Access control method and related apparatuses
Patent Information
- Application Number
- CN202111554356.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-17
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2041-12-17
AI Technical Summary
[0004]但是,基于ACL的访问控制需要人工维护ACL,而对于一个企业园区网络来说ACL过于复杂且开销大,需要实时管理、更新或删除ACL中的条目,人力运维的成本非常大
Smart Images

Figure CN116266793B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more particularly to access control methods and related apparatus. Background Technology
[0002] In network scenarios with boundaries, such as enterprise campus networks and data center networks, it is necessary not only to provide network communication connectivity, but also to cut off unauthorized data flows through access control to prevent unauthorized access and ensure network security.
[0003] Current access control mechanisms in enterprise campus networks typically rely on aggregation layer or core layer switches, or firewalls, which enforce access control lists (ACLs). For example, when a terminal device connects to the campus network, the aggregation layer or core layer switch, or the firewall, obtains the five-tuple information or other information from the data packets sent by the terminal device. It then uses the deployed ACL to determine the authenticity of the five-tuple information or other information. If the five-tuple information or other information is found to be authentic, the data packet is forwarded; otherwise, it is discarded, thus achieving access control.
[0004] However, ACL-based access control requires manual maintenance of ACLs, which is too complex and costly for an enterprise campus network. It requires real-time management, updating or deleting entries in the ACL, resulting in very high human maintenance costs. Summary of the Invention
[0005] This application provides an access control method and related apparatus, which can be applied in Internet Protocol (IP) networks, such as enterprise campus networks or data center networks, to reduce the cost of ACL operation and maintenance and improve network security.
[0006] The first aspect of this application provides an access control method, including:
[0007] The computer device sends a source identifier and a target identifier to the first network device, wherein the source identifier indicates the computer device and the target identifier indicates the target resource, which is the resource that the computer device wants to access.
[0008] Then, the computer device receives first instruction information sent by the first network device. This first instruction information includes at least a first verification code, which is obtained based on at least a first key, an associated attribute, and a first target constraint term corresponding to the associated attribute. The associated attribute is an attribute associated with the source identifier, the first target constraint term is a preset constraint range for the information corresponding to the associated attribute, and the number of associated attributes is at least one. It is understood that the information includes facial information, password information, fingerprint information, numerical information, device information, or voice information, etc., and may also be other recordable information; specific details are not limited here.
[0009] The computer device acquires the associated attribute and determines the first target information corresponding to the associated attribute. The first target information is the information corresponding to the associated attribute when the computer device accesses the target resource.
[0010] Then, the computer device sends a message to access the target resource, the message including at least first indication information, an associated attribute, and first target information corresponding to the associated attribute, and the number of associated attributes is at least one.
[0011] In the embodiments of this application, a computer device sends a source identifier and a target identifier to a first network device, and then receives first indication information including a first verification code from the first network device. The computer device obtains an association attribute and first target information corresponding to the association attribute, and then sends a message to access the target resource. This message includes the first indication information, the association attribute, and the first target information corresponding to the association attribute. The first indication information, the association attribute, and the first target information corresponding to the association attribute in the message sent by the computer device can be used to verify the message; only after successful verification can access the target resource be obtained. This scheme reduces the application of ACLs, thus lowering the maintenance cost of ACLs. Furthermore, the association attribute and the first target information corresponding to the association attribute are real-time, and verifying the message based on this improves network security.
[0012] In one possible implementation of the first aspect, the first instruction information further includes an associated attribute, and the computer device obtains the associated attribute from the first instruction information.
[0013] In the embodiments of this application, the computer device obtains the association attribute from the first indication information including the association attribute, which can improve work efficiency and at the same time ensure consistency with the association attribute determined in the first network device.
[0014] In one possible implementation of the first aspect, the computer device obtains the association attributes from a second network device. This second network device may be another server, controller, or other network device with access control policies or corresponding association attributes for the computer device, wherein the access control list can determine the association attributes. It is understood that the second network device can also be other network devices capable of obtaining association attributes; this is not specifically limited here.
[0015] In the embodiments of this application, the computer device obtains the associated attributes from the second network device, which can reduce the amount of data in the first indication information and save network resources.
[0016] In one possible implementation of the first aspect, the computer device obtains the associated attributes from second indication information, which is information possessed by the computer device including the associated attributes. For example, the second indication information may be preset information or entries that include associated attributes corresponding to the computer device.
[0017] In the embodiments of this application, the computer device obtains the associated attributes from the second indication information it has locally available, which can improve work efficiency and save network resources.
[0018] In one possible implementation of the first aspect, the computer device further receives a second key sent by the first network device, which is obtained by the first network device based on the first instruction information.
[0019] Then, the computer device determines a second verification code based on the second key and the message, and sends the second verification code. This message is the message used by the computer to access the target resource.
[0020] In the embodiments of this application, the computer device receives a second key sent by the first network device, obtains a second verification code based on the second key and the message, and sends the second verification code. The second verification code is used to verify the message. Only after the message verification is passed can the computer device access the target resource. This increases the verification measures for the message, greatly improves the security of network security, and minimizes the possibility of malicious theft of resources.
[0021] In one possible implementation of the first aspect, the first indication information further includes a first target constraint item corresponding to the associated attribute, and / or a validity period, which is the validity period of the first verification code. Only messages within the validity period can access the target resource after successful verification. Additionally, the first target constraint item is used to verify the message.
[0022] In the embodiments of this application, the first indication information may also include a first target constraint item corresponding to the associated attribute, and / or a validity period. Only messages within the validity period can access the target resource after verification, which further increases the verification message measures, improves the reliability of network security, and avoids the malicious theft of resources as much as possible.
[0023] In one possible implementation of the first aspect, the associated attribute includes at least one of the following:
[0024] Login mode, abnormal behavior, abnormal access relationship, terminal health, abnormal traffic, device security level, location information, security group information, or access time. It is understandable that other dynamic characteristics that can identify computer devices can also be associated attributes; specific details are not limited here.
[0025] In the embodiments of this application, the associated attributes include at least one of the following: login mode, behavior anomaly degree, access relationship anomaly degree, terminal health degree, traffic anomaly degree, device security level, location information, security group information, or access time, which improves the flexibility of the solution and the application scenarios.
[0026] In one possible implementation of the first aspect, the source identifier includes at least one of the following:
[0027] The computer device's IP address, device identifier, user identifier, user group or source port number, and other identifiers that can identify the computer device.
[0028] In the embodiments of this application, the source identifier includes at least one of the following: the IP address of the computer device, the device identifier of the computer device, the user identity identifier corresponding to the computer device, the user group or source port number to which the computer device belongs, and other identifiers that can identify the computer device, thereby increasing the flexibility of the solution.
[0029] In one possible implementation of the first aspect, the target identifier includes at least one of the following:
[0030] The target resource's IP address, IP address prefix, partial or complete Uniform Resource Locator (URL) prefix, device identifier, identity identifier, security group, or port number.
[0031] In the embodiments of this application, the target identifier includes at least one of the following: the IP address of the target resource, the IP address prefix of the target resource, part or all of the URL prefix of the target resource, the device identifier of the target resource, the identity identifier of the target resource, the security group to which the target resource belongs, or the port number of the target resource, which increases the reliability of the solution.
[0032] In one possible implementation of the first aspect, the computer device acquires a target attribute and third target information corresponding to the target attribute. The target attribute is an attribute corresponding to a target identifier, and the third target information is preset information corresponding to the target attribute acquired by the computer device.
[0033] The computer device sends the target attributes and the corresponding third target information.
[0034] In the embodiments of this application, the computer device acquires and sends target attributes and third target information corresponding to the target attributes, so that the message can be verified based on the target attributes and the third target information corresponding to the target attributes, thereby preventing resource theft to a greater extent, improving network security, and increasing the flexibility and selectivity of the solution.
[0035] A second aspect of this application provides an access control method, including:
[0036] The first network device receives a source identifier and a target identifier sent by the computer device, wherein the source identifier indicates the computer device, the target identifier indicates the target resource, and the target resource is the resource that the computer device wants to access.
[0037] Then, the first network device determines the associated attributes and the first target constraint item corresponding to the associated attributes based on the received source identifier, target identifier, and access control policy. The access control policy includes conditions for the computer device to access the target resource, the associated attributes are attributes associated with the source identifier, and the first target constraint item is a preset constraint range for the information corresponding to the associated attributes. The number of associated attributes is at least one. It is understood that the information includes facial information, password information, fingerprint information, numerical information, device information, or voice information, etc., and can also be other recordable information; specific details are not limited here.
[0038] The first network device determines the first verification code based at least on the first key, the associated attribute, and the first target constraint item corresponding to the associated attribute.
[0039] Then, the first network device sends a first instruction message to the computer device, enabling the computer device to send a message to access the target resource based on the first instruction message, wherein the first instruction message includes at least a first verification code.
[0040] In the embodiments of this application, a first network device receives a source identifier and a target identifier sent by a computer device, and determines an association attribute and a first target constraint item corresponding to the association attribute based on the source identifier, the target identifier, and the access control list. Then, it determines a first verification code based at least on a first key, the association attribute, and the first target constraint item corresponding to the association attribute. The first network device then sends a first indication information including at least the first verification code to the computer device, so that the computer device sends a message to access the target resource based on the first indication information including the first verification code. Thus, during the forwarding of the message of the computer device accessing the target resource, the message can be verified in real time based on the first verification code, thereby monitoring the status of the computer device. Only after the message is verified can the computer device access the target resource, which improves the real-time protection of network security, avoids the theft of resources as much as possible, and reduces the application of ACLs in the process of verifying messages, thus reducing the operation and maintenance costs of ACLs.
[0041] In one possible implementation of the second aspect, the first network device first determines an associated attribute entry based on the source identifier, the destination identifier, and the access control policy. The associated attribute entry is an entry that includes at least an associated attribute and a first target constraint corresponding to the associated attribute.
[0042] Then, the first network device determines the associated attributes and the first target constraint corresponding to the associated attributes based on the list of associated attributes.
[0043] In the embodiments of this application, the first network device first determines an association attribute list based on the source identifier, the destination identifier, and the access control list, and then determines the association attributes and the first target constraint items corresponding to the association attributes from the association attribute list. The association attribute list includes the association attributes and the first target constraint items corresponding to the association attributes, making the management of the association attributes and the first target constraint items corresponding to the association attributes more convenient and effective, and saving operation and maintenance costs.
[0044] In one possible implementation of the second aspect, the first network device can also determine the second key based on the first instruction information.
[0045] The first network device then sends the second key to the computer device, enabling the computer device to generate a second verification code based on the second key. This second verification code will be used to verify the computer device's messages accessing the target resource.
[0046] In the embodiments of this application, the first network device obtains a second key based on the first instruction information, and then sends the second key to the computer device, which obtains a second verification code based on the second key. Since the second key is obtained from the first instruction information and has high security, using the second verification code generated from the second key to verify messages can significantly enhance network security and prevent the computer device from being maliciously accessed for target resources.
[0047] In one possible implementation of the second aspect, the first network device determines the first verification code based on the source identifier and / or target identifier and / or validity period, the first key, the associated attribute, and the first target constraint item corresponding to the associated attribute, wherein the validity period is the validity period of the first verification code. This validity period can be preset in the access control policy, preset on the first network device, or in other network devices that record access-related information; specific details are not limited here.
[0048] In the embodiments of this application, the first network device determines the first verification code based on the source identifier and / or target identifier and / or validity period, the first key, the association attribute, and the first target constraint item corresponding to the association attribute. The determination of the first verification code by more factors increases the flexibility and selectivity of the scheme and improves the security of network security.
[0049] In one possible implementation of the second aspect, the first instruction information further includes at least any one of the following:
[0050] Validity period, associated attributes, or the first target constraint corresponding to the associated attributes.
[0051] In the embodiments of this application, the first instruction information includes at least an expiration date, an associated attribute, or a first target constraint item corresponding to the associated attribute, which increases the application scenarios of the solution and reflects the selectivity of the solution.
[0052] In one possible implementation of the second aspect, if the first indication information does not include a first target constraint item corresponding to the associated attribute, the first network device sends the first target constraint item corresponding to the associated attribute to the third network device, so that the third network device verifies the message of the computer device accessing the target resource based on the first target constraint item.
[0053] Specifically, after receiving a message from a computer device requesting access to a target resource, the third network device can obtain a second verification code based on the first target constraint and the information carried in the message. If the second verification code is the same as the first verification code carried in the message, the message verification is successful, and then the computer device can access the target resource.
[0054] In the embodiments of this application, the first network device sends a first target constraint to the third network device, which increases the selectivity of the method.
[0055] In one possible implementation of the second aspect, the first network device sends an association attribute and corresponding second target information to a third or fourth network device, enabling the third or fourth network device to verify the computer device's access to the target resource message based on the association attribute and the corresponding second target information. The second target information is preset information corresponding to the association attribute. It is understood that this information includes facial information, password information, fingerprint information, numerical information, device information, or voice information, etc., and can also be other recordable information; specific details are not limited here.
[0056] Specifically, after receiving a message from a computer device requesting access to a target resource, the third or fourth network device determines that the first target information of the associated attribute in the message is genuine and valid if the first target information of the associated attribute matches the second target information corresponding to the associated attribute in the source attribute mapping table. Based on this, the message is further verified.
[0057] In the embodiments of this application, a first network device sends an association attribute and corresponding second target information to a third or fourth network device. The third or fourth network device verifies the authenticity of the first target information corresponding to the association attribute in the message based on the association attribute and the corresponding second target information. Verifying the message only after confirming the authenticity of the first target information corresponding to the association attribute improves work efficiency and saves network resources and costs.
[0058] In one possible implementation of the second aspect, the associated attribute includes at least one of the following:
[0059] Login mode, abnormal behavior, abnormal access relationship, terminal health, abnormal traffic, device security level, location information, security group information, or access time. It is understandable that other dynamic characteristics that can identify computer devices can also be associated attributes; specific details are not limited here.
[0060] In one possible implementation of the second aspect, the source identifier includes at least one of the following:
[0061] The computer device's IP address, device identifier, user identifier, user group or source port number, and other identifiers that can identify the computer device.
[0062] In one possible implementation of the second aspect, the target identifier includes at least one of the following:
[0063] The target resource's IP address, IP address prefix, partial or complete Uniform Resource Locator (URL) prefix, device identifier, identity identifier, security group, or port number.
[0064] A third aspect of this application provides an access control method, including:
[0065] The third network device receives a message from a computer device requesting access to a target resource. This message includes at least first indication information, an associated attribute, and first target information corresponding to the associated attribute. The target resource is the resource the computer device wishes to access. The first indication information includes at least a first target verification code. The associated attribute is an attribute associated with a source identifier. The first target information is the information corresponding to the associated attribute when the computer device accesses the target resource. The source identifier is included in the message.
[0066] Then, the third network device obtains the first target constraint item corresponding to the associated attribute, which is a preset constraint range for the information corresponding to the associated attribute.
[0067] If the first target information corresponding to the associated attribute belongs to the first target constraint item corresponding to the associated attribute, the third network device determines the second target verification code based at least on the first key, the associated attribute, and the first target constraint item corresponding to the associated attribute.
[0068] If the first target verification code is the same as the second target verification code, the third network device sends a message, enabling the computer device to access the target resource.
[0069] In the embodiments of this application, a third network device receives a message from a computer device requesting access to a target resource, and obtains a first target constraint item corresponding to the association attribute. Then, if the first target information corresponding to the association attribute belongs to the first target constraint item corresponding to the association attribute, a second target verification code is determined based at least on a first key, the association attribute, and a second target constraint item corresponding to the association attribute. If the first target verification code and the second target verification code are the same, the third network device sends a message, enabling the computer device to access the target resource. The third network device primarily verifies the message based on the association attribute and the first target information corresponding to the association attribute. Only when the obtained second target verification code is the same as the first target verification code can the computer device access the target resource. This avoids verifying the message based on ACLs, reducing the maintenance cost of ACLs, and allows real-time monitoring of the computer device's status. Furthermore, obtaining the second target verification code through the first key improves network security and minimizes the risk of malicious resource theft.
[0070] In one possible implementation of the third aspect, if the first target information corresponding to the associated attribute does not belong to the first target constraint item corresponding to the associated attribute, the third network device will discard the packet. And / or, if the first target verification code is different from the second target verification code, the third network device will discard the packet.
[0071] In the embodiments of this application, if the first target information corresponding to the associated attribute does not belong to the first target constraint item corresponding to the associated attribute, the third network device will discard the message, and / or if the first target verification code is different from the second target verification code, the third network device will discard the message, thereby preventing computer devices from accessing target resources, preventing resources from being maliciously stolen, and saving network resources.
[0072] In one possible implementation of the third aspect, the first target verification code includes a first verification code, which is obtained based at least on a first key, an associated attribute, and a first target constraint term corresponding to the associated attribute.
[0073] In embodiments of this application, the first target verification code can be a first verification code obtained by the computer device from the first network device, and is at least based on the first key, the associated attribute, and the first target constraint term corresponding to the associated attribute. The third network device re-verifies the first verification code determined by the first network device, thereby further improving network security.
[0074] In one possible implementation of the third aspect, the third network device determines the second target verification code based on the source identifier and / or target identifier and / or validity period, the first key, the association attribute, and the first target constraint item corresponding to the association attribute, wherein the target identifier is included in the message, and the validity period is the validity period of the first target verification code.
[0075] In embodiments of this application, a third network device can determine a second target verification code based on a source identifier and / or a target identifier and / or an expiration date, a first key, an association attribute, and a first target constraint item corresponding to the association attribute. This increases the flexibility and selectivity of the solution, and by determining the second target verification code through multiple factors, it improves network security.
[0076] In one possible implementation of the third aspect, if the first indication information also includes a first target constraint item corresponding to the associated attribute, the third network device obtains the first target constraint item corresponding to the associated attribute from the first indication information.
[0077] Alternatively, the third network device may directly obtain the first target constraint item corresponding to the associated attribute from the first network device.
[0078] In the embodiments of this application, when the first indication information further includes a first target constraint item corresponding to the associated attribute, the third network device obtains the first target constraint item corresponding to the associated attribute from the first indication information; alternatively, the third network device directly obtains the first target constraint item corresponding to the associated attribute from the first network device. This provides multiple application scenarios and demonstrates the selectivity of the solution.
[0079] In one possible implementation of the third aspect, the first indication information further includes a validity period, which is the expiration date of the first target verification code. The third network device determines that the first target verification code is valid based on this validity period. If the first target verification code is valid, then the message is verified based on the first target verification code; or, after the message is verified and the first target verification code is valid, the message is sent, ensuring the timeliness and validity of the message. Conversely, if the third network device determines that the first target verification code is invalid based on the validity period, the message is discarded.
[0080] In the embodiments of this application, the third network device determines the validity of the first target verification code based on a validity period, and then verifies the message based on the first target verification code, or sends the message only after the first target verification code is valid and the verification is successful. This ensures the timeliness and validity of the message. Furthermore, if the third network device determines that the first target verification code is invalid based on the validity period, it discards the message, which saves network resources and ensures that resources are not maliciously stolen.
[0081] In one possible implementation of the third aspect, the message further includes a second verification code, and then the third network device determines the third verification code based on the first indication information and the message. Specifically, the third network device obtains a new key based on the first indication information, and then obtains the third verification code based on the new key and the message.
[0082] Then, if the first target verification code is the same as the second target verification code, and the second verification code is the same as the third verification code, the third network device sends a message.
[0083] In the embodiments of this application, when the received message includes a second verification code, the third network device further obtains a third verification code based on the first indication information and the message. The third network device only sends the message if the first target verification code is the same as the second target verification code, and the second verification code is the same as the third verification code. The third network device verifies the message based on the second verification code, increasing the verification measures and reducing the possibility of malicious theft of target resources. Furthermore, since the third verification code is generated by a new key, it can better prevent messages from accessing target resources by tampering with the generated second verification code, thus ensuring network security.
[0084] In one possible implementation of the third aspect, before the third network device sends a message, the third network device obtains the associated attributes and the second target information corresponding to the associated attributes, wherein the second target information is preset information corresponding to the associated attributes. Specifically, the third network device can obtain the associated attributes and the second target information corresponding to the associated attributes from the first network device, or it can obtain them from other network devices that possess the associated attributes and the second target information corresponding to the associated attributes; this is not limited here. It is understood that the information includes facial information, password information, fingerprint information, numerical information, device information, or voice information, etc., and can also be other recordable information; this is not limited here.
[0085] If the first target information corresponding to the associated attribute matches the second target information corresponding to the associated attribute, the third network device determines that the first target information corresponding to the associated attribute is valid. Specifically, if the first target information is valid, the third network device then takes verification measures on the packet. Conversely, if the first target information is invalid, i.e., the first target information corresponding to the associated attribute does not match the second target information corresponding to the associated attribute, the third network device discards the packet.
[0086] In the embodiments of this application, the third network device obtains the association attribute and the second target information corresponding to the association attribute. If the second target information corresponding to the association attribute matches the first target information corresponding to the association attribute, the third network device determines that the first target information corresponding to the association attribute is valid. If the first target information of the association attribute is valid, then verification measures are taken on the message based on the first target information corresponding to the association attribute, which can reduce the waste of network resources and improve work efficiency.
[0087] In one possible implementation of the third aspect, the associated attribute includes at least one of the following:
[0088] Login mode, abnormal behavior, abnormal access relationship, terminal health, abnormal traffic, device security level, location information, security group information, or access time. It is understandable that other dynamic characteristics that can identify computer devices can also be associated attributes; specific details are not limited here.
[0089] In one possible implementation of the third aspect, the source identifier includes at least one of the following:
[0090] The computer device's IP address, device identifier, user identifier, user group or source port number, and other identifiers that can identify the computer device.
[0091] In one possible implementation of the third aspect, the target identifier includes at least one of the following:
[0092] The target resource's IP address, IP address prefix, part or URL prefix, device identifier, identity identifier, security group, or port number.
[0093] The fourth aspect of this application provides an access control method, including:
[0094] The fourth network device receives a message from a computer device requesting access to a target resource. This message includes at least first indication information, an association attribute, and first target information corresponding to the association attribute. The target resource is the resource the computer device wishes to access. The first indication information includes at least a first verification code, which is determined by the first network device based on a source identifier, a target identifier, an association attribute, and a first target constraint term corresponding to the association attribute. The source identifier indicates the computer device, the target identifier indicates the target resource, the association attribute is the attribute associated with the source identifier, the first target information is the information corresponding to the association attribute when the computer device accesses the target resource, and the first target constraint term is a preset constraint range for the information corresponding to the association attribute.
[0095] The fourth network device obtains the associated attributes and the second target information corresponding to the associated attributes. The second target information is preset information corresponding to the associated attributes. Specifically, the fourth network device obtains the associated attributes and the second target information corresponding to the associated attributes from the first network device, or it can obtain them from other network devices that have associated attributes and the second target information corresponding to the associated attributes. The specific method is not limited here.
[0096] If the first target information corresponding to the association attribute is consistent with the second target information corresponding to the association attribute, the fourth network device sends a message, and then the third network device that receives the message verifies the message based on the first target information corresponding to the association attribute.
[0097] In the embodiments of this application, the fourth network device receives a message from a computer device accessing a target resource, and then obtains the second target information corresponding to the associated attribute. If the first target information corresponding to the associated attribute is consistent with the second target information corresponding to the associated attribute, the fourth network device sends a message, so that the network device receiving the message can verify the message based on the first target information corresponding to the associated attribute, which can improve the overall work efficiency and save the occupation of network resources.
[0098] A fifth aspect of this application provides a computer device having the function of implementing the method of the first aspect or any possible implementation of the first aspect. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described function.
[0099] The computer device of the fifth aspect of this application performs the method described in the first aspect or any possible implementation of the first aspect.
[0100] A sixth aspect of this application provides a network device having the function of implementing the method of the second aspect or any possible implementation of the second aspect. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described function.
[0101] The network device of the sixth aspect of this application performs the method described in the second aspect or any possible implementation of the second aspect.
[0102] A seventh aspect of this application provides a network device that has the function of implementing the method of the third aspect or any possible implementation of the third aspect. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described function.
[0103] The network device of the seventh aspect of this application performs the method described in the third aspect or any possible implementation of the third aspect of this application.
[0104] An eighth aspect of this application provides a network device that has the function of implementing the method of the fourth aspect described above. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described function.
[0105] The network device of the eighth aspect of this application performs the method described in the fourth aspect of this application.
[0106] The ninth aspect of this application provides a communication device that may include a processor coupled to a memory, wherein the memory is used to store instructions, and the processor is used to execute the instructions in the memory to cause the communication device to perform the methods of the first aspect, any possible implementation of the first aspect, the second aspect, any possible implementation of the second aspect, the third aspect, any possible implementation of the third aspect, or the fourth aspect of this application.
[0107] The tenth aspect of this application provides another communication device, including a processor for executing a computer program (or computer-executable instructions) stored in a memory, which, when executed, causes the communication device to perform a method as described in the first aspect, any possible implementation of the first aspect, the second aspect, any possible implementation of the second aspect, the third aspect, any possible implementation of the third aspect, or the fourth aspect.
[0108] In one possible implementation, the processor and memory are integrated together;
[0109] In another possible implementation, the aforementioned memory is located outside the communication device.
[0110] The communication device also includes a communication interface for communicating with other devices, such as sending or receiving data and / or signals. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface.
[0111] The eleventh aspect of this application provides a computer-readable storage medium including computer-readable instructions that, when executed on a computer, cause the methods described in the first aspect, any possible implementation of the first aspect, the second aspect, any possible implementation of the second aspect, the third aspect, any possible implementation of the third aspect, or the fourth aspect of this application to be performed.
[0112] The twelfth aspect of this application provides a computer program product including computer-readable instructions that, when executed on a computer, cause the methods described in the first aspect, any possible implementation of the first aspect, the second aspect, any possible implementation of the second aspect, the third aspect, any possible implementation of the third aspect, or the fourth aspect of this application to be performed.
[0113] The thirteenth aspect of this application provides a chip including at least one processor and at least one interface circuit coupled to the processor. The at least one interface circuit is used to perform transceiver functions and send instructions to the at least one processor. The at least one processor is used to run computer programs or instructions and has the function of implementing the methods of the first aspect, any possible implementation of the first aspect, the second aspect, any possible implementation of the second aspect, the third aspect, any possible implementation of the third aspect, or the fourth aspect. The function can be implemented by hardware, by software, or by a combination of hardware and software. The hardware or software includes one or more modules corresponding to the above functions.
[0114] The fourteenth aspect of this application provides a communication system, including communication devices provided by various possible implementations of the fifth, sixth, and seventh aspects and the foregoing aspects. Attached Figure Description
[0115] Figure 1a A schematic diagram of the architecture of a communication system provided in an embodiment of this application;
[0116] Figure 1b A schematic diagram illustrating an application scenario provided in this application embodiment;
[0117] Figure 2 A schematic diagram of the access control method provided in the embodiments of this application;
[0118] Figure 3 A schematic diagram of an associated attribute list provided for an embodiment of this application;
[0119] Figure 4 A schematic diagram illustrating the determination of the first verification code provided in an embodiment of this application;
[0120] Figure 5 Another schematic diagram illustrating the determination of the first verification code provided in an embodiment of this application;
[0121] Figure 6 A schematic diagram of the first indication information provided in the embodiments of this application;
[0122] Figure 7 Another schematic diagram illustrating the determination of the first verification code provided in an embodiment of this application;
[0123] Figure 8 A schematic diagram of a message provided in an embodiment of this application;
[0124] Figure 9 Another schematic diagram of a message provided in an embodiment of this application;
[0125] Figure 10 Another schematic diagram illustrating an application scenario provided in the embodiments of this application;
[0126] Figure 11 A schematic diagram of the structure of a computer device provided in an embodiment of this application;
[0127] Figure 12 A schematic diagram of the structure of a network device provided in an embodiment of this application;
[0128] Figure 13 Another schematic diagram of the network device provided in the embodiments of this application;
[0129] Figure 14 This is a schematic diagram of the communication device provided in an embodiment of this application. Detailed Implementation
[0130] This application provides access control methods and related devices, which can be applied in IP networks, such as enterprise campus networks or data center networks, to reduce the cost of ACL operation and maintenance and improve network security.
[0131] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms are interchangeable where appropriate; this is merely a way of distinguishing objects with the same attributes in the embodiments of this application. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion, so that a process, method, system, product, or apparatus that comprises a series of elements is not necessarily limited to those elements, but may include other elements not explicitly listed or inherent to those processes, methods, products, or apparatuses.
[0132] Before introducing the embodiments of this application, a brief introduction to common ACL-based access control methods will be given to facilitate subsequent understanding of the embodiments of this application.
[0133] In current enterprise campus networks, data center networks, and other boundary-based network scenarios, packets from computer devices accessing target resources typically rely on network devices at the aggregation or core layers that have deployed Access Control Lists (ACLs) for verification. However, ACL entries are updated frequently and are time-consuming, requiring manual maintenance. Therefore, for an enterprise campus network, ACLs are overly complex and costly, necessitating real-time management, updating, or deletion of ACL entries, resulting in very high operational costs.
[0134] To address the aforementioned problems, embodiments of this application provide an access control method and related devices. These embodiments are applied in IP networks, such as enterprise campus networks or data center networks, to verify packets sent by computer devices to access target resources based on the associated attributes of the computer devices and the information corresponding to those attributes. This reduces the cost of ACL maintenance and improves network security.
[0135] The communication system used in the embodiments of this application will be described below with reference to the accompanying drawings. Those skilled in the art will recognize that, with technological advancements and the emergence of new scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems. Please refer to the following for details. Figure 1a , Figure 1a A schematic diagram of the architecture of the communication system provided in the embodiments of this application specifically includes:
[0136] The computer device 101, the first network device 102, and the third network device 103 may also include the device 104 to which the target resource belongs.
[0137] For specific applications based on this communication system, please refer to [link / reference]. Figure 1b As shown, Figure 1b This is a schematic diagram illustrating an application scenario provided in an embodiment of this application. In this scenario, computer device 101 sends a source identifier and a target identifier to a first network device 102. The first network device 102 then determines an association attribute and a first target constraint corresponding to the association attribute based on the source identifier, the target identifier, and an access control policy. The first network device 102 also determines a first verification code based at least on a first key, the association attribute, and the first target constraint corresponding to the association attribute. Next, computer device 101 receives first indication information sent by the first network device, which includes at least the first verification code. Computer device 101 then determines the association attribute and the first target information corresponding to the association attribute. Finally, computer device 101 sends a message to access the target resource, which includes at least the aforementioned first indication information, the association attribute, and the first target information corresponding to the association attribute.
[0138] It should be noted that, among them, the source identifier indicates computer device 101, the target identifier indicates target resource, the target resource is the resource to be accessed by the computer device, the access control policy includes the conditions for the computer device to access the target resource, the associated attribute is the attribute associated with the source identifier, the first target constraint item is the preset constraint range of the information corresponding to the associated attribute, and the number of associated attributes is at least one.
[0139] Then, the third network device 103 receives a message from the computer device 101 requesting access to the target resource. The message includes at least first indication information, an association attribute, and a first target constraint item corresponding to the association attribute. The first indication information includes at least a first target verification code. The third network device 103 then obtains the first target constraint item corresponding to the association attribute. If the first target information corresponding to the association attribute does not belong to the first target constraint item corresponding to the association attribute, the third network device 103 discards the message. Alternatively, if the first target information corresponding to the association attribute belongs to the first target constraint item corresponding to the association attribute, the third network device 103 determines a second target verification code based at least on the first key, the association attribute, and the first target constraint item corresponding to the association attribute. If the second target verification code is the same as the first target verification code, the third network device 103 sends a message, allowing the computer device 101 to access the target resource normally from the device 104 to which the target resource belongs.
[0140] It should be noted that the first target verification code in the message received by the third network device may be the first verification code determined by the first network device 102, or it may be a verification code forged to steal the target resource. No specific limitation is made here.
[0141] Optionally, computer device 101 may be a terminal device with communication capabilities. Examples include Internet of Things (IoT) devices (e.g., sensors, electricity meters, water meters, etc.), vehicle-to-everything (V2X) devices, stations (STs) in wireless local area networks (WLANs), personal digital assistant (PDA) devices, handheld devices with wireless communication capabilities (such as mobile phones), computing devices or other processing devices connected to a wireless modem, in-vehicle devices, wearable devices (also known as wearable smart devices), tablet computers, or computers with wireless transceiver capabilities.
[0142] Optionally, the first network device 102 and the device 104 to which the target resource belongs can be network devices such as application servers, controllers, or personal computers. The third network device 103 can be a gateway device (such as a router, switch, firewall, or hub, or other network devices with packet forwarding capabilities) or an application server.
[0143] It should be noted that the communication system described in the embodiments of this application is for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and does not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0144] The access control method of this application embodiment will be described more intuitively below with reference to the accompanying drawings. Those skilled in the art will understand that, with the development of technology and the emergence of new scenarios, the technical solutions provided in this application embodiment are also applicable to similar technical problems. Please refer to the following for details. Figure 2 , Figure 2 A schematic diagram of the access control method provided in the embodiments of this application specifically includes:
[0145] 201. The computer device sends the source identifier and the target identifier to the first network device.
[0146] The computer device sends a source identifier and a destination identifier to the first network device. The source identifier indicates the computer device, and the destination identifier indicates the target resource, which is the resource that the computer device wants to access.
[0147] Optionally, the source identifier may include at least one of the following: the computer device's IP address, the computer device's device identifier, the user identifier corresponding to the computer device, the user group to which the computer device belongs, or the source port number. It is understood that, in practice, other identifiers that can represent or represent the computer device are also acceptable; no specific restrictions are imposed here.
[0148] Optionally, the target identifier may include at least one of the following: the IP address of the target resource, the IP address prefix of the target resource, part or all of the URL prefix of the target resource, the device identifier of the target resource, the identity identifier of the target resource, the security group to which the target resource belongs, or the port number of the target resource. It is understood that, in practice, other identifiers representing or identifying the target resource are also acceptable; no specific restrictions are imposed here.
[0149] Alternatively, prior to step 201, the computer device may establish a secure and trusted channel with the first network device through the Transport Layer Security (TLS) protocol, out-of-band configuration, or other means, and then send the source identifier and the target identifier through the secure and trusted channel to prevent the source identifier and the target identifier from being tampered with or leaked.
[0150] 202. The first network device determines the associated attributes and the first target constraint item corresponding to the associated attributes based on the source identifier, the target identifier, and the access control policy.
[0151] After receiving the source identifier and destination identifier from the computer device, the first network device determines the associated attribute and the first target constraint item corresponding to the associated attribute based on the source identifier, destination identifier, and access control policy. The associated attribute is the attribute associated with the source identifier, and the first target constraint item is a preset constraint range for the information corresponding to the associated attribute.
[0152] Specifically, the first network device can use the received source identifier and destination identifier as query conditions to determine the associated attribute corresponding to the source identifier according to the access control policy. The number of associated attributes is at least one. Optionally, the associated attribute may include at least one of the following: login mode, behavior anomaly degree, access relationship anomaly degree, terminal health, traffic anomaly degree, device security level, location information, security group information, or access time. Additionally, optionally, the associated attribute may be identified by its name, or by preset letters, numbers, Chinese characters, combinations of Chinese characters, or strings, etc., without further limitation here.
[0153] Then, the first network device can determine the first target constraint item corresponding to the associated attribute based on the associated attribute. For example, the associated attribute and the corresponding first target constraint item can be represented in the form of key-value pairs. The first target constraint item can be determined through the key-value pairs. Here, the first target constraint item is the preset constraint range of the information corresponding to the associated attribute. Optionally, the information in the first target constraint item includes facial information, password information, fingerprint information, numerical information, letters or letter combinations, strings, device information or voice information, etc., and can also be other recordable information, such as letters and letter combinations, etc., which are not limited here. Optionally, the first target constraint item can be a combination of the aforementioned information (e.g., [fingerprint information, facial information]), or it can be a range between information (e.g., [2-4]), or it can be a word or word combination (e.g., good). It is understood that the first target constraint item can be set according to the actual situation, which is not limited here.
[0154] Examples of key-value pairs representing associated attributes and their corresponding first target constraints include: (Login mode, [fingerprint information, face information]), (behavior anomaly, [2-3]), or (access relationship anomaly, [2-4]), (terminal health, good), or (traffic anomaly, [0]). It should be noted that the first target constraint can include multiple pieces of information or a single piece of information; no specific limitation is made here.
[0155] It is understood that the embodiments of this application use key-value pairs as an example to illustrate the associated attributes and the first target constraint terms corresponding to the associated attributes. This is merely an example and does not constitute a substantial limitation on the embodiments of this application. In practice, other implementation methods that can achieve the same effect are also applicable to this application, and no specific limitation is made here.
[0156] In one possible implementation, the first network device determines an associated attribute entry based on the source identifier, destination identifier, and access control policy. This associated attribute entry is an entry that includes at least an associated attribute and a corresponding first target constraint. The first network device then determines the associated attribute and the corresponding first target constraint based on this associated attribute entry. Other forms of the associated attribute list can be found in [reference needed]. Figure 3 , Figure 3 This is a schematic diagram of an associated attribute list provided in an embodiment of this application, including associated attributes and first target constraint items corresponding to the associated attributes. It is understood that... Figure 3 This is merely an example to help understand the embodiments of this application, and does not constitute a substantial limitation on the embodiments of this application. In actual practice, the list of associated attributes can also be represented in other forms, which are not limited here.
[0157] In the embodiments of this application, the first network device determines the list of associated attributes based on the source identifier, the destination identifier, and the access control policy, and then determines the associated attributes and the first target constraint items corresponding to the associated attributes. This can conveniently and effectively manage the associated attributes and the first target constraint items corresponding to the associated attributes, saving operation and maintenance costs.
[0158] It should be noted that access control policies include the conditions for computer devices to access target resources. Specific implementation forms include ACLs, user control lists (UCLs), or attribute policy lists (APLs). It is understood that there may be other implementation forms as well, but no specific restrictions are made here.
[0159] 203. The first network device determines the first verification code based at least on the first key, the associated attribute, and the first target constraint item corresponding to the associated attribute.
[0160] The first network device determines the first verification code based at least on the first key, the associated attribute, and the first target constraint item corresponding to the associated attribute.
[0161] For example, please refer to [link / reference] for easier understanding. Figure 4 , Figure 4 This is a schematic diagram illustrating the determination of a first verification code according to an embodiment of this application. The first network device obtains the first verification code by using a first key, an associated attribute, and a first target constraint corresponding to the associated attribute as inputs to a security algorithm. Optionally, the security algorithm can be a hash-based message authentication code algorithm (HMAC), a cipher-based message authentication code algorithm (CMAC), or a digital signature algorithm. It is understood that in practice, other algorithms that achieve the same effect can also be used; no specific limitation is made here.
[0162] It should be noted that when determining the first verification code, the first key can be either a symmetric key or an asymmetric public-private key pair. It can be understood that the first key can be determined according to the actual situation, and there is no specific limitation here.
[0163] In one possible implementation, the first network device determines the first verification code based on the source identifier and / or target identifier and / or validity period, the first key, the associated attribute, and the first target constraint item corresponding to the associated attribute. The validity period is the effective period of the first verification code. Optionally, this validity period can be preset in the access control policy, preset on the first network device, or in other network devices that record access-related information. It is understood that, in practice, the choice can be made according to the actual situation, and no specific limitation is made here.
[0164] Please refer to details. Figure 5 , Figure 5 This is another schematic diagram illustrating the determination of the first verification code provided in an embodiment of this application. The specific content is the same as described above. Figure 4 Similar to what is shown, the specifics will not be elaborated here.
[0165] In the embodiments of this application, the first network device determines the first verification code based on the source identifier and / or target identifier and / or validity period, the first key, the association attribute, and the first target constraint item corresponding to the association attribute. The determination of the first verification code by more factors increases the flexibility of the scheme, and the validity period limits the first verification code to prevent access to the target resource outside the validity period, thereby improving the security of network security.
[0166] 204. The first network device sends the first instruction information to the computer device.
[0167] The first network device sends a first instruction message to the computer device. This first instruction message includes at least a first verification code.
[0168] Alternatively, the first instruction information may also include a validity period, associated attributes, or a first target constraint item corresponding to the associated attributes. For an example, please refer to [link to example information]. Figure 6 , Figure 6 A schematic diagram of the first instruction information provided for an embodiment of this application.
[0169] For example, if the source identifier and target identifier received by the first network device are included in a token request sent by the computer device, the first network device can send the first instruction information to the computer device in the form of a token, and the first instruction information still participates in subsequent operations in the form of a token.
[0170] In one possible implementation, when the first instruction information is sent in the form of a token, step 203 above, when determining the first verification code, can also use the token's identification number as input to the security algorithm. This ensures the uniqueness of the first verification code, preventing it from being stolen or tampered with, and improving network security. Please refer to [link / reference] for details. Figure 7 , Figure 7 Another schematic diagram illustrating the determination of the first verification code provided in this application embodiment, wherein the specific content is the same as described above. Figure 5 Similarly, details will not be elaborated here.
[0171] It is understood that the first instruction information, using a token as an example, is merely provided as an example to illustrate a specific application method in order to understand the embodiments of this application. In actual practice, the first instruction information can also be sent in other forms, or the first instruction information can be directly sent to a computer device. No specific limitation is made here.
[0172] In one possible implementation, the first network device determines a second key based on the first indication information, and then the first network device also sends the second key to the computer device. The computer device can generate a second verification code based on the second key, which is used to verify the message of the computer device accessing the target resource.
[0173] For example, the first network device obtains the second key by using the third key and the first indication information as inputs to the key derivation function. Optionally, the third key can be the same as the aforementioned first key, or it can be a randomly generated key, similar to the aforementioned first key, and will not be elaborated here. It is understood that in actual practice, the specific third key can be determined by the actual situation, and is not limited here.
[0174] In the embodiments of this application, the first network device obtains the second key based on the first instruction information and sends it to the computer device, so that the computer device generates a second verification code. The second verification code is used to verify the message of the computer device accessing the target resource, which greatly enhances the security of network security. Moreover, the second key is obtained from the first instruction information, which is more secure and can prevent tampering or forgery to a greater extent.
[0175] 205. The computer device acquires the associated attributes and determines the first target information corresponding to the associated attributes, and sends a message to access the target resource.
[0176] The computer device acquires an associated attribute and then determines the first target information corresponding to the associated attribute. This first target information is the information corresponding to the associated attribute when the computer device accesses a target resource. The computer device then sends a message to access the target resource. This message includes at least first indication information, the associated attribute, and the first target information corresponding to the associated attribute. The number of associated attributes is at least one. For an example, please refer to [link to example message]. Figure 8 , Figure 8 This is a schematic diagram of a message provided in an embodiment of this application.
[0177] It should be noted that the first target information corresponding to the associated attribute can be facial information, password information, fingerprint information, numerical information, letter or letter combination information, numerical and letter combination information, string information, device information or voice information, etc., or other recordable information, which is not limited here.
[0178] In addition, for example, the associated attributes and the first target information corresponding to the associated attributes in the message can be represented in the form of key-value pairs. For example, if the associated attribute is login mode and the first target information corresponding to the login mode is the collected face information, it can be represented by key-value pairs as (login mode, face information). It is understood that the key-value pairs are used here only as an example to understand the embodiments of this application and do not constitute a substantial limitation on this application. Other methods that can achieve the same effect or purpose are also possible, and no specific limitation is made here.
[0179] In one possible implementation, the computer device receives a second key sent by the first network device, and determines a second verification code based on the second key and the message, then sends the second verification code. For example, the computer device determines the second verification code based on the second key and all or part of fixed information in the message; for instance, the computer device determines the second verification code using payload information in the message, or payload information combined with source identifiers, source identifiers combined with target identifiers, etc., along with the second key. Furthermore, the computer device can add the second verification code to the message and send it together, such as... Figure 9 As shown, Figure 9 Another schematic diagram of a message provided in an embodiment of this application.
[0180] In the embodiments of this application, the computer device obtains the second verification code through the second key and the message. The second verification code is used to verify the message, which increases the measures for verifying the message. Moreover, since the second verification code is obtained from the second key, it can better prevent the second verification code from being tampered with or forged, and greatly improve the security of network security.
[0181] In one possible implementation, the aforementioned first indication information, second verification code, associated attribute, and first target information corresponding to the associated attribute can be in the message protocol header field. Optionally, the message protocol header can specifically be an application layer header, transport layer header, or network layer header. For specific examples, the aforementioned first indication information, second verification code, associated attribute, and first target information corresponding to the associated attribute can be in the extension fields or optional headers of Internet Protocol version 6 (IPv6) or Internet Protocol version 4 (IPv4). Alternatively, the aforementioned first indication information, second verification code, associated attribute, and first target information corresponding to the associated attribute can be in the options header of the Transmission Control Protocol (TCP). It is understood that the foregoing examples are merely for understanding the embodiments of this application. In practice, the aforementioned first indication information, second verification code, associated attribute, and first target information corresponding to the associated attribute can also be in other positions in other messages, which are not limited here.
[0182] In one possible implementation, the computer device obtains the association attribute from first indication information including the association attribute, or the computer device obtains the association attribute from a second network device, or the computer device obtains the association attribute from second indication information, where the second indication information is information including the association attribute possessed by the computer device. These are explained below:
[0183] Method 1: The first instruction information also includes associated attributes, and the computer device obtains the associated attributes from the first instruction information.
[0184] The first instruction information sent by the first network device to the computer device also includes associated attributes. The computer device can directly obtain the associated attributes corresponding to the computer device's access to the target resource from the first instruction information. This improves work efficiency and ensures consistency with the associated attributes just determined in the first network device.
[0185] Method 2: The computer device obtains the associated attributes from the second network device.
[0186] The computer device obtains associated attributes from the second network device. For an example, please refer to [link to example]. Figure 10 , Figure 10 This is another schematic diagram illustrating an application scenario provided in this application embodiment. The second network device may be another server, controller, or other network device with access control policies, or a network device with the associated attributes corresponding to the computer device. It is understood that the second network device can also be other network devices capable of obtaining associated attributes; this is not specifically limited here.
[0187] It should be noted that, in the embodiments of this application, the order of steps 205 and 204 is not limited.
[0188] In the embodiments of this application, the computer device obtains the associated attributes from the second network device, which can reduce the amount of data in the first indication information and save network resources.
[0189] Method 3: The computer device obtains the associated attributes from the second instruction information, which is information including the associated attributes possessed by the computer device.
[0190] Optionally, the second instruction information may be a pre-defined table entry including associated attributes corresponding to the computer device, or other forms of information. It is understood that the second instruction information may include only associated attributes, or it may include other information; no specific limitation is made here.
[0191] It should be noted that, in the embodiments of this application, the order of steps 205 and 204 is not limited.
[0192] In the embodiments of this application, the computer device obtains the associated attributes from the second indication information it has locally available, which can improve work efficiency and save network resources.
[0193] 206. The third network device receives a message from the computer device requesting access to the target resource.
[0194] The third network device receives a message from the computer device accessing the target resource. The message includes at least first indication information, associated attributes, and first target information corresponding to the associated attributes, wherein the first indication information includes at least a first target verification code.
[0195] Optionally, the first target verification code may be a first verification code obtained by the aforementioned first network device based at least on the first key, the associated attribute, and the first target constraint item corresponding to the associated attribute, or the first target verification code may be a forged or tampered verification code used to steal target resources.
[0196] Optionally, the third network device receives a message sent by the computer device to access the target resource, or the third network device receives a message forwarded by the fourth network device to access the target resource from the computer device.
[0197] For example, if the third network device is an access layer network device on the computer device side, it directly receives the message sent by the computer device to access the target resource. Alternatively, if the third network device is a core layer network device, it receives the message forwarded by the fourth network device to access the target resource from the computer device. It is understood that the third network device being an access layer network device or a core layer network device is merely an example; the third network device could also be other network devices in the message forwarding path. In practice, the third network device is the network device that deploys the verification code for the first target in the message according to actual needs; specific details are not limited here.
[0198] In one possible implementation, the first network device sends an association attribute and corresponding second target information to the fourth network device. The second target information is preset information corresponding to the association attribute. The fourth network device receives a message from a computer device accessing a target resource. This message includes at least first indication information, an association attribute, and corresponding first target information. The fourth network device then acquires the association attribute and corresponding second target information. If the first target information and the second target information match, the fourth network device sends the message, and the third network device receiving the message executes subsequent steps. If the first target information and the second target information do not match, the fourth network device discards the message.
[0199] Optionally, the fourth network device obtains the association attribute and the corresponding second target information from the first network device, or from the second network device, or the fourth network device may also obtain it from other network devices that possess the association attribute and the corresponding second target information; the specific details are not limited here. As described above. Figure 10 As shown in the diagram, the fourth network device obtains the associated attributes and the corresponding second target information from the first network device. It can be understood that... Figure 10 This is merely an example to facilitate understanding of the embodiments of this application and does not constitute a substantial limitation on this application. It should be noted that the second target information may be preset facial information, password information, fingerprint information, numerical information, letter or letter combination information, numerical and letter combination information, device information or voice information, etc., or other recordable information, which is not specifically limited here.
[0200] Optionally, the fourth network device can be a gateway device (such as a router, switch, firewall, or hub, which are network devices with packet forwarding capabilities) or an application server or other network device.
[0201] In the embodiments of this application, after receiving a message from a computer device accessing a target resource, the fourth network device verifies the authenticity of the message. If the first target information corresponding to the associated attribute in the message matches the second target information corresponding to the associated attribute, the message is determined to be authentic and valid, and only then is the message sent to the third network device for further verification. If the first target information corresponding to the associated attribute in the message does not match the second target information corresponding to the associated attribute, the fourth network device discards the message, ensuring that the message received by the third network device from the fourth network device is valid before performing subsequent message verification operations. This improves overall work efficiency and saves network resource usage.
[0202] 207. The third network device obtains the first target constraint item corresponding to the associated attribute.
[0203] The third-party network device obtains the first target constraint item corresponding to the associated attribute.
[0204] Optionally, if the first indication information also includes a first target constraint item corresponding to the associated attribute, the third network device obtains the first target constraint item corresponding to the associated attribute from the first indication information. Alternatively, the third network device directly obtains the first target constraint item corresponding to the associated attribute from the first network device, that is, the first target constraint item corresponding to the associated attribute sent by the first network device to the third network device. In the embodiments of this application, multiple application scenarios are provided, reflecting the selectivity of the solution.
[0205] In one possible implementation, if the packet received by the third network device has not undergone the authenticity verification performed by the fourth network device as described in step 206, before any of the subsequent steps 208, 209, or 210, the third network device further acquires the association attribute and the second target information corresponding to the association attribute, wherein the second target information is preset information corresponding to the association attribute. Then, if the first target information corresponding to the association attribute matches the second target information corresponding to the association attribute, the third network device determines that the first target information corresponding to the association attribute is valid. Only then does the third network device continue with the subsequent steps. Alternatively, if the first target information of the association attribute does not match the second target information corresponding to the association attribute, the third network device discards the packet.
[0206] Optionally, the third network device obtains the association attribute and the corresponding second target information from the first network device; that is, the association attribute and the corresponding second target information sent by the first network device to the third network device. Alternatively, the third network device obtains the association attribute and the corresponding second target information from the second network device. It is understood that the third network device can also obtain it from other network devices that possess the association attribute and the corresponding second target information; this is not specifically limited here. The specific implementation method is similar to the implementation method of the fourth network device in step 206 above, and will not be described in detail here.
[0207] In the embodiments of this application, the third network device performs subsequent operations on the message that confirms the validity of the first target information corresponding to the associated attribute, which can improve work efficiency and reduce the waste of network resources.
[0208] In one possible implementation, before any of the subsequent steps 208, 209, or 210, the first indication information also includes a validity period, and the third network device determines that the first verification code is valid based on the validity period. If the first verification code is valid, the third network device continues to execute subsequent steps to verify the message. Alternatively, if the first verification code is invalid, the third network device discards the message.
[0209] Optionally, the third network device may determine the validity of the first verification code if the time when it receives the message is within the validity period; or if the time when the third network device verifies the first verification code based on the validity period is within the validity period; or if the time when the computer device accesses the target resource is within the validity period. It is understood that in practice, the validity of the first verification code can be verified based on the validity period according to actual needs, and no specific limitation is made here.
[0210] In the embodiments of this application, the first indication information also includes a validity period. The third network device determines that the first verification code is valid based on the validity period. If the first verification code is valid, the third network device performs subsequent steps to verify the message; or, if the first verification code is invalid, the third network device discards the message. This ensures the timeliness and validity of the message, saves network resources, and ensures that resources are not maliciously stolen.
[0211] In one possible implementation, if the first target information corresponding to the associated attribute belongs to the first target constraint term corresponding to the associated attribute, then proceed with steps 208 and 209 or 210; or, if the first target information corresponding to the associated attribute does not belong to the first target constraint term corresponding to the associated attribute, then proceed with step 210. These are explained below:
[0212] Method 1: When the first target information corresponding to the associated attribute belongs to the first target constraint item corresponding to the associated attribute:
[0213] 208. The third network device determines the second target verification code based at least on the first key, the associated attributes, and the first target constraint item corresponding to the associated attributes.
[0214] For example, if a certain associated attribute in the message is a login mode, and its corresponding first target constraint is [face information, fingerprint information], and the first target information corresponding to the login mode is face information that matches the face information in the first target constraint, then the third network device determines that the first target information corresponding to the login mode belongs to the first target constraint corresponding to the login mode. The third network device then determines the second target verification code based at least on the first key, the associated attribute, and the first target constraint corresponding to the associated attribute. It is understood that this example is merely for understanding the embodiments of this application and does not substantially limit the embodiments of this application.
[0215] It should be noted that step 208 is similar to step 203 above, in which the first network device determines the first verification code based at least on the first key, the associated attribute, and the first target constraint item corresponding to the associated attribute. The specifics will not be repeated here.
[0216] In one possible implementation, the third network device determines the second target verification code based on the source identifier and / or target identifier and / or validity period, the first key, the association attribute, and the second target constraint item corresponding to the association attribute in the message. It should be noted that the specific implementation method is the same as described above. Figure 7 The method described is similar, and will not be repeated here.
[0217] In the embodiments of this application, the third network device determines the second target verification code based on the source identifier and / or target identifier and / or validity period, first key, association attribute and second target constraint item corresponding to the association attribute in the message. By determining the second target verification code through multiple factors, the security of network security can be improved, and the flexibility and selectivity of the scheme can be increased.
[0218] Optionally, the first key may be preset on the third network device or may be sent by the first network device. The specific form of the first key has been described in detail in step 203 above, and will not be repeated here.
[0219] Alternatively, before the third network device receives the first key sent by the first network device, the third network device may establish a secure and trusted channel with the first network device through the Transport Layer Security (TLS) protocol, out-of-band configuration, or other means, and then obtain the first key through this secure and trusted channel to prevent the first key from being tampered with or leaked.
[0220] In one possible implementation, as described above Figure 9 The message also includes a second verification code, and the third network device further determines a third verification code based on the first indication information and the message. For example, the third network device first obtains a new key based on the first indication information and the third key, and then obtains the third verification code based on the new key and some or all of the fixed information in the message. This is similar to steps 204 and 205 described above, and will not be repeated here. It should be noted that the third key can be a shared key preset on both the first and third network devices, or it can be a key randomly derived by the first network device and sent to the third network device. It is understood that in practice, the third key can be determined according to requirements, and no specific limitation is made here.
[0221] Optionally, if the first target verification code and the second target verification code are the same, proceed to step 209; or if the first target verification code and the second target verification code are different, proceed to step 210. These are explained below:
[0222] Method a: If the first target CAPTCHA and the second target CAPTCHA are the same, proceed to step 209:
[0223] 209. The third network device sends a message.
[0224] If the first target verification code is the same as the second target verification code, the third network device sends a message, enabling the computer device to access the target resource.
[0225] In one possible implementation, the message also includes a second verification code. If the first target verification code is the same as the second target verification code, and the second verification code is the same as the third verification code, the third network device sends the message, enabling the computer device to access the target resource.
[0226] In the embodiments of this application, the third network device sends a message only when the first target verification code is the same as the second target verification code, and the second verification code is the same as the third verification code, so that the computer device can access the target resource, providing network security and preventing the malicious theft of resources to a greater extent, thus ensuring network security.
[0227] Method b: If the second and third verification codes are different, proceed to step 210:
[0228] 210. The third network device discards the message.
[0229] If the first target verification code is different from the second target verification code, the third network device will discard the message.
[0230] In one possible implementation, if the second verification code and the third verification code are different, the third network device will discard the message.
[0231] In the embodiments of this application, the third network device discards the packet, which can prevent the computer device from accessing the target resource, prevent the resource from being maliciously stolen, and save network resources.
[0232] Method 2: If the first target information corresponding to the associated attribute does not belong to the first target constraint item corresponding to the associated attribute, proceed to step 210:
[0233] 210. The third network device discards the message.
[0234] For example, if a certain associated attribute in the message is a login mode, and the first target information corresponding to the login mode is password information, and the first target constraint item corresponding to the login mode is [face information, fingerprint information], then the first target information corresponding to the login mode does not belong to the corresponding first target constraint item, and the third network device will discard the message. It is understood that this example is only used to understand the embodiments of this application and does not substantially limit the embodiments of this application.
[0235] In this embodiment, the first network device determines the first verification code based on the first key, the association attribute of the computer device, and the first target constraint item corresponding to the association attribute. The message sent by the computer device to access the target resource includes at least the first indication information, the association attribute, and the first target information corresponding to the association attribute. The third network device verifies the message based on the first indication information, the association attribute, and the first target information corresponding to the association attribute in the message. The association attribute can monitor the status of the computer device in real time, prevent the target resource from being maliciously stolen to the greatest extent possible, improve network security, and reduce the application of ACL during the verification process, thereby reducing the cost of ACL operation and maintenance.
[0236] To achieve the functions of the methods provided in the embodiments of this application, the computer device, the first network device, the second network device, the third network device, and the fourth network device may each include a hardware structure and / or a software module, implementing the above functions in the form of a hardware structure, a software module, or a hardware structure plus a software module. Whether a particular function is executed in the form of a hardware structure, a software module, or a hardware structure plus a software module depends on the specific application and design constraints of the technical solution.
[0237] like Figure 11 As shown in the illustration, this application also provides a computer device 1100. Please refer to the following for details. Figure 11 , Figure 11 This is a schematic diagram of a computer device provided in an embodiment of this application. The computer device 1100 can be a terminal device with communication functions, as specifically illustrated above, and will not be repeated here. In one possible implementation, the computer device 1100 may include modules or units corresponding to the methods / operations / steps / actions performed by the computer device in the above method embodiments. These units can be hardware circuits, software, or a combination of hardware circuits and software. In one possible implementation, the computer device 1100 may include: a sending unit 1101, a receiving unit 1102, an acquisition unit 1103, and a determining unit 1104. The sending unit 1101 can be used to perform the steps of sending a source identifier and a target identifier, and sending a message to access the target resource, as described in the above method embodiments. The receiving unit 1102 can be used to perform the steps of receiving first indication information, as described in the above method embodiments. The acquisition unit 1103 can be used to perform the steps of acquiring associated attributes, as described in the above method embodiments. The determining unit 1104 can be used to perform the steps of determining first target information corresponding to the associated attributes, as described in the above method embodiments.
[0238] In this embodiment, the sending unit 1101 sends a source identifier and a target identifier to the first network device. Then, the receiving unit 1102 receives first indication information sent by the first network device. The first indication information includes at least a first verification code, which is determined based at least on a first key, an association attribute, and a first target constraint item corresponding to the association attribute. The association attribute and the first target constraint item corresponding to the association attribute are obtained based on the source identifier, the target identifier, and an access control list. Then, the obtaining unit 1103 obtains the association attribute, and the determining unit 1104 determines the first target information corresponding to the association attribute. Next, the sending unit 1104 sends a message to access the target resource. The message includes at least the first indication information, the association attribute, and the first target information corresponding to the association attribute. The message includes the first indication information, the association attribute, and the first target information corresponding to the association attribute. This verification ensures the timeliness and authenticity of the message, greatly ensuring that the target resource is not maliciously stolen, improving network security, and reducing the application of ACLs, thus reducing the cost of ACL maintenance.
[0239] In other possible designs, the sending unit 1101, receiving unit 1102, acquiring unit 1103, or determining unit 1104 can execute the methods / operations / steps / actions in various possible implementations of the computer device in the above method embodiments, respectively. Details will not be elaborated here. Furthermore, the beneficial effects of the computer device in other possible designs are described above. Figure 2 The beneficial effects of various implementation methods for one-to-one correspondence between computer devices in the Chinese method embodiments will not be elaborated here.
[0240] It should be noted that, Figure 11 The information interaction and execution process between modules / units in the computer device described in the corresponding embodiments are similar to those in this application. Figure 2 The corresponding method embodiments are based on the same concept, and the specific details can be found in the description of the method embodiments shown above in this application, which will not be repeated here.
[0241] like Figure 12 As shown in the illustration, this application also provides a network device 1200. Please refer to the following for details. Figure 12 , Figure 12This is a schematic diagram of a network device provided in an embodiment of this application. The network device 1200 can be a network device such as an application server, controller, gateway device, or personal computer. In one possible implementation, the network device 1200 may include modules or units corresponding to the methods / operations / steps / actions performed by the first network device in the above method embodiments. The unit may be hardware circuitry, software, or a combination of hardware circuitry and software implementation. In one possible implementation, the network device 1200 may include: a receiving unit 1201, a first determining unit 1202, a second determining unit 1203, and a sending unit 1204. The receiving unit 1201 can be used to perform the steps of receiving a source identifier and a target identifier as in the above method embodiments. The first determining unit 1202 can be used to perform the steps of determining an association attribute and a first target constraint item corresponding to the association attribute as in the above method embodiments. The second determining unit 1203 can be used to perform the steps of determining a first verification code as in the above method embodiments. The sending unit 1204 can be used to perform the steps of sending first indication information including at least the first verification code as in the above method embodiments.
[0242] In this embodiment, the receiving unit 1201 receives a source identifier and a target identifier sent by a computer device. Then, the first determining unit 1202 determines an association attribute and a first target constraint item corresponding to the association attribute based on the source identifier, the target identifier, and the access control policy. Next, the second determining unit 1203 determines a first verification code based at least on a first key, the association attribute, and the first target constraint item corresponding to the association attribute. The sending unit 1204 sends first indication information, including at least the first verification code, to the computer device, causing the computer device to send a message to access the target resource based on the first indication information. The first verification code is determined based on the association attribute corresponding to the computer device and the first target constraint item corresponding to the association attribute, reducing the possibility of the first verification code being forged or tampered with, improving network security, and verifying the message based on the first verification code reduces the application of ACLs and reduces ACL maintenance costs.
[0243] In other possible designs, the receiving unit 1201, the first determining unit 1202, the second determining unit 1203, or the sending unit 1204 can execute the methods / operations / steps / actions in various possible implementations of the first network device in the above method embodiments, respectively. Details will not be elaborated here. Furthermore, the beneficial effects of other possible network device designs can be found above. Figure 2 The beneficial effects of various implementation methods for the one-to-one correspondence of the first network device in the Chinese method embodiment will not be elaborated here.
[0244] It should be noted that, Figure 12 The information interaction and execution process between modules / units in the network device described in the corresponding embodiments are similar to those in this application. Figure 2 The method embodiments corresponding to the first network device are based on the same concept, and the specific details can be found in the description of the method embodiments shown above in this application, which will not be repeated here.
[0245] like Figure 13 As shown in the illustration, this application also provides a network device 1300. Please refer to the following for details. Figure 13 , Figure 13 This is another structural diagram of the network device provided in this application embodiment. The network device 1300 can be a gateway device (such as a router, switch, firewall, or hub, etc., network devices with packet forwarding capabilities) or an application server, etc. In one possible implementation, the network device 1300 may include modules or units corresponding to the methods / operations / steps / actions performed by the third network device in the above method embodiments. The unit may be a hardware circuit, software, or a combination of hardware circuit and software implementation. In one possible implementation, the network device 1300 may include: a receiving unit 1301, an acquiring unit 1302, a determining unit 1303, and a sending unit 1304. The receiving unit 1301 can be used to perform the step of the third network device receiving a message from the computer device accessing the target resource as described in the above method embodiment; the obtaining unit 1302 can be used to perform the step of the third network device obtaining the first target constraint item corresponding to the associated attribute as described in the above method embodiment; the determining unit 1303 can be used to perform the step of the third network device determining the second target verification code as described in the above method embodiment; and the sending unit 1304 can be used to perform the step of the third network device sending a message to access the target resource as described in the above method embodiment.
[0246] In another possible design, network device 1300 further includes a discarding unit 1305, which can be used to perform the steps of discarding packets as described in the method embodiment above.
[0247] In this embodiment, the receiving unit 1301 receives a message from a computer device accessing a target resource. The obtaining unit 1302 obtains the first target constraint item corresponding to the associated attribute. Then, if the first target information corresponding to the associated attribute belongs to the first target constraint item corresponding to the associated attribute, the determining unit 1303 determines the second target verification code based at least on the first key, the associated attribute, and the first target constraint item corresponding to the associated attribute. The sending unit 1304 sends the message if the first target verification code and the second target verification code are the same, enabling the computer device to access the target resource. The discarding unit 1305 discards the message if the first target information corresponding to the associated attribute does not belong to the first target constraint item corresponding to the associated attribute, or if the first target verification code and the second target verification code are different. Obtaining the second target verification code verification message based on the associated attribute and the first target information corresponding to the associated attribute allows for real-time monitoring of the computer device's status, improves network security, minimizes the risk of malicious resource theft, and avoids ACL-based verification messages, reducing ACL maintenance costs.
[0248] In other possible designs, the receiving unit 1301, acquiring unit 1302, determining unit 1303, sending unit 1304, or discarding unit 1305 can each execute the methods / operations / steps / actions in the various possible implementations of the third network device in the above method embodiments, which will not be elaborated here. Furthermore, the beneficial effects of other possible network device designs can be found in the above descriptions. Figure 2 The beneficial effects of various implementation methods for the one-to-one correspondence of the third network device in the Chinese method embodiment will not be elaborated here.
[0249] It should be noted that, Figure 13 The information interaction and execution process between modules / units in the network device described in the corresponding embodiments are similar to those in this application. Figure 2 The method embodiments corresponding to the third network device are based on the same concept, and the specific details can be found in the description of the method embodiments shown above in this application, which will not be repeated here.
[0250] It should be noted that this application also provides a network device, which can be a gateway device (such as a router, switch, firewall, or hub, or other network device with packet forwarding capabilities) or an application server, etc. It can execute the methods / operations / steps / actions in various possible implementations corresponding to the fourth network device in the above method embodiments. The information interaction and execution process between the modules / units in this network device are similar to those in this application. Figure 2The method embodiments corresponding to the fourth network device are based on the same concept. For details, please refer to the description in the method embodiments shown above in this application. The specific details will not be repeated here.
[0251] Furthermore, the functional modules or units in the various embodiments of this application can be integrated into a single processor, exist as separate physical entities, or be integrated into a single module or unit. The integrated modules or units described above can be implemented in hardware or as software functional modules.
[0252] The following describes a communication device provided in an embodiment of this application. Please refer to [link / reference]. Figure 14 , Figure 14 This is a schematic diagram of a communication device provided in an embodiment of this application. The communication device 1400 may be equipped with... Figure 11 or Figure 12 or Figure 13 The module described in the corresponding embodiment is used to implement Figure 11 The functions of computer equipment, or Figure 12 or Figure 13 In accordance with the functionality of the network device in the corresponding embodiment, specifically, the communication device 1400 is implemented by one or more servers. The communication device 1400 can vary significantly due to differences in configuration or performance, and may include one or more central processing units (CPUs) 1422 (e.g., one or more CPUs) and a memory 1432, and one or more storage media 1430 (e.g., one or more mass storage devices). The memory 1432 and storage media 1430 can be temporary or persistent storage. The program stored in the storage media 1430 may include one or more modules (not shown in the figure), each module may include a series of instruction operations on the communication device 1400. Furthermore, the CPU 1422 may be configured to communicate with the storage media 1430 and execute the series of instruction operations in the storage media 1430 on the communication device 1400.
[0253] The communication device 1400 may also include one or more power supplies 1426, one or more wired or wireless network interfaces 1450, and / or one or more input / output interfaces 1458.
[0254] In this embodiment, the central processing unit 1422 is used to execute... Figure 2The method in the corresponding embodiment. For example, the central processing unit 1422 can be used to: send a source identifier and a target identifier, then receive first indication information including at least a first verification code, then obtain an association attribute and determine first target information corresponding to the association attribute, and then send a message to access the target resource, the message including at least the first indication information, the association attribute and the first target information corresponding to the association attribute.
[0255] The central processing unit 1422 may be used to: receive a source identifier and a target identifier, then determine an associated attribute and a first target constraint item corresponding to the associated attribute based on the source identifier, the target identifier and the access control policy, then determine a first verification code based on the source identifier, the target identifier, the associated attribute and the first target constraint item corresponding to the associated attribute, and then send first indication information including at least the first verification code to the computer device.
[0256] Alternatively, the central processing unit 1422 may be configured to: receive a message from a computer device accessing a target resource, the message including at least first indication information, an association attribute, and first target information corresponding to the association attribute; then obtain a first target constraint item corresponding to the association attribute; and then determine a second target constraint item based on the first target constraint item corresponding to the association attribute, the association attribute in the message, and the first target information corresponding to the association attribute; then determine a second target verification code based on the source identifier, the target identifier, the association attribute, and the second target constraint item corresponding to the association attribute, and send a message if the first verification code and the second target verification code are the same.
[0257] It should be noted that the central processing unit 1422 can also be used to perform operations related to those described in this application. Figure 2 For details of any step in the corresponding method embodiment, please refer to the description in the method embodiment shown above in this application, which will not be repeated here.
[0258] This application also provides a computer-readable storage medium including computer-readable instructions that, when executed on a computer, cause the computer to perform any of the implementations shown in the foregoing method embodiments.
[0259] This application also provides a computer program product, which includes a computer program or instructions that, when run on a computer, cause the computer to perform any of the implementation methods shown in the foregoing method embodiments.
[0260] This application also provides a chip or chip system, which may include a processor. The chip may also include a memory (or storage module) and / or a transceiver (or communication module), or the chip may be coupled to a memory (or storage module) and / or a transceiver (or communication module), wherein the transceiver (or communication module) can be used to support the chip in wired and / or wireless communication, and the memory (or storage module) can be used to store a program or a set of instructions, which the processor can call to implement the operations performed by a terminal or network device in any of the above-described method embodiments or any possible implementations of the method embodiments. The chip system may include the above-described chip, or may include the above-described chip and other discrete devices, such as a memory (or storage module) and / or a transceiver (or communication module).
[0261] This application also provides a communication system, which may include the above-mentioned computer equipment, first network device, and third network device, and may also include a fourth network device. This communication system can be used to implement the operations performed by the computer equipment, first network device, third network device, or fourth network device in the above-described method embodiments and any possible implementations of the method embodiments.
[0262] It should also be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. In addition, in the device embodiment drawings provided in this application, the connection relationship between modules indicates that they have a communication connection, which can be implemented as one or more communication buses or signal lines.
[0263] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware, or it can be implemented by special-purpose hardware including application-specific integrated circuits, special-purpose CPUs, special-purpose memory, special-purpose components, etc. Generally, any function performed by a computer program can be easily implemented by corresponding hardware, and the specific hardware structure used to implement the same function can also be diverse, such as analog circuits, digital circuits, or special-purpose circuits. However, for this application, software program implementation is more often the preferred implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium, such as a computer floppy disk, USB flash drive, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, training equipment, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0264] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product.
[0265] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, training device, or data center to another website, computer, training device, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a training device or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid-state drives (SSDs)).
Claims
1. An access control method, characterized in that, include: The computer device sends a source identifier and a target identifier to the first network device. The source identifier indicates the computer device, and the target identifier indicates a target resource, which is the resource that the computer device wants to access. The computer device receives first indication information sent by the first network device. The first indication information includes at least a first verification code. The first verification code is obtained based at least on a first key, an association attribute, and a first target constraint item corresponding to the association attribute. The association attribute is an attribute associated with the source identifier, and the number of the association attributes is at least one. The first target constraint item is a preset constraint range of the information corresponding to the association attribute. The computer device acquires the associated attribute and determines the first target information corresponding to the associated attribute, wherein the first target information is the information corresponding to the associated attribute when the computer device accesses the target resource; The computer device sends a message to the third network device to access the target resource. The message includes at least the first indication information, the association attribute, and the first target information corresponding to the association attribute, so that the third network device verifies the message based on the first indication information, the association attribute, and the first target information corresponding to the association attribute.
2. The method according to claim 1, characterized in that, The first indication information further includes the associated attribute, and the computer device obtains the associated attribute by: The computer device obtains the associated attribute from the first indication information.
3. The method according to claim 1, characterized in that, The computer device obtains the associated attribute including: The computer device obtains the associated attributes from the second network device.
4. The method according to claim 1, characterized in that, The computer device obtains the associated attribute including: The computer device obtains the associated attribute from the second indication information, wherein the second indication information is information possessed by the computer device including the associated attribute.
5. The method according to any one of claims 1-4, characterized in that, The method further includes: The computer device receives a second key sent by the first network device, the second key being obtained by the first network device based on the first indication information; The computer device determines the second verification code based on the second key and the message; The computer device sends the second verification code.
6. The method according to any one of claims 1-4, characterized in that, The first indication information also includes the first target constraint item corresponding to the associated attribute, and / or the validity period, wherein the validity period is the validity period of the first verification code.
7. The method according to any one of claims 1-4, characterized in that, The associated attribute includes at least one of the following: Login mode, abnormal behavior, abnormal access relationship, terminal health, abnormal traffic, device security level, location information, security group information, or access time.
8. The method according to any one of claims 1-4, characterized in that, The source identifier includes at least one of the following: The computer device's Internet Protocol (IP) address, the computer device's device identifier, the user identifier corresponding to the computer device, and the user group or source port number to which the computer device belongs.
9. The method according to any one of claims 1-4, characterized in that, The target identifier includes at least one of the following: The target resource's IP address, IP address prefix, partial or complete Uniform Resource Locator (URL) prefix, device identifier, identity identifier, security group, or port number.
10. An access control method, characterized in that, include: The first network device receives a source identifier and a target identifier sent by the computer device, wherein the source identifier indicates the computer device, the target identifier indicates a target resource, and the target resource is the resource that the computer device wants to access. The first network device determines an associated attribute and a first target constraint item corresponding to the associated attribute based on the source identifier, the target identifier, and the access control policy. The access control policy includes the conditions for the computer device to access the target resource. The associated attribute is an attribute associated with the source identifier, and the number of associated attributes is at least one. The first target constraint item is a preset constraint range of the information corresponding to the associated attribute. The first network device determines the first verification code based at least on the first key, the associated attribute, and the first target constraint item corresponding to the associated attribute; The first network device sends a first instruction to the computer device, causing the computer device to send a message to the third network device to access the target resource based on the first instruction. The message includes at least the first instruction, the association attribute, and the first target information corresponding to the association attribute. The first instruction includes at least the first verification code, causing the third network device to verify the message based on the first instruction, the association attribute, and the first target information corresponding to the association attribute.
11. The method according to claim 10, characterized in that, The first network device determines the associated attribute and the first target constraint item corresponding to the associated attribute based on the source identifier, the target identifier, and the access control policy, including: The first network device determines an associated attribute table entry based on the source identifier, the target identifier, and the access control policy. The associated attribute table entry is an entry that includes at least the associated attribute and a first target constraint item corresponding to the associated attribute. The first network device determines the associated attribute and the first target constraint item corresponding to the associated attribute based on the associated attribute list.
12. The method according to claim 10, characterized in that, The method further includes: The first network device determines the second key based on the first indication information; The first network device sends the second key to the computer device, causing the computer device to generate a second verification code based on the second key.
13. The method according to any one of claims 10-12, characterized in that, The first network device determines the first verification code based at least on the first key, the associated attribute, and the first target constraint term corresponding to the associated attribute, including: The first network device determines a first verification code based on the source identifier and / or the target identifier and / or the validity period, the first key, the association attribute, and the first target constraint item corresponding to the association attribute, wherein the validity period is the validity period of the first verification code.
14. The method according to claim 13, characterized in that, The first indication information also includes at least one of the following: The validity period, the associated attribute, or the first target constraint item corresponding to the associated attribute.
15. The method according to any one of claims 10-12, characterized in that, If the first indication information does not include the first target constraint item corresponding to the associated attribute, the method further includes: The first network device sends the first target constraint item corresponding to the associated attribute to the third network device, so that the third network device verifies the message of the computer device accessing the target resource based on the first target constraint item.
16. The method according to claim 15, characterized in that, The method further includes: The first network device sends the association attribute and the second target information corresponding to the association attribute to the third network device or the fourth network device, so that the third network device or the fourth network device verifies the message of the computer device accessing the target resource based on the association attribute and the second target information corresponding to the association attribute, wherein the second target information is preset information corresponding to the association attribute.
17. An access control method, characterized in that, include: A third network device receives a message from a computer device accessing a target resource. The message includes at least first indication information, an association attribute, and first target information corresponding to the association attribute. The target resource is the resource to be accessed by the computer device. The first indication information includes at least a first target verification code. The association attribute is an attribute associated with a source identifier, and the number of association attributes is at least one. The first target information is the information corresponding to the association attribute when the computer device accesses the target resource. The source identifier is included in the message. The third network device obtains a first target constraint item corresponding to the associated attribute, where the first target constraint item is a preset constraint range of the information corresponding to the associated attribute. When the first target information corresponding to the associated attribute belongs to the first target constraint item corresponding to the associated attribute, the third network device determines the second target verification code based at least on the first key and the first target constraint item corresponding to the associated attribute. If the first target verification code is the same as the second target verification code, the third network device sends the message.
18. The method according to claim 17, characterized in that, The method further includes: if the first target information corresponding to the associated attribute does not belong to the first target constraint item corresponding to the associated attribute, the third network device will discard the packet; And / or, If the first target verification code is different from the second target verification code, the third network device will discard the message.
19. The method according to claim 17, characterized in that, The first target verification code includes a first verification code, which is obtained based at least on a first key, the associated attribute, and the first target constraint item corresponding to the associated attribute.
20. The method according to any one of claims 17-19, characterized in that, The third network device determines the second target verification code based at least on the first key, the associated attribute, and the first target constraint item corresponding to the associated attribute, including: The third network device determines the second target verification code based on the source identifier and / or target identifier and / or validity period, the first key, the association attribute, and the first target constraint item corresponding to the association attribute, wherein the target identifier is included in the message, and the validity period is the validity period of the first target verification code.
21. The method according to any one of claims 17-19, characterized in that, The third network device obtains the first target constraint item corresponding to the associated attribute, including: If the first indication information further includes the first target constraint item corresponding to the associated attribute, the third network device obtains the first target constraint item corresponding to the associated attribute from the first indication information; or, The third network device obtains the first target constraint item corresponding to the associated attribute from the first network device.
22. The method according to claim 20, characterized in that, The first indication information also includes the validity period. Before the third network device sends the message, the method further includes: The third network device determines that the first target verification code is valid based on the validity period.
23. The method according to any one of claims 17-19, characterized in that, The message also includes a second verification code, and the method further includes: The third network device determines the third verification code based on the first indication message and the message. When the first target verification code is the same as the second target verification code, the third network device sends the message including: If the first target verification code is the same as the second target verification code, and the second verification code is the same as the third verification code, the third network device sends the message.
24. The method according to any one of claims 17-19, characterized in that, Before the third network device sends the message, the method further includes: The third network device acquires the associated attribute and the second target information corresponding to the associated attribute, wherein the second target information is preset information corresponding to the associated attribute; If the first target information corresponding to the associated attribute is consistent with the second target information corresponding to the associated attribute, the third network device determines that the first target information corresponding to the associated attribute is valid.
25. A communication device, characterized in that, include: A processor coupled to a memory storing instructions, the processor executing the instructions such that the communication device performs the method according to any one of claims 1 to 9.
26. A communication device, characterized in that, include: A processor coupled to a memory storing instructions, the processor executing the instructions to cause the communication device to perform the method of any one of claims 10 to 16.
27. A communication device, characterized in that, include: A processor coupled to a memory storing instructions, the processor executing the instructions such that the communication device performs the method of any one of claims 17 to 24.
28. A computer-readable storage medium comprising computer-readable instructions, characterized in that, When the computer-readable instructions are executed on a computer, the method as described in any one of claims 1-24 is performed.
29. A computer program product comprising computer-readable instructions, characterized in that, When the computer-readable instructions are executed on a computer, the method as described in any one of claims 1-24 is performed.
Citation Information
Patent Citations
Method and apparatus for an access function in network applications
CN105100034A