party extension modules.
[0035] The gateway system dynamically controls access policies to ensure that the user's access operations are trustworthy. After the end user is authenticated, he or she can access each internal network system in the organization through a general terminal operation to complete instant messaging and collaboration functions, as well as the functions of dynamic security access control of the zero trust gateway. Through CLI command line operation pipeline, approval process, and search for OA content of the organization's website. CLI is a command line program that accepts text input to execute operating system functions. It easily and conveniently realizes terminal security check and dynamic policy control access. Taking the IM terminal as an example, in this process, the gateway system is integrated and merged to realize IM communication and security policies of the zero trust gateway through the IM gateway of the IM instant messaging software.
[0036] In this process, the authentication user who logs in for the first time records the information confirmed during the login process in the system when logging out for the first time, and sends this information to the authentication user and his or her superior manager through the system's preset communication method. Only when the authentication user and the superior manager both confirm the information can they log in again. Through this combination of online and offline multi-dimensional authentication methods, although the process is increased, it saves system resources for the zero trust system. At the same time, the reliability of such verification is greatly increased.
[0037] Similarly, the user terminal also generates user usage habit information after multiple logins, and the user usage habit information is verified at the end of the first-step authentication. The usage habit information includes the user's regular login time, regular login device, and regular operation steps. As for public operations, the time, frequency, and operation object of the user logging into the system are traceable according to the user's identity. For example, the login time of an office worker often matches the work time, and if overtime work and overtime work information in the OA system can be verified with each other. Maintenance personnel will also log in temporarily according to the help request initiated in addition to regular maintenance. However, if an office user is detected to suddenly log in at a non-working time and attempt to use a module unrelated to his work, even if he has passed the two-step authentication, his identity is still questionable. When multiple user usage information is detected to be inconsistent, the operation is recorded, the record information is sent to the administrator, and the user is prohibited from creating, inserting, and deleting operations. If it is really not the user himself, only the damage to the system can be minimized.
[0038] Still taking the IM terminal as an example, for the zero-trust terminal integrated with IM, the CLI command is integrated in the present application, the system inside the enterprise is operated through the CLI command, unnecessary trouble of opening a web page to operate the system again is avoided, for example, we can integrate the oa command in the IM terminal, identify that it is an OA CLI command through the keyword " / oa", search the announcements, documents, etc. in the OA system through " / oasearch xxx", directly display the content in the IM terminal chat interface of the user, quickly return the content to the user for reading, and there is no need to open the system web page for viewing, reducing the operation of the user accessing the system and improving the security of the entire system.
[0039] At the same time, for the operation of the CLI, the operation of the development system is conveniently integrated in the present application, the / devops runxxx operation is used to quickly access the devops pipeline, and after the unified authentication of the zero-trust gateway integrated in the IM gateway, the CLI operation can quickly pull up the running of the pipeline and package and deploy the entire system. In this way, non-research and development personnel or external collaborative development personnel can also easily authorize their collaborative development of the pipeline without logging into the pipeline system, achieving security protection through the IM gateway without affecting the application and modification of the pipeline system, based on identity-based trust and the minimum permission access mechanism, ensuring that the user can deploy the test environment or production environment deployment system, but will not affect the security of the system, and the export application is concentratedly controlled, and the minimum external network access application is configured. Only by using the IM integrated zero-trust terminal cli for quick operation can the operation of the pipeline be achieved, and the user's trusted and secure access is also achieved.
[0040] Or through " / oa search xxx" to find the corresponding process application form, return the temporary application form link "http: / / oa.com / id=xxxx&token=abcd" and the like, the token can be added on the returned temporary link, the token is authenticated by the zero-trust terminal authentication center, and after the authentication is completed, it is confirmed that there is no exception, and then the token is removed and forwarded to the back-end OA system, a secure verification temporary link is achieved, and it is ensured that the access of each link is safe and reliable.
[0041] In the communication dialogue of the IM, we can also pull up the approval form through / oa process xxxx agree, etc. After the other party receives the pulled-up approval form, the approval form is directly clicked on the approval interface of the pulled-up approval form, and the approval of the user in the dialogue is quickly completed. Avoid logging into the system, and also ensure that the user's approval is monitored by the zero-trust terminal environment, and the identity is authenticated, and it is ensured that the user's approval has complete operation audit and environment information record when the approval is completed.
[0042] As shown in Figure 4 and Figure 5 The schematic diagram of the gateway system of the present application is shown, based on the user terminal and the zero-trust terminal authentication center with the gateway, the zero-trust terminal authentication center scans all the user terminal installation devices in the local, confirms whether the device has the gateway, for the device with the gateway, the zero-trust terminal is set in the device gateway, the device information of the user terminal installation device is sent to the gateway system, the gateway performs authentication, the user performs the first step authentication based on the default policy verification of the writable switch in the user terminal, and after passing the first step authentication, the user accesses the zero-trust terminal authentication center, and the second step authentication of confirming the terminal device and the terminal environment is performed in the gateway of the zero-trust terminal authentication center. All communication protocols are encrypted by the national secret SM4 algorithm for data communication, especially when the user terminal is an IM terminal, the software and hardware devices can be fully utilized. When the device does not have a gateway, the SDP zero-trust gateway in the form of software agent is adopted, so as to realize the deployment of the zero-trust gateway without hardware and by using pure software.
[0043] Meanwhile, the present application also includes a computer storage medium, the storage medium stores at least one executable instruction, and the executable instruction makes the processor execute the steps of the zero-trust network security access control method. In this way, the carrying, saving and deployment of the whole system are facilitated. The efficiency of system upgrading can also be improved according to the storage medium.
[0044] Although the present application has been described in terms of the preferred embodiments, it is not intended that the application be limited to such embodiments. Any modifications of the application that come within the spirit and scope of the following claims should be considered part of the present application. In the description of the specification, the terms "one embodiment / implementation", "some embodiments / implementations", "an example", "a specific example", or "some examples" are intended to mean that a particular feature, structure, material, or characteristic is included in at least one embodiment / implementation of the present application. The appearances of the above terms in various places in the specification are not intended to exclude that the specific feature, structure, material or characteristic can be present in any one or more embodiments / implementations of the present application. Moreover, the described particular features, structures, materials or characteristics can be combined in any suitable manner in any one or more embodiments / implementations of the present application. Furthermore, the terms "a" or "an", as used herein in the specification, are used generically to include one or more, unless otherwise indicated. Still further, the term "number" shall mean one or more unless otherwise indicated. Still further, the terms "primarily", "about", and "substantially" are used to ended a range of values of ±20% unless otherwise stated.
[0045] In addition, the terms "first", "second", and the like, do not denote any order, quantity, combination, or importance, but rather are used to nomenclature different components. Thus, such terms are used herein "merely" to identify and distinguish a component from another. Additionally, the use of "including", "containing", "comprising", "having", "featuring", "involving", "including" or "featuring" and variations thereof herein, are intended to be broad and encompass the occurrence of zero, one or more of a component, feature, structure, and / or characteristic, and are not to be construed as limiting. Furthermore, a structure, material, or characteristic that is "on" or "adjacent" a second structure can be directly on or adjacent to the second structure or can have one or more third structures between the two structures.
[0046] It will be appreciated by persons skilled in the art that the present application is not limited to what has been particularly shown and described herein above. In addition, unless otherwise noted, the description of a particular feature, structure, material, or characteristic is intended to extend to all embodiments of the application. Thus, the scope of the application should be determined by the appended claims and equivalents thereof, rather than by the description alone.
Claims
1. A zero trust based network security access control method, characterized by, The method comprises the following steps: The first step of authentication: authenticating whether the account information of the user is correct, whether the encryption and decryption are normal, and whether the basic information of the user existing in the gateway system can be decrypted; The transfer package: re-packing the authenticated information, forwarding it to the zero-trust terminal authentication center through proxy encryption; The second step of authentication: obtaining terminal information and environment information from the encrypted package, and performing authorization check on the information, and the gateway system performs dynamic control access strategy according to the checked result, and specifies the operation range of the user and ensures that the access operation of the user is reliable; After the final user is authenticated, the user can operate each intranet system in the organization through a general terminal; For the first login authentication user: according to the dynamic control access strategy, the authentication user can execute the command, and after the authentication user confirms, the authentication user is logged out and logged in again; For the non-first login and login passed authentication user: run the pipeline through the CLI command line, approve the process and search OA; The first login authentication user records the information confirmed in the login process when logging out for the first time, and sends the information to the authentication user and his superior manager through the system preset communication mode, and when the authentication user and the superior manager confirm the information, the second login can be realized.
2. The zero trust based network security access control method of claim 1, wherein, Before the first step of authentication, the UDP knock package is checked to confirm that the UDP package of the user is normal and can be decrypted and identified, and after decryption and identification, the basic access control strategy can be issued to realize the basic authorization authentication.
3. The zero trust based network security access control method of claim 1, wherein, The basic information of the user in the first step of authentication includes the user name, login token information and cookie information, and user usage habit information is also generated after multiple logins, and the user usage habit information is verified at the end of the first step of authentication.
4. The zero trust based network security access control method of claim 3, wherein, The usage habit information includes the user's regular login time, regular login equipment and regular operation steps, when the user usage information is detected to be inconsistent in many places, the operation is recorded, and the record information is sent to the manager, and the user is prohibited from creating, inserting and deleting operations.
5. The zero trust based network security access control method of claim 1, wherein, In the second step of authentication, the environment sensing strategy is authenticated, the terminal device is authenticated by the zero-trust terminal authentication center, and the terminal environment is authenticated, and the dynamic control access strategy is executed after the authentication.
6. The zero trust based network security access control method of claim 1, wherein, When the user terminal itself has the function of instant messaging cooperation, the function of zero-trust dynamic security access control is realized by using the function of instant messaging cooperation.
7. A computer storage medium, characterized in that: The storage medium stores at least one executable instruction, and the executable instruction makes the processor execute the steps of the zero-trust based network security access control method according to any one of claims 1-6.
Citation Information
Patent Citations
Application access methods, devices and computing equipment in zero trust
CN113422768B
Terminal zero-trust security control method and system
CN112653689A
Business access control system and control method based on zero trust
CN115001770A