Access control method, access control system, terminal, and storage medium

By monitoring access status on the terminal side and interacting with the SDP policy controller and network firewall, the access control rules are dynamically adjusted, solving the access control problem of single packet authorization in the SDP security architecture, and realizing the full lifecycle protection and security improvement of legitimate access by the network firewall.

CN116346375BActive Publication Date: 2026-03-27ZTE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-22
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

In the existing SDP security architecture, single-packet authorization access control cannot accurately control the access control rules of the network firewall, resulting in legitimate user access being affected or attackers having an attack window.

Method used

By monitoring access status on the endpoint and interacting with the SDP policy controller and network firewall, access control rules can be dynamically adjusted to ensure accurate protection of the network firewall throughout the access lifecycle.

Benefits of technology

It achieves full lifecycle protection of legitimate access by the network firewall, avoids forgery and replay attacks, and improves the concealment and security of network services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116346375B_ABST
    Figure CN116346375B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides an access control method, an access control system, a terminal and a storage medium, and belongs to the technical field of zero trust. The method comprises the following steps: when initiating access to a target server, a single packet authorization authentication message is sent to a policy controller, so that the policy controller informs a network firewall to generate a first access control rule for exposing a service port of the terminal according to a verification result of the single packet authorization authentication message; a session connection is established with the target server based on the first access control rule, and a connection establishment notification message is sent to the policy controller, so that the policy controller informs the network firewall to generate a second access control rule for access management of an application of the terminal and deletes the first access control rule. The embodiment of the application synchronously adjusts the access control of the network firewall according to the access state by monitoring the remote access of the terminal, so that the protection of the network firewall for the remote access can strictly run through the whole life cycle of the access.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of zero trust, in particular to an access control method, an access control system, a terminal and a storage medium. BACKGROUND

[0002] The SDP (Software Defined Perimeter) security model of zero trust is different from the traditional network access control model. The network stealth technology is used to realize the connection after authentication, and the service port is not directly exposed to the Internet. The SDP changes from the traditional network center to the identity center for minimum permission access control. Through the network stealth technology, the internal and external networks are not distinguished, and it is ensured that only the legal identity and the terminal and network environment can access. SPA (Single Packet Authorization) is the core network security protocol for realizing the SDP network stealth. The device and user identity are verified before allowing the network where the access controller, gateway and other related system components are located, and the security model concept of "authentication first, then connection" of zero trust is realized.

[0003] In the prior art, when the terminal application initiates a network access request, an SPA packet is triggered to be constructed and sent. The SDP policy controller performs authentication and authorization processing after receiving the SPA packet, and notifies the network firewall to open the corresponding service, that is, to create the corresponding access control filtering rule for admission, so as to permit the application to access the network service. However, when the corresponding access control filtering rule is closed, since the SDP policy controller and the network firewall do not master the precise state of the subsequent access session connection, only the preset timeout threshold can be used to delay the closing, so as to control the length of the service exposure time window. Since the service exposure time window is difficult to determine, if the length of the time window is too short, the legal user has not had time to establish a session connection, and the time window is closed, which affects normal access; if the length of the service exposure time window is too long, the attacker is given ample time to conduct a probe attack.

[0004] Therefore, how to completely implement the zero trust concept, improve the weakness of the access control for single packet authorization in the SDP security architecture, and ensure that the protection of the network firewall for each network access is strictly throughout the entire life cycle of the access, is an urgent problem to be solved. SUMMARY

[0005] The main purpose of the embodiment of the present application is to provide an access control method, an access control system, a terminal and a storage medium, by monitoring and sensing the real state of remote access at the terminal, and synchronously adjusting the access control of the network firewall according to the access state at the terminal side, the protection of the network firewall for network access is realized and strictly runs through the whole life cycle of remote access.

[0006] In a first aspect, the embodiment of the present application provides an access control method applied to a terminal, comprising:

[0007] When initiating access to a target server, a single packet authorization authentication message is sent to a policy controller, so that the policy controller notifies a network firewall to generate a first access control rule according to the verification result of the single packet authorization authentication message; wherein the first access control rule is used for the target server to expose a service port to the terminal;

[0008] Based on the first access control rule, a session connection is established with the target server, and a connection establishment notification message is sent to the policy controller, so that the policy controller notifies the network firewall to generate a second access control rule and delete the first access control rule; wherein the second access control rule is used for the target server to perform admission management on the application of the terminal.

[0009] In a second aspect, the embodiment of the present application further provides an access control method applied to an access control system, the access control system comprising: a terminal, a policy controller, a network firewall and a target server; the access control method comprising:

[0010] When the terminal initiates access to the target server, a single packet authorization authentication message is sent to the policy controller;

[0011] The policy controller notifies the network firewall to generate a first access control rule according to the verification result of the single packet authorization authentication message; wherein the first access control rule is used for the target server to expose a service port to the terminal;

[0012] The terminal establishes a session connection with the target server based on the first access control rule, and sends a connection establishment notification message to the policy controller;

[0013] The policy controller notifies the network firewall to generate a second access control rule and delete the first access control rule; wherein the second access control rule is used for the target server to perform admission management on the application of the terminal.

[0014] In a third aspect, to implement the above-mentioned access control method applied to a terminal, an embodiment of the present application further provides a terminal, which comprises a processor, a memory, a computer program stored in the memory and executable by the processor, and a data bus for realizing connection communication between the processor and the memory, wherein the computer program, when executed by the processor, realizes the steps of any one of the access control methods applied to a terminal provided in the specification of the present application.

[0015] In a fourth aspect, to implement the above-mentioned access control method applied to an access control system, an embodiment of the present application further provides an access control system, which comprises a terminal, a policy controller, a network firewall and a target server; the terminal, the policy controller, the network firewall and the target server are used to jointly realize the steps of any one of the access control methods applied to an access control system provided in the specification of the present application.

[0016] In a fifth aspect, an embodiment of the present application further provides a storage medium for computer-readable storage, characterized in that the storage medium stores one or more programs, and the one or more programs are executable by one or more processors to realize the steps of any one of the access control methods provided in the specification of the present application.

[0017] The embodiments of the present application provide an access control method, an access control system, a terminal and a storage medium, by monitoring and sensing the real state of a terminal application access session connection on the terminal side, and interacting the access state message with an SDP policy controller and a network firewall, the opening and closing of the corresponding access control rules on the network firewall are accurately controlled, and then the network firewall can realize the whole life cycle protection of the legal terminal access in the whole life cycle of the terminal application access to the network service. Further, by dynamically maintaining different types of access control rules on the network firewall in the creation and maintenance stage of the terminal access connection, the time window of protection is strictly synchronized with the actual access. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0019] Figure 1 A schematic block diagram of an access control system provided by an embodiment of the present application;

[0020] Figure 2 A flowchart of an access control method provided by an embodiment of the present application;

[0021] Figure 3 A scenario flow chart of an access control system in implementing an access control method is provided for an embodiment of the present application;

[0022] Figure 4 Another schematic block diagram of an access control system is provided for an embodiment of the present application;

[0023] Figure 5 A flow chart of an access control method applied to a terminal is provided for an embodiment of the present application;

[0024] Figure 6 A scenario flow chart of an access control system in implementing an access control method is provided for an embodiment of the present application; Figure 4

[0025] A scenario flow chart of an access control system in implementing an access control method is provided for an embodiment of the present application; Figure 7

[0026] A scenario flow chart of an access control system in implementing an access control method is provided for an embodiment of the present application; Figure 8

[0027] A schematic block diagram of a terminal is provided for an embodiment of the present application. Figure 9 DETAILED DESCRIPTION

[0028] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of the present application.

[0029] The flow chart shown in the drawings is only an example and is not necessarily to include all the contents and operations / steps, nor is it necessarily to be executed in the described order. For example, some operations / steps can be decomposed, combined or partially merged, so that the actual execution order can be changed according to the actual situation.

[0030] It should be understood that the terms used in the present application specification are only for the purpose of describing specific embodiments and are not intended to limit the present application. As used in the present application specification and the appended claims, the singular forms "a", "an" and "the" are intended to include the plural forms unless the context clearly indicates otherwise.

[0031] ​Traditional network access control is access first and authentication later. Since network service ports are directly exposed to the Internet, they are vulnerable to security attacks, thus generating various security threats. The SDP (Software Defined Perimeter) security model of zero trust is different from the traditional network access control model. It realizes connection after authentication through network stealth technology, and the service port is not directly exposed to the Internet. SDP changes from the traditional network-centric to identity-centric minimum privilege access control. Through network stealth technology, it does not distinguish between internal and external networks, and ensures that only legitimate identities, terminals and network environments can access.

[0032] SPA (Single Packet Authorization) is the core network security protocol for implementing SDP network stealth. It verifies the identity of devices and users before allowing access to the network where the access controller, gateway and other related system components are located, thus realizing the security model concept of zero trust "authentication first, connection later". SPA contains connection request information including the IP address of the requestor, which is encrypted and authenticated in a single network packet. The protected network service is invisible to the outside by configuring a default-dropped firewall policy. The purpose of SPA is to allow network services to be hidden by the firewall and to default-drop any probe and access packets, thus not providing any information to potential attackers about whether the service port is being monitored.

[0033] After single packet authorization, the terminal application should initiate a connection to the exposed network service to establish a session link. After that, the network firewall should adjust the access rules to close the service exposure port and allow the established session connection to access.

[0034] In the prior art, when the terminal application initiates a network access request, it will trigger the construction and sending of an SPA packet. The SDP policy controller performs authentication and authorization processing after receiving the SPA packet, and notifies the network firewall to open the corresponding service, that is, to create the corresponding access control filtering rules, thus permitting the application to access the network service. However, as to when to close the corresponding access control filtering rules, since neither the SDP policy controller nor the network firewall masters the precise state of the subsequent access session connection, they can only delay the closing by presetting a timeout threshold, thus controlling the length of the service exposure time window. Since it is difficult to determine the service exposure time window, if the length of the time window is too short, the legitimate user has not had time to establish a session connection before the time window is closed, affecting normal access; if the length of the service exposure time window is too long, it leaves enough time for the attacker to conduct a probe attack.

[0035] After the session connection is established, the service packets carried by the session connection still need to pass through the network firewall to reach the network service. Based on the concept of zero trust, the firewall should only allow the packets related to the legal session connection to pass through and discard other illegal packets. However, the SDP security framework does not regulate the access control of the session connection, and how to automatically and accurately implement the access control of the session connection on the network firewall is a problem to be solved.

[0036] In addition, to solve the problem of the accuracy of the service exposure time window, the prior art scheme proposes to monitor the data packets received on the network service side, so as to determine whether the subsequent session connection has been established, and if so, to trigger the network firewall to adjust the access rules and close the service exposure port, so that the network service quickly returns to the stealth state. However, this technical solution can only solve the problem of inaccurate service exposure time, and cannot solve the problem of access control of the network firewall for subsequent session connection packets. At the same time, since the state of the session connection is analyzed by sniffing packets on the network side, it is easy to be deceived by the connection control packets (such as TCP SYN packets) or replay packets constructed by external attackers through the network, resulting in the service exposure port being closed too early due to the mistaken belief that the session connection has been established, and causing the failure of the legal terminal application to access the network service.

[0037] In summary, how to completely implement the concept of zero trust, improve the weakness of the access control of the single packet authorization in the SDP security architecture, and ensure that the protection of the network firewall for each network access is strictly throughout the entire life cycle of the access, is an urgent problem to be solved.

[0038] Embodiments of the present application provide an access control method, an access control system, a terminal and a storage medium. The access control method can be applied to a mobile terminal, which can be a mobile phone, a tablet computer, a notebook computer, a desktop computer, a personal digital assistant and a wearable device, and the like.

[0039] Some embodiments of the present application will be described in detail below with reference to the accompanying drawings. In the case of no conflict, the embodiments described below and the features in the embodiments can be combined with each other.

[0040] In order to better illustrate the access control method of the present application, first, the access control system provided by the embodiments of the present application is introduced.

[0041] The present application is applied to the scenario of remote secure access service provided based on the SDP security framework, and is used for the access control processing of the application of the terminal remotely accessing the network server.

[0042] Please refer to Figure 1 , Figure 1A schematic block diagram of an access control system is provided for an embodiment of the present application, and the access control system specifically comprises a terminal, a policy controller, a network firewall and a target server.

[0043] When the terminal needs to access the target server, the terminal first sends a request to the policy controller, the policy controller issues a command of creating, deleting or the like of an access control rule to the network firewall according to an authentication result of the terminal request, triggers the network firewall to adjust an access rule of a data packet, and the terminal realizes session connection with the target server according to the access control rule of the network firewall.

[0044] Specifically, refer to Figure 2 , Figure 2 A flowchart of an access control method applied to the above access control system is provided for an embodiment of the present application, and specifically comprises steps S101 to S104. Figure 3 A scenario diagram of the access control system provided for an embodiment of the present application in implementing the access control method.

[0045] S101, when the terminal initiates access to the target server, a single packet authorization authentication packet is sent to the policy controller;

[0046] Specifically, when an application deployed on the terminal needs to initiate access to the target server, the terminal sends a SPA (Single Packet Authorization) packet to the SDP policy controller.

[0047] S102, the policy controller notifies the network firewall to generate a first access control rule according to a verification result of the single packet authorization authentication packet, and the first access control rule is used for the target server to expose a service port to the terminal.

[0048] The SDP policy controller receives the SPA packet and performs authentication: if the authentication is passed, authorization is performed, and a network firewall of the target server is notified to create an access control rule (ACL RULE) according to an authorization result, that is, to allow the target server to expose a service port to the terminal, which is called a first access control rule.

[0049] It should be noted that the network firewall needs to be started in a default discard mode.

[0050] Optionally, the first access control rule is a three-tuple or a four-tuple, in the case of the three-tuple, only the message satisfying the IP address of the target server of the terminal + target service port + protocol type characteristics is allowed to access, and there is no limitation on the source port of the terminal and the source IP address of the terminal; in the case of the four-tuple, only the message satisfying the source IP address of the terminal + the IP address of the target server + the target service port + the protocol type characteristics is allowed to access, and there is no limitation on the source port of the terminal.

[0051] S103, the terminal establishes a session connection with the target server based on the first access control rule, and sends a connection establishment notification message to the policy controller;

[0052] According to the first access rule created by the firewall, the application on the terminal can start a link establishment process as a client between the network side target server, if the session connection is successfully established, the connection establishment notification message is further sent to the SDP policy controller.

[0053] S104, the policy controller notifies the network firewall to generate a second access control rule and delete the first access control rule; wherein the second access control rule is used for the target server to perform access management on the application of the terminal.

[0054] The SDP policy controller receives the notification message that the application of the terminal has been connected and established with the target server, and notifies the network firewall to add the access control rule entry corresponding to the established connection feature information to strictly control the access, so as to adjust the network access of the application of the terminal. Specifically, the policy controller notifies the network firewall to generate a second access control rule and delete the first access control rule for exposing the service port.

[0055] The second access control rule includes: the access control rule corresponding to the source IP address of the terminal + the source port of the terminal + the IP address of the target server + the service port + the protocol type.

[0056] Exemplarily, the protocol type can be TCP, UDP, and other communication protocols determined by the specific application of the terminal.

[0057] At this point, the network firewall will only allow the corresponding message of the established access session connection to pass, and the service port is restored to the hidden state due to the closing of the service exposure port access. Since the second access control rule is a more stringent access rule than the first access control rule, it only allows legitimate terminal application connection session messages to pass; therefore, replacing the first access control rule with the second access control rule can effectively prevent malicious attackers from exploiting service port exposure, forging source IP addresses or exploiting the uncertainty of source ports to forge messages that can bypass the network firewall to attack network services; and the time span of service port exposure is completely consistent with the time spent on establishing a real connection, avoiding the use of excessive time windows by malicious attackers for probing attacks.

[0058] Subsequently, when the access session between the terminal and the target server ends, the terminal sends a connection termination notification message to the SDP policy controller, which contains the session connection feature information. After receiving the connection termination notification message, the SDP policy controller performs network access adjustment processing again and notifies the network firewall to delete the access control rule (ACLRULE) corresponding to the session connection, i.e., delete the second access control rule. Specifically, when the session connection between the terminal and the target server is terminated, a connection termination notification message is sent to the policy controller; the policy controller notifies the network firewall to delete the second access control rule.

[0059] At this point, with the end of a single access of a legitimate terminal application to a network service, the network firewall will adjust the access rule and discard any message corresponding to the access feature, thereby avoiding forgery and replay attacks.

[0060] Further, a timeout deletion mechanism can be set for both the first access control rule and the second access control rule to deal with issues such as abnormal exit of a legitimate terminal during access to a network service or network interruption.

[0061] For example, in the case of subsequent network interruption or terminal failure, etc., due to the inability to notify the SDP policy controller of the abnormal termination of the access session connection, the second access control rule built by the firewall cannot be deleted. In this abnormal scenario, the SDP controller and the network firewall can add a protection mechanism. For the second access control rule, an aging timeout time window is set. When the timeout occurs and there is no matching message passing in the subsequent several statistical periods, the network firewall can automatically delete the second access control rule.

[0062] Specifically, after the network firewall generates the access control rule, if no packet matching the access control rule is received within a preset period, a timer is started, and if no packet meeting the access control rule is received after the timer expires, the network firewall automatically deletes the access control rule; wherein the access control rule includes the first access control rule and the second access control rule.

[0063] In addition, for the delivery of the newly added control messages between the terminal and the SDP policy controller, including the connection establishment notification message and the connection termination notification message, integrity and confidentiality protection can be performed to ensure the security of the newly added control messages. The specific implementation manner is not limited by the present application. For example, the inherent trust letter between the terminal application and the SDP policy controller can be used to implement the security protection mechanism of the existing SPA authentication request message, including but not limited to: digital certificate, user password or key, etc.

[0064] The access control method provided by the present application improves the access control method based on single packet authorization in the existing SDP framework, and through the interaction of the state message of remote access actively monitored by the terminal side with the SDP policy controller and the network firewall, the opening and closing of the corresponding access control rule on the network firewall are accurately controlled, thereby ensuring the entire life cycle of the terminal application accessing the network service. Further, in the creation of the access connection and the maintenance of the access connection session, different types of access control rules are dynamically maintained on the network firewall, so that the network firewall realizes the whole life cycle protection of the legal terminal access traffic, and the time window of the protection is strictly synchronized with the actual access.

[0065] In order to effectively implement the access control method of the present application, the present application further provides a terminal including a terminal application and a security agent module. The security agent module is deployed on the terminal together with the application, and the security agent module can sense and monitor the state of the session of the application accessing the network service in the whole life cycle through an internal interface; at the same time, the security agent module can construct the expected access control admission and rejection rule information according to the state change of the session connection and notify the SDP policy controller. The SDP policy controller issues instructions such as creation and deletion of access control rules to the network firewall according to the above request from the security agent, to trigger the network firewall to adjust the data packet admission rule.

[0066] Figure 4 The access control system provided by the present application includes a terminal, a policy controller, a network firewall and a target server, and the terminal is internally deployed with a plurality of terminal applications and a security agent.

[0067] Please refer to Figure 5 , Figure 5 A flowchart of an access control method applied to a terminal is provided for an embodiment of the present application, and specifically includes steps S201 to S202. Figure 6 A scenario diagram of a security agent module in a terminal and other components of an application and access control system is provided for an embodiment of the present application.

[0068] In step S201, when initiating access to a target server, a single-packet authorization authentication message is sent to a policy controller, so that the policy controller notifies the network firewall to generate a first access control rule according to a verification result of the single-packet authorization authentication message; wherein the first access control rule is used for the target server to expose a service port to the terminal.

[0069] Specifically, after the terminal is powered on, the security agent module starts to monitor the legal terminal application and the access behavior of the terminal application to an external network target server. There are multiple optional ways to implement the monitoring of the terminal application by the security agent module, including but not limited to: sniffing the messages of the terminal application interacting with the external system through the system kernel or the network card device to restore the state of the session connection, or in some embedded application scenarios, the security agent directly interacts with the application and subscribes to the connection transaction start and stop information of the network access initiated by the application.

[0070] When a legal terminal application initiates access to a network server, the security agent module constructs and sends an SPA authentication message, and the SDP policy controller receives the message and performs authentication: if the authentication is passed, authorization is performed, and the network firewall is notified to create a first access control rule according to the authorization result, i.e., to allow the network server to be exposed to the terminal. It should be noted that the network firewall needs to be started in the default discard mode.

[0071] The first access control rule is a three-tuple or a four-tuple. In the three-tuple scenario, only messages meeting the IP address of the target server of the terminal + target service port + protocol type characteristics are allowed to access, and there is no limitation on the source port of the terminal and the source IP address of the terminal. In the four-tuple scenario, only messages meeting the source IP address of the terminal + IP address of the target server + target service port + protocol type characteristics are allowed to access, and there is no limitation on the source port of the terminal.

[0072] In step S202, a session connection is established based on the first access control rule and the target server, and a connection establishment notification message is sent to the policy controller, so that the policy controller notifies the network firewall to generate a second access control rule and delete the first access control rule; wherein the second access control rule is used for the target server to perform access management on the application of the terminal.

[0073] According to the first access control rule created by the firewall, the application on the terminal can initiate a link establishment process as a client between the network side target server, if a session connection is successfully established, the security agent module is aware of that the terminal application has successfully established a session connection with the network service through monitoring, records the characteristic information of the session connection, such as the five-tuple characteristics (source IP + source port + target IP + service port + protocol type) of the TCP connection, and constructs a connection establishment notification message to notify the SDP policy controller.

[0074] The SDP policy controller receives the notification message that the terminal's application has connected to the target server, and notifies the network firewall to add an access control rule entry strictly corresponding to the characteristic information of the established connection, thereby adjusting the network access of the terminal's application. Specifically, the policy controller notifies the network firewall to generate a second access control rule and delete the first access control rule for exposing the service port.

[0075] The second access control rule is an access control rule corresponding to the terminal's source IP address + terminal's source port + target server's IP address + service port + protocol type. Exemplarily, the protocol type can be TCP, UDP, and other communication protocols determined by the specific application of the terminal.

[0076] At this point, the network firewall will only allow the corresponding packets of the established access session connection to pass, and at the same time, the service port returns to the hidden state due to the closing of the service exposure port access.

[0077] Subsequently, when the access session between the terminal application and the network service ends, the security agent module is aware of the termination of the session connection through monitoring the connection state of the application accessing the network service in the terminal, and then constructs a connection termination notification message to notify the SDP policy controller, which contains the characteristic information of the session connection.

[0078] The SDP policy controller receives the connection termination notification message and performs network access adjustment processing again, and notifies the network firewall to delete the second access control rule corresponding to the session connection. Specifically, when the session connection with the target server is terminated, a connection termination notification message is sent to the policy controller to make the policy controller notify the network firewall to delete the second access control rule.

[0079] With the end of a single access of a legitimate terminal application to a network service, the network firewall will adjust the access rule and discard any packets corresponding to the access characteristics at the same time, thereby avoiding forgery and replay attacks.

[0080] The access control method provided by the application guarantees that the access control rules configured on the network firewall correspond to real and legal access messages, and avoids the possibility that malicious and fake messages from the network side open the firewall by cheating.

[0081] In order to better explain the access control method of the application, the application is applied to the access control processing of a general terminal in a remote security access environment based on single packet authorization, and the access control processing of a special embedded device terminal in a remote security access environment based on single packet authorization. The difference between the two embodiments is only that the technical means for the security agent to perceive and monitor the session state of the application accessing the network is different.

[0082] Embodiment one

[0083] Please refer to Figure 7 , Figure 7 A scene schematic diagram for implementing the access control method of the embodiment one is shown in FIG. 1, and the embodiment demonstrates the access control processing of a general terminal in a remote security access environment based on single packet authorization. Figure 7

[0084] It should be noted that the network firewall needs to be started in the default discard mode.

[0085] Step 1, the terminal side security agent pre-configures a white list of legal applications, which includes application program name features and communication protocol types required for accessing the network. After the application program is started and registered with the security agent, the security agent confirms that it is a legal application through the white list comparison, and then starts to monitor its access behavior to the external network. In this embodiment, it is assumed that the application accesses the network service based on the TCP protocol, and the terminal is based on a general operating system such as Linux and Windows. The security agent can obtain the state and application program of the network protocol connection in the current kernel IP protocol stack by periodically calling the netstat command provided by the operating system.

[0086] Step 2, when the terminal application initiates access to the network server, the security agent module constructs and sends an SPA authentication message, and the SDP policy controller receives the message and performs authentication: if the authentication is passed, authorization is performed, and the network firewall is notified to create a first access control rule according to the authorization result: an access control rule for the four-tuple features of the source IP address + target IP + target service port + protocol type, that is, the service allows the terminal to be exposed. Optionally, the system can also set a timeout window for the first access control rule, and if the timeout occurs, the first access control rule is forced to age and deleted, so that the service port can be restored to the stealth state.

[0087] ​Step 3, the terminal application initiates a TCP connection establishment process as a client between the network side server, and successfully establishes a session connection before the first access control rule expires.

[0088] Step 4, the security agent module on the terminal side monitors and senses in real time that the terminal application has successfully established a session TCP connection with the network service through the method described in step 2, records the feature information of the session connection, i.e. the five-tuple features of the TCP connection (source IP + source port + target IP + service port + protocol type), and constructs a connection establishment notification message to notify the SDP policy controller. Optionally, the connection establishment notification message can be protected by confidentiality and integrity using the inherent trust letter between the terminal and the SDP policy controller, and the protection mechanism is the same as that of the SPA authentication message.

[0089] Step 5, the SDP policy controller receives the connection establishment notification message, if it is a securely protected message, decrypts and integrity checks it to recover the plaintext, then adjusts the network access according to the message content, notifies the network firewall to add an access control rule entry strictly corresponding to the established connection feature information, i.e. the second access control rule corresponding to the five-tuple features of the established TCP connection (source IP + source port + target IP + service port + protocol type), and deletes the first access control rule entry used for service port exposure.

[0090] Optionally, for the abnormal scenario that the second access control rule cannot be deleted due to the inability of the security agent to notify the SDP controller of the abnormal termination of the access session connection due to network interruption or terminal failure, the SDP controller and the network firewall can also increase the protection mechanism, set a timeout window for the second access control rule, and when the timeout occurs, if there is no matching message passing through the access control rule in the subsequent several statistical periods, the network firewall can automatically delete the second access control rule.

[0091] At this point, the network firewall will only allow messages of the established access session connection to pass through, and at the same time, the service port returns to the hidden state due to the closure of the service exposure port access. Since the second access control rule is a more stringent access rule than the first access control rule, it only allows legitimate application connection session messages to pass through; therefore, replacing the first access control rule with the second access control rule can effectively prevent malicious attackers from exploiting the service port exposure to forge source IP addresses or using the uncertainty of the source port to forge messages that can bypass the network firewall to attack the network service; and the time span of the service port exposure is completely consistent with the time span of the actual connection establishment, avoiding the use of the excess time window by malicious attackers for probing attacks.

[0092] Step 6, When the access session between the terminal application and the network service ends, the security agent monitors and senses the termination of the session connection in real time through the method described in step 2, and then constructs a connection termination notification message to notify the SDP policy controller, which contains the feature information of the session connection, such as the quintuple features of the TCP connection (source IP + source port + target IP + service port + protocol type). Optionally, the connection termination notification message can be protected by confidentiality and integrity using the inherent trust letter between the terminal and the SDP policy controller, and the mechanism is the same as the protection of the SPA authentication message.

[0093] Step 7, The SDP policy controller receives the connection termination notification message, if it is a securely protected message, decrypts and integrity checks it to recover the plaintext, and then adjusts the network access again according to the message content, and notifies the network firewall to delete the second access control rule corresponding to the connection.

[0094] At this point, with the end of a single access of a legitimate terminal application to a network service, the network firewall will adjust the access rules synchronously and discard any message corresponding to the features of this access, thereby avoiding forgery and replay attacks.

[0095] Embodiment Two

[0096] Please refer to Figure 8 , Figure 8 A scenario diagram of the access control method provided for the implementation of this embodiment two, in this embodiment, the terminal is a dedicated embedded device terminal.

[0097] Because in a typical embedded environment, the communication protocol uses a simplified user mode protocol stack developed by the manufacturer, the connection state is directly controlled by the application, and the computing resources of the system are extremely limited. Therefore, the security agent needs to directly subscribe to the network connection state from the application regarding the state of the network connection.

[0098] It should be noted that the network firewall needs to be turned on in the default discard mode.

[0099] Step 1, the terminal side application program is started, and the security agent is registered, the security agent subscribes to the network access connection information of the application, and starts to monitor its access behavior to the external network.

[0100] Step 2, the terminal application initiates an access to the network server. Since the security agent has subscribed to the connection state of the application, the application will notify the security agent in advance of the access connection establishment request, triggering the security agent module to construct and send the SPA authentication message. The SDP policy controller receives the message and performs authentication: if the authentication is passed, authorization is performed, and the network firewall is notified to create a first access control rule according to the authorization result: an access control rule (ACL RULE) for the source IP address + target IP address + target service port + protocol type four-tuple characteristics, that is, allowing the service to expose to the terminal. At the same time, the system sets a timeout window for the first access control rule, and if the timeout occurs, the first access control rule is forced to age and deleted, so that the service returns to the stealth state and the process ends.

[0101] Step 3, the terminal application as a client initiates an access session connection establishment process between the network side server, and successfully establishes a session connection before the first access control rule ages.

[0102] Step 4, the security agent module on the terminal side learns from the terminal application through the application's subscription notification mechanism that the access session connection is successfully established, records the session connection feature information such as the five-tuple characteristics (source IP + source port + target IP + service port + protocol type) of the connection, and constructs a connection establishment notification message to notify the SDP policy controller. Optionally, the connection establishment notification message can be protected by the inherent trust letter between the terminal and the SDP policy controller for confidentiality and integrity, and the mechanism is the same as that of the SPA authentication message.

[0103] Step 5, the SDP policy controller receives the connection establishment notification message, if it is a securely protected message, decrypts and integrity checks and restores the plaintext, and then performs network access adjustment processing according to the message content, that is, notifies the network firewall to add an access control rule entry corresponding to the established session connection characteristics, that is, a second access control rule corresponding to the five-tuple characteristics (source IP + source port + target IP + service port + protocol type) of the established session connection, and deletes the first access control rule for service port exposure in step b.

[0104] Optionally, for the abnormal scenario that the security agent cannot notify the SDP controller of the abnormal termination of the access session connection due to network interruption or terminal failure, causing the established second access control rule to be unable to be deleted, the SDP controller and the network firewall can also increase the protection mechanism, set a timeout window for the second access control rule, and when the timeout occurs, the network firewall can automatically delete the second access control rule if no matching message passes through in the subsequent several statistical periods.

[0105] At this point, the network firewall will only allow the packet of the established access session connection to pass, and the service port is back to the hidden state due to the closing of the service exposure port access. Since the second access control rule is a more stringent access rule than the first access control rule, it only allows the legal application connection session packet to pass; therefore, replacing the first access control rule with the second access control rule can effectively prevent malicious attackers from exploiting service port exposure, forging source IP addresses or exploiting the uncertainty of source ports to forge packets that can bypass the network firewall to attack network services; and the time span of service port exposure is completely consistent with the time span of the real connection establishment, avoiding the malicious attacker's use of the extra time window for probing attacks.

[0106] Step 6, when the access session between the terminal application and the network service ends, the security agent monitors and senses the session connection termination in real time through the application's subscription notification mechanism, and then constructs a connection termination notification message to notify the SDP policy controller, which contains the feature information of the session connection, i.e. the five-tuple features of the session connection (source IP + source port + target IP + service port + protocol type). Optionally, the connection termination notification message can be protected by the inherent trust letter between the terminal and the SDP policy controller for confidentiality and integrity, and the mechanism is the same as the protection of the SPA authentication packet.

[0107] Step 7, the SDP policy controller receives the connection termination notification message, if it is a securely protected packet, it needs to be decrypted and integrity checked to recover the plaintext, and then according to the message content, the network access adjustment processing is performed again, and the network firewall is notified to delete the second access control rule corresponding to the connection.

[0108] At this point, with the end of the single access of the legal terminal application to the network service, the network firewall will adjust the access rules synchronously and discard any packet corresponding to the access features, thereby avoiding the forgery and replay attacks.

[0109] The access control method provided by the embodiment of the present application can at least achieve the following beneficial effects: 1. The access control method based on single packet authorization in the existing SDP framework is improved. A security agent module that can sense the access network service state of a terminal application is implanted in the access terminal, and the opening and closing of the corresponding access control rules on the network firewall are precisely controlled through the interaction with the SDP policy controller and the network firewall, thereby improving the concealment of the network service and leaving no additional time window for malicious attackers to detect and attack. 2. During the entire life cycle of the terminal application accessing the network service, the different types of access control rules are dynamically maintained on the network firewall during the creation of the access connection and the maintenance of the access connection session, so that the network firewall realizes the full life cycle protection of the legitimate network access traffic, and the protection time window is strictly synchronized with the actual access. Not only does this ensure that the network firewall protects each network access throughout the entire life cycle of the access, thereby improving the security of the access, but also the access control policy is efficiently and automatically implemented without manual intervention to configure the network firewall. 3. By monitoring the state change of the network access session connection on the terminal side and synchronously adjusting the access control rules on the network firewall, the legitimate terminal application access network service scenarios and demands can be truly reflected, the network access packets that are forged by malicious attackers can be avoided, and the credibility of the SDP system is improved.

[0110] Please refer to Figure 9 , Figure 9 The embodiment of the present application provides a structural schematic diagram of a terminal.

[0111] As Figure 9 shown, the terminal 300 includes a processor 301 and a memory 302, and the processor 301 and the memory 302 are connected through a bus 303, such as an I2C (Inter-integrated Circuit) bus.

[0112] Specifically, the processor 301 is configured to provide calculation and control capabilities to support the operation of the entire terminal. The processor 301 can be a central processing unit (CPU), and the processor 301 can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.

[0113] Specifically, the memory 302 can be a Flash chip, a Read-Only Memory (ROM) disk, an optical disk, a U disk, or a mobile hard disk, etc.

[0114] Those skilled in the art can understand that, Figure 9 The structure shown in the figure is only a block diagram of part of the structure related to the embodiment of the present application, and does not constitute a limitation on the terminal to which the embodiment of the present application is applied. Specifically, the server can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.

[0115] The processor is configured to run a computer program stored in the memory and implement any one of the access control methods provided by the embodiments of the present application when the computer program is executed.

[0116] In an embodiment, the processor is configured to run a computer program stored in the memory and implement the following steps when the computer program is executed:

[0117] When initiating access to the target server, a single-packet authorization authentication message is sent to the policy controller, so that the policy controller notifies the network firewall to generate a first access control rule according to the verification result of the single-packet authorization authentication message; wherein the first access control rule is used for the target server to expose a service port service port to the terminal.

[0118] Based on the first access control rule, a session connection is established with the target server, and a connection establishment notification message is sent to the policy controller, so that the policy controller notifies the network firewall to generate a second access control rule and delete the first access control rule; wherein the second access control rule is used for the target server to perform admission management on the application of the terminal.

[0119] In an embodiment, when implementing the access control method, the processor is configured to implement: when the session connection with the target server is terminated, a connection termination notification message is sent to the policy controller, so that the policy controller notifies the network firewall to delete the second access control rule.

[0120] In an embodiment, when implementing the access control method, the processor is configured to implement: by API calling from the operating system of the terminal and / or by subscribing to a notification mechanism to the application of the terminal, the access behavior and access state of the application of the terminal to the target server are monitored.

[0121] In an embodiment, the processor, when implementing the access control method, is configured to implement: the first access control rule comprises the IP address of the target server, the service port and the protocol type; and the second access control rule comprises the IP address of the terminal, the source port of the terminal, the IP address of the target server, the service port and the protocol type.

[0122] It should be noted that, for the convenience and brevity of description, the specific working process of the terminal described above can refer to the corresponding process in the foregoing access control method embodiments, and will not be described here.

[0123] The embodiment of the present application also provides an access control system, which comprises a terminal, a policy controller, a network firewall and a target server; the terminal, the policy controller, the network firewall and the target server are configured to jointly execute the computer program to implement any one of the access control methods provided by the embodiment of the present application.

[0124] In an embodiment, the access control system is configured to run the computer program stored in the memory, and implement the following steps when executing the computer program:

[0125] When the terminal initiates an access to the target server, a single-packet authorization authentication message is sent to the policy controller;

[0126] The policy controller informs the network firewall to generate a first access control rule according to the verification result of the single-packet authorization authentication message; wherein the first access control rule is used for the target server to expose a service port to the terminal.

[0127] The terminal establishes a session connection with the target server based on the first access control rule, and sends a connection establishment notification message to the policy controller;

[0128] The policy controller informs the network firewall to generate a second access control rule and delete the first access control rule; wherein the second access control rule is used for the target server to perform admission management on the application of the terminal.

[0129] In an embodiment, the access control system, when implementing the access control method, is configured to implement: when the session connection between the terminal and the target server is terminated, a connection termination notification message is sent to the policy controller; and the policy controller informs the network firewall to delete the second access control rule.

[0130] In an embodiment, the access control system, when implementing the access control method, is configured to implement: performing encryption protection and integrity check on messages between the terminal and the policy controller; wherein the messages include the connection establishment notification message and the connection termination notification message.

[0131] In an embodiment, the access control system, when implementing the access control method, is configured to implement: after the network firewall generates an access control rule, if no packet conforming to the access control rule is received within a preset period, starting a timer, and if no packet conforming to the access control rule is received after the timer expires, the network firewall automatically deletes the access control rule; wherein the access control rule includes the first access control rule and the second access control rule.

[0132] In an embodiment, the access control system, when implementing the access control method, is configured to implement: the first access control rule includes the IP address of the target server, the service port and the protocol type; and the second access control rule includes the IP address of the terminal, the source port of the terminal, the IP address of the target server, the service port and the protocol type.

[0133] The embodiment of the present application also provides a storage medium for computer readable storage, the storage medium storing one or more programs, the one or more programs being executable by one or more processors to implement the steps of any one of the access control methods provided in the specification of the embodiment of the present application.

[0134] The storage medium can be an internal storage unit of the terminal, such as a hard disk or a memory of the terminal. The storage medium can also be an external storage device of the terminal, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc.

[0135] Those skilled in the art can understand that all or some of the steps in the methods disclosed above, the functional modules / units in the systems and devices can be implemented by software, firmware, hardware, or a combination thereof. In hardware embodiments, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, one physical component can have multiple functions, or one function or step can be performed by several physical components in cooperation. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on computer-readable media, which can include computer storage media (or non-transitory media) and communication media (or transitory media). As is well known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store the desired information and which can be accessed by a computer. In addition, it is well known to those skilled in the art that communication media typically embodies computer readable instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave or other transport mechanism and can include any information delivery media.

[0136] It should be understood that the term "and / or" as used herein refers to any combination of associated listed items, and all possible combinations, and includes these combinations. It should be noted that the terms "comprising", "including", or any other variant thereof are intended to cover non-exclusive inclusion, so that processes, methods, articles or systems including a series of elements not only include those elements, but also include other elements not explicitly listed, or inherent to such processes, methods, articles or systems. Without more limitations, the element defined by the phrase "comprising a" does not exclude the presence of additional identical elements in the process, method, article or system including the element.

[0137] The above-mentioned serial numbers of the embodiments of the present application are only for description, and do not represent the advantages and disadvantages of the embodiments. The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical range disclosed by the present application, and these modifications or replacements should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. An access control method, characterized in that, Applied to terminals, including: When initiating access to the target server, a single-packet authorization and authentication message is sent to the policy controller, so that the policy controller notifies the network firewall to generate a first access control rule based on the verification result of the single-packet authorization and authentication message; wherein, the first access control rule is used by the target server to expose service ports to the terminal; Based on the first access control rule, a session connection is established with the target server. If the session connection is successfully established, a connection establishment notification message is sent to the policy controller, so that the policy controller notifies the network firewall to generate a second access control rule and delete the first access control rule. The second access control rule is used by the target server to perform access control management on the terminal's applications.

2. The access control method according to claim 1, characterized in that, After the step of establishing a session connection with the target server based on the first access control rule, the method further includes: When the session connection with the target server is terminated, a connection termination notification message is sent to the policy controller so that the policy controller notifies the network firewall to delete the second access control rule.

3. The access control method according to claim 1, characterized in that, Before initiating access to the target server, the following is also included: The access behavior and access status of the terminal's applications to the target server are monitored by making API calls from the terminal's operating system and / or by subscribing to notification mechanisms for the terminal's applications.

4. The access control method according to any one of claims 1-3, characterized in that, The first access control rule includes: the IP address of the target server, the service port, and the protocol type; The second access control rule includes: the IP address of the terminal, the source port of the terminal, the IP address of the target server, the service port, and the protocol type.

5. An access control method, characterized in that, It is applied to an access control system, which includes: a terminal, a policy controller, a network firewall, and a target server; When the terminal initiates access to the target server, it sends a single-packet authorization and authentication message to the policy controller; The policy controller notifies the network firewall to generate a first access control rule based on the verification result of the single-packet authorization and authentication message; wherein, the first access control rule is used by the target server to expose service ports to the terminal; The terminal establishes a session connection with the target server based on the first access control rule, and sends a connection establishment notification message to the policy controller when the session connection is successfully established. The policy controller instructs the network firewall to generate a second access control rule and delete the first access control rule; wherein, the second access control rule is used by the target server to perform access control management on the terminal's applications.

6. The access control method according to claim 5, characterized in that, Also includes: When the session connection between the terminal and the target server is terminated, a connection termination notification message is sent to the policy controller. The policy controller instructs the network firewall to delete the second access control rule.

7. The access control method according to claim 6, characterized in that, Also includes: The messages between the terminal and the policy controller are encrypted and their integrity is verified. The messages include: the connection establishment notification message and the connection termination notification message.

8. The access control method according to claim 5, characterized in that, Also includes: After the network firewall generates access control rules, if no message conforming to the access control rules is received within a preset period, a timer is started. If no message conforming to the access control rules is received after the timer expires, the network firewall automatically deletes the access control rules. The access control rules include: the first access control rule and the second access control rule.

9. The access control method according to any one of claims 5-8, characterized in that, The first access control rule includes: the IP address of the target server, the service port, and the protocol type; The second access control rule includes: the IP address of the terminal, the source port of the terminal, the IP address of the target server, the service port, and the protocol type.

10. A terminal, characterized in that, The terminal includes a processor, a memory, a computer program stored in the memory and executable by the processor, and a data bus for implementing communication between the processor and the memory, wherein when the computer program is executed by the processor, it implements the steps of the access control method as described in any one of claims 1 to 4.

11. An access control system, characterized in that, The access control system includes: a terminal, a policy controller, a network firewall, and a target server; the terminal, policy controller, network firewall, and target server are used to jointly execute the steps of the access control method as described in any one of claims 5 to 9.

12. A storage medium for computer-readable storage, characterized in that, The storage medium stores one or more programs, which can be executed by one or more processors to implement the steps of the access control method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Access control method, device and system, computer equipment and storage medium

    CN111131310A

  • Remote Access Manager for Virtual Computing Services

    US20150058967A1