Data control method and system for intranet device intercommunication

By acquiring the security of the visitor's device during network data access and managing the access channel according to security rules, the problem of data leakage caused by the failure to consider the security of the visitor's device in the existing technology is solved, and higher security and efficiency are achieved.

CN116346428BActive Publication Date: 2025-11-18BEIJING VRV SOFTWARE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310196271.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-03
Publication Date
2025-11-18
Estimated Expiration
2043-03-03

AI Technical Summary

Technical Problem

In existing technologies, network data access control is mainly based on the identity, protocol, and port of the server and client, without fully considering the security of the visitor's device, resulting in a high risk of data leakage.

Method used

By sending self-test information to online devices, the security of the visitor's device is obtained and verified. Based on security rules, it is determined whether access is allowed, and the access channel is blocked or opened. The device address is obtained by using terminal ARP for management.

Benefits of technology

It improved the security level for visitors, reduced the data leakage rate, ensured the timeliness and security of access, and enhanced the security and efficiency of network data access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116346428B_ABST
    Figure CN116346428B_ABST
Patent Text Reader

Abstract

The application discloses a data control method and system for intranet device mutual visit, wherein the method comprises the following steps: sending first self-checking information to online devices; the online devices feed back second self-checking information based on the first self-checking information; if the second self-checking information is unsafe information, the access channel of the corresponding online device is blocked; otherwise, it is judged whether the devices corresponding to all the received second self-checking information are consistent with the online devices; if yes, it is determined that all the online devices are safe devices, and the access channel of all the safe devices is opened; if no, one or more first online devices without feeding back the second self-checking information are acquired, it is judged whether there is third self-checking information of the first online device, if yes, the third self-checking information is sent to the target device, and the access channel is opened, if no, the access channel of the first online device is blocked. The application can effectively detect the safety of the devices, ensure the safety of all information between the mutual visit devices, and provide a safe mutual visit control method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of network security technology, and in particular to a data control method and system for inter-device access within an intranet. Background Technology

[0002] With the rapid development of network applications and data security, the widespread adoption of portable terminals, and the rapid exchange of information, network security and data security are constantly impacting the development of every enterprise and individual. Enterprises use networks for collaborative work, processing various documents and other business data. In such an open and data-sharing network environment, the leakage of confidential information often occurs, posing security risks to the company.

[0003] Currently, there are many ways to control network data access, most of which are based on the server side controlling the data on the client side through network devices. These controls are based on user identity, protocols, and ports, and rarely consider the security of the visitor's device. This leads to situations where the visitor's own insecurity allows them to access data from secure devices, resulting in data theft. Summary of the Invention

[0004] In view of this, the present disclosure provides a data control method and system for inter-device access within an intranet, which can obtain the device security of the visitor / visited, update and monitor in real time, effectively improve the security level of the visitor, ensure the device security of the visitor / visited, effectively reduce the data leakage rate, and ensure the timeliness, security and efficiency of access.

[0005] Firstly, this disclosure provides a data control method for intranet device access, which can securely and effectively control network data access, while also facilitating secure terminal devices to quickly access business data and utilize the network environment. Specifically, it includes:

[0006] Send the first self-test information to the online device;

[0007] The online device feeds back second self-test information based on the first self-test information;

[0008] Determine whether the second self-test information is security information.

[0009] If not, the corresponding online device is determined to be a prohibited access device, and the access channel of the prohibited access device is blocked;

[0010] If so, determine whether the devices corresponding to all the received second self-test information are consistent with the online devices.

[0011] If so, determine that all the online devices are security devices, and open the access channels for all the security devices;

[0012] If not, obtain one or more first online devices that did not provide the second self-test information.

[0013] Determine whether the third self-test information of the first online device is stored in the security information storage list.

[0014] If so, if the first online device is determined to be a secure device, the third self-test information is sent to the target device, and the access channel is opened.

[0015] If not, the first online device is determined to be a prohibited device, and the access channel is blocked.

[0016] Optionally, sending the first self-test information to the online device includes:

[0017] Based on the list of online devices, the target device sends its online status to all the online devices.

[0018] Based on security rules, the target device performs a self-test to obtain the first self-test information;

[0019] Send the first self-test information to all the online devices.

[0020] Optionally, the step of performing a self-test on the target device based on security rules to obtain the first self-test information includes:

[0021] The device security rules, system security rules, and identity security rules of the target device are checked. If all of them are satisfied, the first self-check information is obtained.

[0022] Optionally, the device security rules include: antivirus software level requirements, port opening requirements, working software type requirements, and access device requirements;

[0023] The system security rules include: requirements for system vulnerability detection software and preset system version requirements;

[0024] The identity security rules include: preset weak password requirements, password error count lockout requirements, and new password usage cycle requirements.

[0025] Optionally, the online time of the target device is later than the online time of the online device.

[0026] Optionally, the data control method further includes:

[0027] Determine whether the device scan results of newly connected devices are safe.

[0028] If so, determine that the newly connected device is a secure device and open the access channel for the newly connected device;

[0029] If not, the newly connected device is determined to be a prohibited device, and its access channel is blocked.

[0030] Optionally, the data control method further includes:

[0031] It can determine in real time whether the identity on the security device has been logged out.

[0032] If so, determine that the security device is an access-restricted device and block the access channel;

[0033] If not, access will be reserved.

[0034] The second aspect of this application discloses a data control system for intranet terminal access, comprising:

[0035] The sending module is configured to send the first self-test information to the online device;

[0036] The feedback module is configured so that the online device can provide feedback on the second self-test information based on the first self-test information;

[0037] The first judgment module is configured to determine whether the second self-test information is security information;

[0038] The first blocking module is configured to determine that if the second self-test information is not security information, the corresponding online device is a prohibited access device and the access channel of the prohibited access device is blocked.

[0039] The second judgment module is configured to, if the second self-test information is security information, determine whether the devices corresponding to all received second self-test information are consistent with the online devices;

[0040] The first activation module is configured to, if all the devices corresponding to the received second self-test information are consistent with the online devices, determine that all the online devices are security devices and open the access channel of the security devices;

[0041] The acquisition module is configured to acquire one or more first online devices that have not fed back the second self-test information if all the devices corresponding to the received second self-test information are inconsistent with the online devices;

[0042] The third judgment module is configured to determine whether the third self-test information of the first online device is stored in the security information storage list;

[0043] The second enabling module is configured to determine that the first online device is a security device if the third self-test information of the first online device is stored in the security information storage list, send the third self-test information to the target device, and enable the access channel.

[0044] The second blocking module is configured to determine that the first online device is a prohibited access device and block the access channel if the third self-test information of the first online device is not stored in the security information storage list.

[0045] Thirdly, this disclosure also provides an electronic device that adopts the following technical solution:

[0046] The electronic device includes:

[0047] At least one processor; and,

[0048] A memory communicatively connected to the at least one processor; wherein,

[0049] The memory stores instructions that can be executed by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform any of the above-described data control methods for inter-network device access.

[0050] Fourthly, embodiments of this disclosure also provide a computer-readable storage medium storing computer instructions for causing a computer to execute any of the above-described data control methods for inter-device access within an intranet.

[0051] The data control method for intranet device access provided in this disclosure allows the visitor / visible device to perform self-checks, thereby obtaining device security information for each terminal. After verifying the terminal's security and identity, the accessed device allows the terminal visitor to interact with it on the network for normal data access and business processing. Real-time interaction enables the acquisition of the visitor's computer device's current security, allowing for rapid control of network data access and improving the security of internal network data access within the enterprise. This reduces the risk of insecure terminals accessing secure data without the knowledge of confidential personnel, thus enhancing enterprise data security. Simultaneously, it improves the timeliness and efficiency of secure terminal data access, reducing the risk of simultaneous leakage of customer data due to leaked data access identity information, and minimizing the risk of insecure terminals accessing secure data without the knowledge of confidential personnel.

[0052] The above description is merely an overview of the technical solution disclosed herein. In order to better understand the technical means of this disclosure and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this disclosure more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0053] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0054] Figure 1 This is a flowchart illustrating a specific embodiment of the data control method for inter-device access within an intranet provided in this disclosure.

[0055] Figure 2 A detailed schematic diagram illustrating the data control method for intranet device access provided in this embodiment of the present disclosure.

[0056] Figure 3 A flowchart of another embodiment of the method provided in this disclosure for performing a self-test on a target device.

[0057] Figure 4 This is a schematic diagram illustrating the processing when the target device in the method provided in this application is a passive device.

[0058] Figure 5 This is a flowchart illustrating the real-time monitoring of the identity of a security device in the method provided in this application.

[0059] Figure 6 This is a schematic diagram illustrating intranet terminal access in a specific embodiment of the method provided in this application.

[0060] Figure 7 This is a schematic diagram of the terminal configuration in this application.

[0061] Figure 8 This is a schematic diagram of the server configuration in this application.

[0062] Figure 9 This is a flowchart of the self-test process for the online devices in this application.

[0063] Figure 10 This is a schematic diagram of the device list update process for the terminal in this application.

[0064] Figure 11 A schematic diagram of the data control system for intranet device access provided in this embodiment of the disclosure.

[0065] Figure 12 This is a schematic block diagram of an electronic device provided in an embodiment of the present disclosure. Detailed Implementation

[0066] The embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0067] It should be understood that the following specific examples illustrate the implementation of this disclosure, and those skilled in the art can easily understand other advantages and effects of this disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. This disclosure can also be implemented or applied through other different specific implementation methods, and the details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this disclosure. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. Based on the embodiments in this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0068] It should be noted that various aspects of embodiments within the scope of the appended claims are described below. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any particular structure and / or function described herein is merely illustrative. Based on this disclosure, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects set forth herein can be used to implement the device and / or practice the method. Additionally, this device and / or method can be implemented using structures and / or functionalities other than one or more of the aspects set forth herein.

[0069] It should also be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of this disclosure. The drawings only show the components related to this disclosure and are not drawn according to the number, shape and size of the components in actual implementation. In actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0070] Furthermore, specific details are provided in the following description to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.

[0071] Reference Figure 1 This application provides a data control method for inter-device access within an intranet, the method comprising the following steps:

[0072] S100, sends the first self-test information to the online device;

[0073] S200, the online device feeds back the second self-test information based on the first self-test information;

[0074] S300, determine whether the second self-test information is a security information;

[0075] If not, the corresponding online device is determined to be a prohibited device, and the access channel of the prohibited device is blocked.

[0076] S400, if yes, determine whether the devices corresponding to all received second self-test information are consistent with the online devices; if yes, determine that all online devices are security devices and open the access channels of all security devices; if no, obtain one or more first online devices that have not returned second self-test information.

[0077] S500, determine whether the third self-test information of the first online device is stored in the security information storage list;

[0078] If so, determine that the first online device is a secure device, send the third self-test information to the target device, and open the access channel;

[0079] If not, the first online device is determined to be a prohibited device, and the access channel is blocked.

[0080] In this embodiment, the first self-test information is security information by default; the security information storage list is stored in the server.

[0081] Specifically, refer to Figure 2 The data control method for inter-device access within an intranet disclosed in this application specifically includes:

[0082] Based on the list of online devices, the online status of the target device is sent to all online devices to inform them that the target device is online and they can proceed with the next step.

[0083] Among them, all online devices are those online devices that were online earlier than the target device in the online device list, meaning the target device went online later than all other online devices.

[0084] Based on security rules, the target device performs a self-test, obtains the target self-test information (i.e., the first self-test information), and sends the target self-test information to all online devices.

[0085] Specifically, the target device uses the system's ARP request method to obtain the physical addresses and IP addresses of all computer devices within the subnet, in order to send online status and target self-test information to all online devices, thereby performing security management of terminals within the network.

[0086] All online devices will send their actual self-test information (i.e., second self-test information) to the target device. That is, when all online devices receive the online notification and self-test information from the target device, they will send their actual self-test information to the target device.

[0087] Then, determine whether the actual self-test information is secure. If it is insecure, determine that the corresponding device is a prohibited device and block its access channel with the target device.

[0088] If it is security information, determine whether the number of actual self-test messages received by the target device is equal to the total number of online devices. By default, there are no new devices in the online device list. Therefore, judging by the number alone can quickly determine whether there are online devices that have not returned self-test information.

[0089] If so, determine all online devices as secure devices and open their access channels with the target device;

[0090] If not, obtain the first set of devices, which includes all devices that have not fed back self-test information, that is, the first set of devices is one or more first online devices that have not fed back second self-test information.

[0091] Send an information retrieval request to the target server; the information retrieval request includes a request to retrieve backup self-test information (i.e., third self-test information) of devices that have not returned self-test information from the security information storage list;

[0092] If the target server does not respond, the corresponding device is determined to be a prohibited device, and its access channel with the target device is blocked.

[0093] If the target server responds, the third self-test information of the corresponding device is sent to the target device, and the access channel is opened.

[0094] It should be noted that when it is uncertain whether a new device has been added to the online device list, the judgment criterion can be: whether the devices corresponding to all the actual self-test information received are consistent with the devices already online.

[0095] Specifically, performing a self-check on the target device includes checking the device security rules, system security rules, and identity security rules of the target device. If all of these rules are met, the target self-check information is obtained.

[0096] The device security rules include: antivirus software level requirements, port opening requirements, software type requirements, and access device requirements.

[0097] System security rules include: requirements for system vulnerability detection software and preset system version requirements.

[0098] Identity security rules include: preset weak password requirements, password error count lockout requirements, and new password usage cycle requirements.

[0099] In this embodiment, when the target device is an active device, it means that the target device's online time is later than the online time of all other online devices, and no new devices have come online.

[0100] Reference Figure 3 In another embodiment of this application, if the target self-test information is not defaulted to security information, the self-test of the target device specifically includes the following:

[0101] Determine whether the target device meets the device security rules. If not, the target self-test information is unsafe, and the target device is determined to be a prohibited access device, and the access channel between the target device and other security devices is blocked.

[0102] If yes, meaning the target device meets the device security rules, then it is determined whether the target device meets the system security rules. If not, the target self-check information is unsafe, and the target device is determined to be a prohibited access device, and the access channel between the target device and other security devices is blocked.

[0103] If yes, meaning the target device meets the system security rules, determine whether the target device meets the identity security rules. If not, the target self-check information is insecure, and the target device is determined to be a prohibited access device, and the access channel between the target device and other security devices is blocked.

[0104] If so, meaning the target device meets the identity security rules, then the target self-check information indicates that the device is secure, and the target device is determined to be a secure device, and access channels between the target device and other secure devices are opened.

[0105] In this embodiment, the device security rules specifically include having installed antivirus software of the level specified by the company, not opening blocked ports, having installed the working software required by the company, and not connecting to unknown devices.

[0106] Among them, unknown devices include USB flash drives, mobile phones, personal computers, etc.

[0107] In this embodiment, the system security rules specifically include the installation of designated software for detecting system vulnerabilities and the installation of a system version that meets the company's requirements.

[0108] In this embodiment, the identity security rules include the weak password level being consistent with the company's requirements, the password error count locking requirements being consistent with the company's requirements, and the password usage period being consistent with the company's requirements.

[0109] Reference Figure 4 Furthermore, when the target device is a passive device, i.e., when a new device comes online later than the target device, the data control method also includes:

[0110] Determine whether the device scan results received by the target device for a newly online device are safe.

[0111] If so, determine that the newly launched device is a security device and open the access channel between the target device and the security device;

[0112] If not, the newly launched device is determined to be a prohibited device, and the access channel between the target device and the prohibited device is blocked.

[0113] In this embodiment, the target self-test information of the target device is assumed to be security information.

[0114] Reference Figure 5 When performing real-time monitoring of the identity of security devices, this data control method also includes:

[0115] Real-time detection of whether the user has logged out on the security device.

[0116] If so, determine that the security device is a prohibited access device and block the access channel between the target device and the prohibited access device;

[0117] If not, retain access channels between the target device and the security device.

[0118] In this embodiment, the target self-test information of the target device is assumed to be security information.

[0119] Reference Figures 6 to 8 The following explanation will be based on terminal A as the target device.

[0120] In this embodiment, terminal B and terminal C are online devices in the intranet online device list, and terminal D is a device that went online later than terminal A.

[0121] Each terminal includes a self-test module, a first module, a second module, an identity verification module, and a self-test status request module. The self-test module is used to perform security checks on its own device. The first module is used to send its own device's self-test information to other terminals. The second module is used to receive the self-test information sent by other terminals. The identity verification module is used to verify the login status of the other terminal that has opened the access channel and obtain the security of the other terminal in real time. The self-test status request module is used to send a request to the server to obtain the self-test information of the corresponding device if it has not received the self-test information of the online device.

[0122] The server includes a list update module, a security rule storage module, and a terminal self-test status storage module. The list update module is used to store the list of online devices on the intranet and to periodically update the list of online devices. The security rule storage module is used to store security rules. The terminal self-test status storage module is used to store the security information storage list.

[0123] In this application, the self-test module is signal-connected to the terminal self-test status storage module, which is used to store (i.e. back up) the self-test information of each terminal device in real time.

[0124] Specifically, after terminal A goes online, it performs security monitoring of its own device through its self-test module according to the security rules stored in the security rule storage module, and obtains target self-test information (i.e., security information); according to the list update module, it obtains the list of online devices on the intranet, and sends its own target self-test information (through the physical address and IP address of the terminal device point) to other online terminal devices, namely terminal B and terminal C. The purpose is to inform other online terminal devices that the device has gone online and is secure, and that terminal A is ready to establish mutual access with other secure terminals.

[0125] Alternatively, in step S100, terminal A obtains the list of online devices on the intranet according to the list update module, and sends its own online status (via the physical address and IP address of the terminal device) to other online terminal devices, namely terminals B and C. Then, terminal A performs security monitoring of its own device through its self-test module according to the security rules stored in the security rule storage module, obtains target self-test information, and sends it to all terminal devices in the intranet online device list. In this embodiment, because terminal A is not in the intranet online device list, that is, the devices in the intranet online device list are unaware of terminal A's online status, after terminal A goes online, it first informs other online devices that it has gone online.

[0126] The self-check performed by terminal A specifically includes: checking device security rules, system security rules, and identity security rules. If all are satisfied, the target self-check information is obtained. That is, the target self-check information is only output after the terminal A is determined to be safe, and then used for subsequent interactions.

[0127] Meanwhile, terminals B and C also perform self-tests on their own devices through their self-test modules, outputting the actual self-test information of the corresponding terminals.

[0128] Reference Figure 9 For self-testing of online devices, the specific procedures include:

[0129] Determine whether online devices meet the device security rules. If not, the actual self-test information is unsafe. The device security rules specifically include having company-specified level antivirus software installed, not opening blocked ports, having company-required work software installed, and not connecting to unknown devices.

[0130] If the online device meets the device security rules, then it is determined whether the online device meets the system security rules. If not, the actual self-test information is insecure. Specifically, the system security rules include having installed designated software for detecting system vulnerabilities and having installed a system version that meets company requirements.

[0131] If yes, the online device meets the system security rules. The system then checks if the online device meets the identity security rules. If not, the self-check information is insecure. The identity security rules include whether the weak password level is consistent with company requirements, whether the password error count restriction requirements are consistent with company requirements, and whether the password usage period is consistent with company requirements.

[0132] If so, meaning the online device meets the identity security rules, then the actual self-check information indicates that the device is secure.

[0133] After the online device completes its self-test, it will theoretically send its self-test information back to terminal A.

[0134] At this point, terminal A receives the security scan results of other online devices through its second module. However, online devices may not necessarily send their self-test information to terminal A, so a judgment is required.

[0135] Specifically, if the number of actual self-test messages received by terminal A is less than the number of online devices in the intranet online device list (i.e., the number of actual self-test messages received is inconsistent with the number of online devices in the intranet online device list), it indicates that there are online terminal devices that have not fed back their own device security information to terminal A; in this embodiment, either or both of terminal B and terminal C have not fed back to terminal A.

[0136] Then, terminal A sends a request to the server through its self-test status request module to obtain the self-test information of terminal devices that have not returned their own device security information, in order to obtain the self-test information of the corresponding device.

[0137] If the server does not provide feedback, it means that the terminal's self-test status storage module does not contain the corresponding device's self-test information. Therefore, the terminal device that does not provide its own security information is determined to be a prohibited access device, and the access channel between terminal A and the corresponding prohibited access device is blocked.

[0138] In this embodiment, since terminal A is a device that comes online later than terminal B and terminal C, terminal A will proactively send its own device self-test information to terminal B and terminal C.

[0139] Furthermore, after terminal A comes online, it can be updated in the intranet online device list in real time. When other devices come online, the intranet online device list will then include terminal A, terminal B, and terminal C.

[0140] When terminal D (i.e., the newly online device) comes online, terminal A is already online relative to terminal D. For terminal A, it is passive. Only when terminal A receives the self-test information sent by terminal D will it send its own self-test information to terminal D.

[0141] Specifically, it determines whether the device scan result received by terminal A from terminal D is secure; if so, terminal D is determined to be a secure device, and the access channel between terminal A and the secure device is opened; if not, terminal D is determined to be a prohibited access device, and the access channel between terminal A and the prohibited access device is blocked.

[0142] In this embodiment, the target self-test information of terminal A is assumed to be security information.

[0143] During subsequent interactions between Terminal A and the security device, the identity of the other device is monitored in real time through Terminal A's identity verification module.

[0144] Specifically, it determines in real time whether the identity on the security device has been logged out; if so, it determines that the security device is a prohibited access device and blocks the access channel between terminal A and the prohibited access device; if not, it retains the access channel between terminal A and the security device.

[0145] At this time, the real-time interaction between terminal A and the security device enables secure data access while ensuring the security of both devices and eliminating the danger of mutual access caused by security vulnerabilities in the devices.

[0146] Reference Figure 10 This application also includes updating the device list of the terminal. Taking terminal A as an example, in this case, terminal A is the terminal that started later in the list of online devices on the intranet; terminal B and terminal C are online devices in the list of online devices on the intranet; and terminal D is a device that came online later than terminal A.

[0147] Obtain the list of online devices on the intranet and use it as the first list; that is, at this time, the list of online devices on the intranet includes terminal B and terminal C.

[0148] Actively send target self-test information to all online devices; that is, terminal A sends its own target self-test information to terminal B and terminal C.

[0149] The list of online devices on the intranet is updated in real time to obtain a second list; in this embodiment, the update can be performed at a preset period of 3 to 5 seconds.

[0150] It determines whether the devices in the second list are the same as those in the first list, that is, it is used to determine whether new terminals appear in the updated list.

[0151] If not, it is determined that there is a device that starts late. At this time, terminal A becomes passive and no longer actively sends its own device status to the device that starts late.

[0152] If so, terminal A remains in an active state.

[0153] In practical project applications, specific computer devices may require access to their network resources, necessitating access control over the entire network environment. This requires support from the customer's network environment, necessitating direct or bypass connections to the device network based on the on-site deployment. This necessitates adjustments to the customer's on-site network deployment structure or bypass configuration of switches to meet the overall software deployment requirements. However, during product implementation, the customer's network deployment structure and switch equipment may not be compatible for adjustments, yet network management is a crucial functionality and a key aspect of current data security. Therefore, to meet these scenario requirements, we implement data access control at the root of data storage devices, addressing network data security at its source.

[0154] Currently, there are many ways to manage network data access. Data access control based on ARP (Address Resolution Protocol) and terminal interaction provides more secure data protection. However, it requires multiple data interactions between terminals and between terminals and servers to truly determine whether data access is open to a specific terminal. At the same time, it can better avoid the security and uncertainty of terminal devices, reducing the possibility of network data loss and network paralysis caused by insufficient terminal device security.

[0155] Existing technologies rarely consider the security of the visitor's device. This leads to data theft when a visitor with inherent security vulnerabilities accesses data on a secure device. To address this issue, our product, based on its features, implements network control over computer devices through security scanning and identity management on the client-side. When a user attempts to access secure data on another user's computer, real-time interaction with the client allows for the assessment of the user's device's current security status. This enables rapid control of network data access and reduces the risk of data loss and network outages caused by inadequate terminal device security.

[0156] In this application, taking terminal A as an example, terminal A can manage visitors and achieve accurate and rapid access control. It only needs to know whether the visitor meets the security rules of terminal A and the user's identity. Since user identity is the first condition for data access, we only need to obtain and manage the security of the visitor to determine whether the access terminal needs to be blocked, thereby meeting the user's requirements for data security.

[0157] This application is implemented on the basis of terminals accessing the network and satisfying mutual access to data. It utilizes the principle of terminals obtaining the physical address of internal network terminal devices through ARP and manages the local ARP cache of the terminals to achieve control over terminal access.

[0158] This system determines whether a specified terminal is allowed to access network data on a particular network device by utilizing interactions between terminals and between terminals and servers. It employs principles of terminal security and identity verification to determine the security of the terminal visitor and the device's identity. Once the terminal's security and identity are verified, the accessed device allows the terminal visitor to interact with it, perform normal data access and business processing, effectively improving the security of network data and the verification function of the accessing terminal machine itself. This provides better control over the data interaction process of device visitors within the network and enhances the overall security of the enterprise network environment.

[0159] Reference Figure 11 This application also discloses a data control system for intranet terminal access, including:

[0160] The sending module is configured to send the target device's self-test information to all online devices.

[0161] The feedback module is configured to feed back the actual self-test information of the online device to the target device based on the target self-test information;

[0162] The first judgment module is configured to determine whether the actual self-test information is security information;

[0163] The first blocking module is configured to determine that if the actual self-test information is not security information, the corresponding online device is a prohibited access device, and block the access channel between the target device and the prohibited access device.

[0164] The second judgment module is configured to, if the actual self-test information is security information, determine whether the devices corresponding to all the actual self-test information received by the target device are the same as the online devices, and confirm the same device by device IP and MAC address.

[0165] The first activation module is configured to, if the devices corresponding to all the actual self-test information received by the target device are consistent with the online devices, determine that all the online devices are security devices, and open the access channel between the target device and the security devices;

[0166] The acquisition module is configured to acquire a first device if the devices corresponding to all the actual self-test information received by the target device are inconsistent with the online devices, wherein the first device is an online device that has not returned self-test information.

[0167] The third judgment module is configured to determine whether the backup self-test information of the first device is stored in the security information storage list;

[0168] The second enabling module is configured to determine that the first device is a security device if the backup self-test information of the first device is stored in the security information storage list, send the backup self-test information to the target device, and enable the access channel between the target device and the security device.

[0169] The second blocking module is configured to determine that the first device is a prohibited access device if the backup self-test information of the first device is not stored in the security information storage list, and to block the access channel between the target device and the prohibited access device.

[0170] An electronic device according to embodiments of the present disclosure includes a memory and a processor. The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory. The non-volatile memory may, for example, include read-only memory (ROM), a hard disk, flash memory, etc.

[0171] The processor may be a central processing unit (CPU) or other processing unit with data processing and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions. In one embodiment of this disclosure, the processor is used to execute computer-readable instructions stored in the memory, causing the electronic device to perform all or part of the steps of the data control method for intranet device access described in the foregoing embodiments of this disclosure.

[0172] Those skilled in the art will understand that, in order to solve the technical problem of how to achieve a good user experience, this embodiment may also include well-known structures such as communication buses and interfaces, and these well-known structures should also be included within the protection scope of this disclosure.

[0173] like Figure 12 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure. It illustrates a structural schematic diagram suitable for implementing the electronic device in the embodiment of the present disclosure. Figure 4 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0174] like Figure 12As shown, an electronic device may include a processing unit (such as a central processing unit, graphics processing unit, etc.) that can perform various appropriate actions and processes based on a program stored in read-only memory (ROM) or a program loaded from a storage device into random access memory (RAM). The RAM also stores various programs and data required for the operation of the electronic device. The processing unit, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.

[0175] Typically, the following devices can be connected to the I / O interface: input devices, such as sensors or visual information acquisition devices; output devices, such as displays; storage devices, such as magnetic tapes or hard drives; and communication devices. Communication devices allow electronic devices to communicate wirelessly or wiredly with other devices (such as edge computing devices) to exchange data. Although Figure 12 Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or have alternatively.

[0176] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processing device, all or part of the steps of the data control method for intranet device access according to embodiments of this disclosure are performed.

[0177] For a detailed description of this embodiment, please refer to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.

[0178] A computer-readable storage medium according to embodiments of the present disclosure stores non-transitory computer-readable instructions. When the non-transitory computer-readable instructions are executed by a processor, all or part of the steps of the data control method for intranet device access described in the foregoing embodiments of the present disclosure are performed.

[0179] The aforementioned computer-readable storage media include, but are not limited to: optical storage media (e.g., CD-ROM and DVD), magneto-optical storage media (e.g., MO), magnetic storage media (e.g., magnetic tape or portable hard drive), media with built-in rewritable non-volatile memory (e.g., memory card), and media with built-in ROM (e.g., ROM cartridge).

[0180] For a detailed description of this embodiment, please refer to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.

[0181] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.

[0182] In this disclosure, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, devices, and systems involved in this disclosure are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as "comprising," "including," "having," etc., are open-ended terms meaning "including but not limited to," and are used interchangeably with them. The terms "or" and "and" as used herein refer to the terms "and / or," and are used interchangeably with them unless the context clearly indicates otherwise. The term "such as" as used herein refers to the phrase "such as but not limited to," and is used interchangeably with it.

[0183] Additionally, as used herein, the “or” used in a list of items beginning with “at least one” indicates a separate list, such that a list of, for example, “at least one of A, B, or C” means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word “exemplary” does not imply that the described example is preferred or better than other examples.

[0184] It should also be noted that in the systems and methods of this disclosure, the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions to this disclosure.

[0185] Various changes, substitutions, and modifications can be made to the technology described herein without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, events, means, methods, and actions described above. Currently existing or later-developed processes, machines, manufactures, events, means, methods, or actions that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Therefore, the appended claims include such processes, machines, manufactures, events, means, methods, or actions within their scope.

[0186] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.

[0187] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.

Claims

1. A data control method for inter-device communication within an intranet, characterized in that, include: Send the first self-test information to the online device; The online device feeds back second self-test information based on the first self-test information; Determine whether the second self-test information is security information. If not, the corresponding online device is determined to be a prohibited access device, and the access channel of the prohibited access device is blocked; If so, determine whether the devices corresponding to all the received second self-test information are consistent with the online device. If so, determine that all the online devices are security devices, and open the access channels for all the security devices; If not, obtain one or more first online devices that did not provide the second self-test information. Determine whether the third self-test information of the first online device is stored in the security information storage list. If so, if the first online device is determined to be a secure device, the third self-test information is sent to the target device, and the access channel is opened. If not, the first online device is determined to be a prohibited device, and the access channel is blocked; Sending the first self-test information to the online device includes: Based on the list of online devices, the target device sends its online status to all the online devices. Based on security rules, the target device performs a self-test to obtain the first self-test information; Send the first self-test information to all the online devices; The step of performing a self-test on the target device based on security rules to obtain the first self-test information includes: The device security rules, system security rules, and identity security rules of the target device are checked. If all of them are satisfied, the first self-check information is obtained.

2. The data control method according to claim 1, characterized in that, The device security rules include: antivirus software level requirements, port opening requirements, working software type requirements, and access device requirements; The system security rules include: requirements for system vulnerability detection software and preset system version requirements; The identity security rules include: preset weak password requirements, password error count lockout requirements, and new password usage cycle requirements.

3. The data control method according to claim 1, characterized in that, The online time of the target device is later than the online time of the online device.

4. The data control method according to claim 1, characterized in that, Also includes: Determine whether the device scan results of newly connected devices are safe. If so, determine that the newly connected device is a secure device and open the access channel for the newly connected device; If not, the newly connected device is determined to be a prohibited device, and its access channel is blocked.

5. The data control method according to any one of claims 1-4, characterized in that, Also includes: It can determine in real time whether the identity on the security device has been logged out. If so, determine that the security device is an access-restricted device and block the access channel; If not, access will be reserved.

6. A data control system for intranet terminal inter-access, characterized in that, include: The sending module is configured to send the first self-test information to the online device; The feedback module is configured so that the online device can provide feedback on the second self-test information based on the first self-test information; The first judgment module is configured to determine whether the second self-test information is security information; The first blocking module is configured to determine that if the second self-test information is not security information, the corresponding online device is a prohibited access device and the access channel of the prohibited access device is blocked. The second judgment module is configured to, if the second self-test information is security information, determine whether the devices corresponding to all received second self-test information are consistent with the online devices; The first activation module is configured to, if all the devices corresponding to the received second self-test information are consistent with the online devices, determine that all the online devices are security devices and activate the access channel of the security devices; The acquisition module is configured to acquire one or more first online devices that have not fed back the second self-test information if all the devices corresponding to the received second self-test information are inconsistent with the online devices; The third judgment module is configured to determine whether the third self-test information of the first online device is stored in the security information storage list; The second enabling module is configured to determine that the first online device is a security device if the third self-test information of the first online device is stored in the security information storage list, send the third self-test information to the target device, and enable the access channel. The second blocking module is configured to determine that the first online device is a prohibited access device and block the access channel if the third self-test information of the first online device is not stored in the security information storage list. Sending the first self-test information to online devices includes: based on the online device list, the target device sends its online status to all the online devices; based on security rules, the target device performs a self-test to obtain the first self-test information; and sends the first self-test information to all the online devices. The step of performing a self-test on the target device based on security rules to obtain the first self-test information includes: performing tests on the device security rules, system security rules, and identity security rules of the target device; if all are satisfied, the first self-test information is obtained.

7. An electronic device, characterized in that, The electronic device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the data control method for intranet device access as described in any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to perform the data control method for inter-network device access as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Access control method, device and equipment and readable storage medium

    CN111371738A

  • Intranet security policy detection method and device

    CN113179271A