Zero-trust im terminal configuration method based on identity authentication
By using an identity-based zero-trust IM terminal configuration method, and leveraging the device characteristics and security identifiers of IM terminals, fast and secure access to the zero-trust network is achieved. This solves the problems of complex configuration and insufficient security in existing technologies, and improves the system's security and deployment efficiency.
Patent Information
- Application Number
- CN202310251931.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-15
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2043-03-15
AI Technical Summary
In existing technologies, IM terminals are complicated to configure when accessing zero-trust networks, and the security of connectors is not covered, resulting in system resource consumption and potential crash risks. This does not fully utilize the advantages of IM terminal devices and leads to redundant construction.
The zero-trust IM terminal configuration method based on identity authentication leverages the unique characteristics of the IM terminal itself, utilizes an identity authentication policy server to record the device identity, generates a security identifier, performs minimum access control, and ensures secure and rapid access to the zero-trust network through secondary multi-factor authentication and dynamic switch ACL policies.
It enables IM terminals to quickly and securely access zero-trust networks, reduces configuration complexity, improves system security and deployment speed, avoids risks of unauthorized access and resource consumption, and enhances system reliability.
Smart Images

Figure CN116318971B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer network technology, and in particular to a zero-trust IM terminal configuration method based on identity authentication. Background Technology
[0002] Zero Trust addresses the security issues arising from excessive trust, particularly within trusted areas. This is especially important for organizations with high security requirements. However, IM (Instant Messaging) terminals, due to their built-in communication functions, present complex configuration challenges when connecting to a zero-trust network. For example, the invention patent with patent application number CN202011536114.X, entitled "Communication Method, Target System and Network System under Zero Trust Architecture," discloses a communication method, a target system, and a network system under a zero-trust architecture. The target system includes: a server providing application services within an intranet system, and a connector connected to the server; the connector also connects to a zero-trust cloud gateway deployed on an external network; the connector actively connects to the zero-trust cloud gateway; after actively connecting to the zero-trust cloud gateway, the connector and the zero-trust cloud gateway use a preset encryption / decryption algorithm for encrypted communication. On the one hand, the connector proactively connects to the zero-trust cloud gateway. This means the connector doesn't need to provide external ports; by actively connecting to the zero-trust cloud gateway, a tunnel is established between them, preventing the internal network from being compromised and thus improving internal network security. On the other hand, after proactively connecting to the zero-trust cloud gateway, the connector uses a preset encryption / decryption algorithm for encrypted communication, further enhancing internal network security.
[0003] In this application, after the connector actively connects to the zero-trust cloud gateway, it uses a preset encryption / decryption algorithm for encrypted communication with the gateway, thereby further improving the security of the intranet. However, because the connector's own security is not actually covered, once the connector is compromised or controlled by malicious actors, they can use the connector to continuously send requests for permissions. Even if they cannot enter the zero-trust system, they will still consume a large amount of system resources and may even cause the entire system to crash. At the same time, this configuration method does not fully utilize the device advantages of the IM terminal itself, resulting in redundant construction. Summary of the Invention
[0004] To address the shortcomings of existing technologies, the purpose of this invention is to provide a zero-trust IM terminal configuration method based on identity authentication. This method fully utilizes the inherent characteristics of the IM terminal itself, enabling it to securely and quickly connect to a zero-trust network. Simultaneously, it streamlines the zero-trust system after the IM terminal connects, ensuring overall security.
[0005] To achieve the above objectives, this invention provides a zero-trust IM terminal configuration method based on identity authentication. This method adds IM terminal devices to an already configured zero-trust system. Each IM terminal device includes a main device with the IM terminal installed and other devices connected to that main device. The main device with the IM terminal connects to a network with the zero-trust terminal. After detecting the main device, the zero-trust terminal obtains the existing service types and corresponding configuration information within the main device. The identity authentication policy server in the zero-trust terminal records the identity of the main device, adds a security identifier to the main device, issues basic access permissions to the main device, and writes the permissions to a writable switch. IM users can then access the system via O... Process A requests the opening of other permissions. The request is approved by the process control center. After approval, the configuration information of the main device is added to the access control list, and permission requests are made based on this. IM users submit corresponding permission opening requests to the permission control center according to the provided permission request function. The permission opening request is issued entirely by the main device with the IM terminal installed. Permission opening involves other devices connected to the main device. After the request is approved, the corresponding device carries the permission policy control active zero-trust security identifier issued by the permission control center in the identity authentication policy server. The security identifier is uniformly sent to the main device and distributed to other devices by the main device according to the permission request.
[0006] Preferably, the security identifiers represent personnel, services, or IoT devices. They define the zero-trust control plane. When a security identifier attempts to access a resource, strong authentication is required to verify the identifier and ensure that the access is compliant and typical of that identifier's behavior, adhering to the principle of least access. The basic functions of a zero-trust terminal are integrated into the main device with the IM terminal, and then the zero-trust gateway function is integrated through a gateway connected to the main device to achieve the zero-trust gateway. In this case, the main device with the IM terminal can act as an independent zero-trust system server after authorization.
[0007] Preferably, a secondary multi-factor authentication request is required when suspicious access is detected during security verification. Suspicious access includes instances of login from unusual IP addresses, login at unusual times, and other login behaviors that conflict with the operator's schedule.
[0008] Preferably, the secondary multi-factor authentication request specifically includes sending a verification code via SMS or email on the IM terminal. After the verification code is completed, facial recognition is used to perform secondary authentication of the user. Simultaneously, the IM terminal's built-in friend group is used to find a trusted role to assist in confirming the user's trusted access. This can prevent unauthorized users from accessing the zero-trust system through normal means.
[0009] Preferably, a zero-trust gateway is implemented by controlling the gateway connected to the main device with the IM terminal installed through a configurable switch. This gateway verifies the legitimacy of user request packets and decides whether to open a TCP port for application access. This allows for management and control at the content transmission level.
[0010] Preferably, the switch ACL policy is dynamically issued as a zero-trust terminal policy to complete the first authentication within the switch. At the same time, it relies on the user data, environment, IP, GPS and other basic environmental data obtained by the gateway connected to the main device with the IM terminal installed to verify the user's access security.
[0011] Preferably, after obtaining the configuration information of the main device with the IM terminal installed, the zero-trust terminal generates a configuration information list, performs initialization processing based on the configuration information list, and sequentially closes high-risk ports and idle ports, modifying the configuration of the main device with the IM terminal installed to the minimum configuration that meets basic functions. Some functions of the main device, as well as some functions of other devices connected to the main device, can be temporarily enabled upon request from IM users.
[0012] Preferably, the basic permissions granted to the IM terminal after being recorded by the identity authentication policy server include OA login permission, WIFI authentication access permission, and basic access function permission.
[0013] Preferably, it also includes writing back the configuration, uploading the configuration information of the IM terminal before initialization and after configuration as a configuration template to the zero-trust terminal. If the IM terminal encounters a problem after initialization, it will be rolled back to the previous configuration information, the corresponding configuration template will be deleted in the zero-trust terminal, and the IM terminal will be excluded from the zero-trust system. The IM user needs to resolve the problem before trying to reconfigure.
[0014] Preferably, after the zero-trust terminal detects the service type and corresponding configuration information of a new IM terminal, it first compares it with the configuration information of the already saved and configured IM terminal, and then selects whether to directly use the existing configuration template based on the comparison result.
[0015] The present invention provides a zero-trust IM terminal configuration method based on identity authentication, which can make full use of the performance of the IM terminal itself and quickly and securely configure it into the existing zero-trust network. While ensuring the reliability of the zero-trust system, it improves the deployment speed and success rate.
[0016] Compared with the prior art, the technical solution of the present invention has the following significant advantages:
[0017] 1. By utilizing the inherent functions of the IM terminal, for some non-confidential data interactions, such as downloading data when configuring a zero-trust network client, no prior operation is required; data transmission can be achieved directly using the IM terminal.
[0018] 2. In case of anomalies, minimal interaction can be achieved using the IM terminal. Temporarily disconnect the IM terminal from the zero-trust network and re-establish trust. If the anomaly cannot be eliminated during the trust re-establishment process, completely shut down the zero-trust system and disable the IM terminal and related devices. After thorough testing and ensuring the anomaly is resolved, the zero-trust network can be quickly rebuilt using the IM terminal.
[0019] 3. Once an IM terminal is blocked from the zero-trust system, the IM terminal will transmit the process data to the identity authentication policy server, which will facilitate analysis by relevant technical personnel and thus continuously improve the zero-trust system.
[0020] 4. When an IM terminal connects to the Zero Trust system, other devices connected to the main device that are not connected to the Zero Trust system can operate independently according to their own functions. However, these devices are data isolated from the devices connected to the Zero Trust system, unless they are actively requesting access or waiting for a response. Attached Figure Description
[0021] The accompanying drawings illustrate exemplary embodiments of the present disclosure and, together with the description thereof, serve to explain the principles of the present disclosure. These drawings are included to provide a further understanding of the present disclosure and are incorporated in and constitute a part of this specification.
[0022] Figure 1 This is a schematic diagram of the overall configuration method of a zero-trust IM terminal based on identity authentication according to the present invention.
[0023] Figure 2 This is a schematic diagram of the workflow of a zero-trust IM terminal configuration method based on identity authentication according to the present invention.
[0024] Figure 3 This is a schematic diagram of the write-back process architecture of a zero-trust IM terminal configuration method based on identity authentication according to the present invention. Detailed Implementation
[0025] The present disclosure will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the disclosure. Furthermore, it should be noted that, for ease of description, only the parts relevant to the present disclosure are shown in the accompanying drawings.
[0026] It should be noted that, where there is no conflict, the embodiments and features described in this disclosure can be combined with each other. This disclosure will now be described in detail with reference to the accompanying drawings and embodiments. To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0027] Here is an explanation of some of the terms:
[0028] IM (Instant Messaging). Most existing zero-trust systems come with built-in communication modules, but very few have communication modules compatible with instant messaging.
[0029] OA (Office Automation) refers to the use of Internet / Intranet technology and workflow concepts to enable employees within an organization to easily and quickly share information and collaborate efficiently. It transforms the complex and inefficient manual office methods of the past, achieving rapid and comprehensive information collection and processing, and providing a scientific basis for enterprise management and decision-making.
[0030] IoT devices (Internet of Things) are network devices that link physical devices, vehicles, buildings, and other things embedded with electronic devices, software, sensors, etc., to a network, enabling these objects to communicate and exchange data.
[0031] IP (Internet Protocol) is the Internet Protocol assigned to users for accessing the Internet.
[0032] GPS (Global Positioning System) is a satellite navigation system.
[0033] Zero-trust networks require dynamic and continuous monitoring, and the adjustment of permissions based on the security status of objects. Meanwhile, traditional enterprise instant messaging (IM) systems typically use third-party communication software, which is not well integrated with zero-trust systems. Data leaks within IM terminals remain a concern, with multiple accounts frequently sharing the same information, easily leading to account theft or leakage and compromising enterprise system security.
[0034] like Figure 1The diagram illustrates a zero-trust IM terminal configuration method based on identity authentication, used to add IM terminal devices to an already configured zero-trust system. This includes a main device with the IM terminal installed and other devices connected to the main device. The main device with the IM terminal connects to a network with the zero-trust terminal. Upon detecting the IM terminal, the zero-trust terminal obtains the existing service types and corresponding configuration information within the main device. The identity authentication policy server in the zero-trust terminal records the identity of the main device with the IM terminal installed, adds a security identifier to the main device, grants basic access permissions to the IM terminal, and writes these permissions to a writable switch. IM users can apply for additional permissions through an OA (Office Automation) process. The application is approved by the process control center. Upon approval, the configuration information of the IM terminal is added to the access control list, and permission requests are granted based on this list.
[0035] An Access Control List (ACL) is a list of rules (statements describing conditions for matching packets) that are applied to various hardware and software interfaces of network devices. It includes the source address, destination address, and port number of the packet. Incoming and outgoing packets are filtered based on the matching conditions in the ACL. Traffic is also marked according to the conditions in the ACL for further special processing by the device. In this embodiment, adding the IM terminal's configuration information to the access control list allows the transmission of packets whose source address or destination address is the IM terminal.
[0036] IM users submit corresponding permission requests to the permission control center using the provided permission request function. These requests are entirely initiated by the IM terminal and carry with them a security identifier representing a proactive zero-trust access control mechanism issued by the permission control center. This security identifier represents a person, service, or IoT device and defines the zero-trust control plane. When a security identifier attempts to access a resource, strong authentication is required to verify it, ensuring the access is compliant and typical of that identifier's behavior, adhering to the principle of least access. The basic functions of a zero-trust terminal are integrated into the IM terminal. This is achieved by connecting a gateway to the main device with the IM terminal installed, integrating the functions of a zero-trust gateway. When suspicious access is detected during security identifier verification, a secondary multi-factor authentication request is required. This secondary multi-factor authentication specifically involves the IM terminal sending a verification code via SMS or email, followed by facial recognition for secondary authentication. Simultaneously, the IM terminal's built-in friend group is used to find trusted individuals to assist in confirming the user's trusted access. This prevents unauthorized users from accessing the zero-trust system through legitimate means.
[0037] Example 1: When the identity authentication policy server detects that an IM terminal is accessing the site from an overseas IP address, and simultaneously finds no overseas travel history based on the IM user's schedule, the server uses the IM terminal's built-in pop-up notification to request access confirmation from the client. The server also requires the user to verify their mobile phone login account a second time via SMS; otherwise, the user's access request will be terminated. If there is no response to the pop-up notification within one minute, the user's client login will be directly disconnected. Furthermore, all login attempts from that IM terminal will be rejected until the user verifies their mobile phone login account a second time via SMS.
[0038] After the user successfully logs in to their account via SMS verification, an error message will be sent to their mobile phone. The user should then provide a detailed explanation of the situation. The IM terminal will transmit the process data to the identity authentication policy server for analysis by technical personnel and verification against the user's explanation. In this example, the user illegally opened VPN software, causing a change in their IP address. This behavior is not permitted. Therefore, after recording the situation, the connection permissions of the IM terminal's corresponding host device were blocked.
[0039] like Figure 2 As shown, the gateway connected to the main device with the IM terminal installed verifies the legitimacy of the user's request packet and decides whether to open a TCP port for application access. This allows for management and control through the content being sent. Switch ACL policies are dynamically issued as a zero-trust terminal policy, completing the first authentication within the switch. Simultaneously, it relies on user data, environment, IP, GPS, and other basic environmental data obtained from the IM terminal's own gateway to verify user access security. After obtaining the IM terminal's configuration information, the zero-trust terminal generates a configuration information list and performs initialization processing based on this list. High-risk ports and idle ports are closed sequentially, modifying the IM terminal's configuration to the minimum required for basic functionality. Some functions can be temporarily enabled upon request from the IM user. The basic permissions granted to the IM terminal after being recorded on the identity authentication policy server include OA login permissions, WIFI authentication access permissions, and basic access function permissions.
[0040] Example 2: When a gateway connected to a host device with an IM terminal installed verifies a user's client IMEI information, if it detects that the user profile on the host device has been modified, a pop-up window may request the user to re-enter their password or log in using an SMS verification code. Simultaneously, the user's corresponding IM friends may be required to send a confirmation code to the user's account to confirm login security.
[0041] like Figure 3As shown, this invention also includes configuration rewrite, uploading the configuration information of the IM terminal before initialization and after configuration as a configuration template to the zero-trust terminal. If a problem occurs in the IM terminal after initialization, the configuration information is rolled back to the previous state, the corresponding configuration template is deleted from the zero-trust terminal, and the IM terminal is excluded from the zero-trust system. The IM user needs to resolve the problem before attempting reconfiguration. After detecting a new IM terminal's service type and corresponding configuration information, the zero-trust terminal first compares it with the already saved configuration information of configured IM terminals, and then selects whether to directly use the existing configuration template based on the comparison result.
[0042] While the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the scope of the invention. Any person skilled in the art can make modifications without departing from the scope of the invention; all equivalent modifications made in accordance with the invention should be covered by the scope of the invention. In the description of this specification, references to terms such as "one embodiment / mode," "some embodiments / modes," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment / mode or example is included in at least one embodiment / mode or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment / mode or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments / modes or examples. Moreover, without contradiction, those skilled in the art can combine and integrate different embodiments / modes or examples and features of different embodiments / modes or examples described in this specification.
[0043] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.
[0044] Those skilled in the art should understand that the above embodiments are merely for illustrating the present disclosure and are not intended to limit the scope of the disclosure. Those skilled in the art can make other changes or modifications based on the above disclosure, and these changes or modifications still fall within the scope of the present disclosure.
Claims
1. A zero-trust IM terminal configuration method based on identity authentication, used to add IM terminal devices to an already configured zero-trust system, characterized in that, An IM terminal device includes a main device with an IM terminal installed and other devices connected to the main device. The main device with the IM terminal installed accesses a network with a zero-trust terminal. After detecting the main device, the zero-trust terminal obtains the existing service types and corresponding configuration information within the main device. The identity authentication policy server in the zero-trust terminal records the identity of the main device, adds a security identifier to the main device, issues basic access permissions to the main device, and writes the permissions to a writable switch. IM users apply for additional permissions through an OA process. The application is approved by the process control center. After approval, the configuration information of the main device is added to the access control list, and permission requests are made based on this. IM users submit corresponding permission opening requests to the permission control center according to the provided permission application function. The permission opening request is entirely issued by the main device with the IM terminal installed. Permission opening involves other devices connected to the main device. After the request is approved, the corresponding device carries the security identifier of the permission policy control active zero-trust issued by the permission control center within the identity authentication policy server. The security identifier is uniformly sent to the main device and distributed to other devices by the main device according to the permission request.
2. The zero-trust IM terminal configuration method based on identity authentication according to claim 1, characterized in that, The security identifiers are used to represent people, services, or IoT devices. They define a zero-trust control plane. When a security identifier attempts to access a resource, strong authentication is used to verify the security identifier and ensure that the access is compliant and typical of the security identifier's behavior, following the principle of least access.
3. The zero-trust IM terminal configuration method based on identity authentication according to claim 2, characterized in that, When a suspicious access is detected during the verification of the security identifier, a secondary multi-factor authentication request is made.
4. The zero-trust IM terminal configuration method based on identity authentication according to claim 3, characterized in that, The secondary multi-factor authentication request specifically includes sending a verification code via SMS or email on the IM terminal, and then using facial recognition to perform secondary authentication of the user after the verification code is completed. At the same time, the IM terminal's built-in friend group is used to find a trusted role to assist in confirming the user's trusted access.
5. The zero-trust IM terminal configuration method based on identity authentication according to claim 1, characterized in that, A zero-trust gateway is implemented by controlling the gateway connected to the master device with the IM terminal installed through a configurable switch. The gateway verifies the legitimacy of the user's request packet and decides whether to open a TCP port for the application to access.
6. The zero-trust IM terminal configuration method based on identity authentication according to claim 5, characterized in that, Dynamically distribute switch ACL policies as zero-trust terminal policies to complete the first authentication within the switch. At the same time, it relies on the basic environment data obtained by the gateway connected to the main device with the IM terminal installed to verify the user's access security. The basic environment data includes: user data, environment, IP and GPS.
7. The zero-trust IM terminal configuration method based on identity authentication according to claim 1, characterized in that, After obtaining the configuration information of the main device with the IM terminal installed, the zero-trust terminal generates a configuration information list, performs initialization processing based on the configuration information list, and sequentially closes high-risk ports and idle ports according to the configuration information list, and modifies the configuration of the main device with the IM terminal installed to the minimum configuration that meets the basic functions.
8. A zero-trust IM terminal configuration method based on identity authentication according to claim 1 or 7, characterized in that, After the identity authentication policy server records the basic access permissions granted to the IM terminal, the permissions include OA login permission, WIFI authentication access permission, and basic access function permission.
9. The zero-trust IM terminal configuration method based on identity authentication according to claim 7, characterized in that, It also includes writing back the configuration, uploading the configuration information of the IM terminal before initialization and after configuration as a configuration template to the zero-trust terminal. If the IM terminal encounters a problem after initialization, it will be rolled back to the previous configuration information, the corresponding configuration template will be deleted from the zero-trust terminal, and the IM terminal will be excluded from the zero-trust system. The IM user can then try to reconfigure after resolving the problem.
10. The zero-trust IM terminal configuration method based on identity authentication according to claim 9, characterized in that, After the zero-trust terminal detects the service type and corresponding configuration information of a new IM terminal, it first compares it with the configuration information of the already saved and configured IM terminals, and then selects whether to directly use the existing configuration template based on the comparison results.
Citation Information
Patent Citations
Communication methods, target systems and network systems under zero-trust architecture
CN114666080B
Zero-trust service access control system and method
CN113949573A
Zero-trust network access request processing method and apparatus, and electronic device
CN115701019A