Apparatus, method, and system for handling access control
By managing the authentication, authorization and communication modules in the device, the problems of high cost and low security in remote device access information management are solved, and more secure access control is achieved.
Patent Information
- Application Number
- CN202211206548.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-12-28
- Filing Date
- 2022-09-30
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2042-09-30
AI Technical Summary
As the number of remote devices increases, the cost of managing access information becomes high and network security decreases. Access information of multiple remote devices can be easily stolen, increasing the risk of illegal access.
The authentication module, authorization module, communication module and integration module in the management device are used to authenticate the identity and authority of the administrator device, establish a link with the network device, and set up communication port forwarding to achieve access control.
This improves network security, prevents multiple remote devices from being exposed to illegal access risks due to the theft of the same access information, and reduces management costs.
Smart Images

Figure CN116366274B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to an apparatus, a method and a system, in particular to an apparatus, a method and a system for processing access control.
BACKGROUND
[0002] In a network, when a device manager accesses a remote device, the device manager and the remote device are linked to a virtual private network (VPN), and the device manager accesses the remote device according to access information (e.g. password) of the remote device. However, in the case that the number of remote devices is increasing, the number of access information of remote devices also increases, so that the management cost of access information increases greatly. In order to save the management cost, a plurality of remote devices can be pre-configured with the same or related access information. In this case, when the access information of the virtual private network is stolen, the access information of the plurality of remote devices is easily obtained together, so that the plurality of remote devices are exposed to the risk of illegal access, thereby greatly reducing the security of the network. Therefore, how to access the remote device to improve the security of the network is a problem to be solved.
SUMMARY
[0003] The present application provides an apparatus, a method and a system for processing access control to solve the above problems.
[0004] The present application discloses a management device for processing access control, comprising: a first authentication module for receiving a first information, and executing a first decision whether an administrator device is correct according to the first information; an authorization module coupled to the first authentication module, for executing a second decision whether the administrator device comprises an access qualification of a remote device when the first decision is yes and when a first request information for accessing the remote device is received; a communication module coupled to the authorization module, for transmitting a second request information for establishing a link with a network device to the remote device when the second decision is yes and when it is decided to establish the link with the network device; and an integration module coupled to the authorization module, for transmitting a third request information for setting a communication port forwarding to the network device when the second decision is yes.
[0005] The present invention further discloses a method for processing access control for a management device, the method comprising: receiving a first message, and based on the first message, executing a first decision as to whether an administrator device is correct; when the first decision is yes and when a first request message for accessing a remote device is received, executing a second decision as to whether the administrator device includes access qualifications for the remote device; when the second decision is yes and when it is decided to establish a link with a network device, transmitting a second request message for establishing the link with the network device to the remote device; and when the second decision is yes, transmitting a third request message for setting a communication port forwarding to the network device.
[0006] The present invention further discloses a system for processing access control, comprising: a management device, comprising a first authentication module, for receiving a first message and, based on the first message, executing a first decision as to whether an administrator device is correct; an authorization module, coupled to the first authentication module, for executing a second decision as to whether the administrator device has an access qualification for the remote device when the first decision is yes and when receiving a first request message for accessing a remote device; a communication module, coupled to the authorization module, for transmitting a second request message for establishing the first link with the network device to the remote device when the second decision is yes and when deciding to establish a first link with a network device; and an integration module, coupled to the authorization module, for transmitting a request message for setting a first link with the network device when the second decision is yes. A third request message forwarded by a communication port is sent to the network device; and a network device includes an online module for receiving a fourth request message for establishing a second link from the remote device, and establishing the second link with the remote device based on the fourth request message; an integration module coupled to the online module, for receiving the third request message for setting the communication port forwarding to the remote device from the management device, and establishing the communication port forwarding based on the third request message, and transmitting a first path to the management device in response to the third request message; and a network service module coupled to the integration module, for receiving a fifth request message for accessing the remote device from the administrator device, and executing an application-level service with the remote device based on the fifth request message.
Brief Description of the Drawings
[0007] Figure 1 FIG. 1 is a schematic diagram of a network according to an embodiment of the present invention.
[0008] Figure 2 Schematic diagram of a management device according to an embodiment of the present invention.
[0009] Figure 3 FIG. 1 is a schematic diagram of a network device according to an embodiment of the present invention.
[0010] Figure 4 Flowchart of a process of embodiment 1 of the present invention.
[0011] Figure 5 Flowchart of a process of embodiment 1 of the present invention. [Specific implementation method]
[0012] Figure 1 FIG. 1 is a schematic diagram of a network 10 according to an embodiment of the present invention. The network 10 may include an external network (internet) 100, a firewall 110, and an internal network (intranet) 120. Figure 1 As shown, the network 10 can be divided into an external network 100 and an internal network 120 by a firewall 110. Specifically, the external network 100 can be a public network and can include an administrator device 1000, a management device 1002, and a network device 1004. The administrator device 1000 can be a communication device used by a device administrator. The management device 1002 can be a communication device that can be used to handle access control. The network device 1004 can be a virtual private network server (VPN server) that can be used to establish a virtual private network (VPN), such as extending the internal network 120, so that devices in the external network 100 and the internal network 120 can transmit and receive data through the external network 100. The firewall 110 may be a security device in the network 10 that can be used to separate different networks (e.g., the external network 100 and the internal network 120) and to manage (e.g., control) the transmission and reception of data in the internal network 120 to ensure the security of the internal network 120. The internal network 120 may be a private network that may include a remote device 1200. The remote device 1200 may be a communication device.
[0013] The communication devices may include user equipment (UE), low-cost devices (e.g., machine type communication (MTC)), device-to-device (D2D) communication devices, narrow-band IoT (NB-IoT) devices, power devices, servers, mobile phones, various types of computers (e.g., desktop computers, laptop computers, tablet computers), e-books, and portable computer systems, or combinations thereof, but are not limited thereto.
[0014] Figure 2 This is a schematic diagram of a management device 20 according to an embodiment of the present invention, which can be used to implement Figure 1 The management device 1002 is used to process access control. The management device 20 may include a first authentication module 200, an authorization module 210, a communication module 220 and an integration module 230. In detail, the first authentication module 200 may be received from the administrator device (e.g. Figure 1 The first authentication module 200 may receive the first information and, based on the first information, the first authentication module 200 may perform a first determination as to whether the administrator device is correct. The authorization module 210 may be coupled to the first authentication module 200 and, when the first determination is yes (i.e., the administrator device is correct) and when receiving a request for accessing a remote device (e.g., Figure 1 When the first request information of the remote device 1200 is received, the authorization module 210 may perform a second determination on whether the administrator device has access qualifications for the remote device. The communication module 220 may be coupled to the authorization module 210, and when the second determination is yes (i.e., the administrator device has access qualifications for the remote device) and when the communication module 220 determines to communicate with the network device (e.g., Figure 1 When establishing a connection with the network device 1004, the communication module 220 may transmit a second request message to the remote device for establishing a connection with the network device. The integration module 230 may be coupled to the authorization module 210 or the communication module 220. When the second determination is yes, the integration module 230 may transmit a third request message to the network device for configuring port forwarding.
[0015] In one embodiment, the first information may include, for example, an account name and password for the administrator device to access the management device 20. In one embodiment, the administrator device can access the management device 20 by opening a browser, connecting to the management device 20 on the browser, and entering the account name and password for the management device 20. In one embodiment, the first authentication module 200 may establish an account for the administrator device and may store information about the administrator device, such as, but not limited to, an account name, password, certificate, email address, or mobile phone number, in the account. In one embodiment, the first authentication module 200 may establish multiple accounts for multiple administrator devices in the network 10 and may store information about the multiple administrator devices in the multiple accounts. In one embodiment, the first authentication module 200 may compare the first information with the information about the multiple administrator devices stored therein. If the first information and the information about the multiple administrator devices have the same account name and password, the first authentication module 200 may make a first determination that the administrator device is the correct one.
[0016] In an embodiment, the first authentication module 200 can include a second authentication module. When the first decision is yes, according to the configuration of the first authentication module 200, the second authentication module can decide whether to perform multi factor authentication (MFA) on the administrator device. That is, in addition to the account name and password of the administrator device, the first authentication module 200 can further decide whether the administrator device is correct through one or more other factors. In an embodiment, the second authentication module can perform multi factor authentication on the administrator device by sending a short message to the administrator device. In detail, the second authentication module can send a short message (e.g., including a verification code) to the administrator device, according to the short message, the administrator device can send corresponding information (e.g., the verification code) to the second authentication module, in response to the short message, the second authentication module can compare the short message and the information sent by the administrator device, when the two are corresponding (e.g., the verification codes are the same), the second authentication module can decide that the administrator device is correct. In an embodiment, the second authentication module can perform multi factor authentication on the administrator device through the short message, biometric identification (e.g., scanning fingerprints or iris biometrics, etc.), a verification code application (e.g., inputting a verification code in an application), other ways that can authenticate the administrator device, or a combination of the above.
[0017] In an embodiment, the authorization module 210 can receive the first request information from the administrator device. In an embodiment, the access qualification can include at least one of an access right to access the remote device, an access time (e.g., 09:00-18:00) to access the remote device, and an access area (e.g., a country or a city) to access the remote device. In an embodiment, the authorization module 210 can establish the access qualification of the administrator device, and can store the access qualification of the administrator device in the account of the administrator device. In an embodiment, the authorization module 210 can establish the access qualifications of a plurality of administrator devices in the network 10, and can store the access qualifications of the plurality of administrator devices in a plurality of accounts. In an embodiment, the authorization module 210 can obtain (e.g., search for) the access qualification of the administrator device from the access qualifications of the plurality of administrator devices stored by the authorization module 210 according to the information of the administrator device. The authorization module 210 can compare the remote device to be accessed by the administrator device, the time to access the remote device, and the area to access the remote device with the access qualification of the administrator device, when the two are consistent (e.g., having an access right to the remote device to be accessed, the time to access the remote device being in the allowed time, and the area to access the remote device being in the allowed area), the authorization module 210 can perform the second decision of the administrator device including the access qualification of the remote device.
[0018] In one embodiment, when the first determination is yes, the authorization module 210 may perform a third determination to determine whether the administrator device has access rights to the remote device. If the third determination is yes, the authorization module 210 may transmit second information about the remote device to the administrator device. The second information may include an identity of the remote device (e.g., a name of the remote device). In one embodiment, the identity of the remote device may be displayed on a browser on the administrator device.
[0019] In one embodiment, when a link with the network device is not established (e.g., does not exist), the communication module 220 may decide to establish a link with the network device. When a link with the network device is already established (e.g., exists), the communication module 220 may decide not to establish a link with the network device. That is, when a link with the network device is previously established, the communication module 220 can transmit and receive data with the network device via the previously established link, and the communication module 220 does not need to re-establish a link with the network device. In one embodiment, the second request message may include the Internet Protocol Address (IP Address) of the network device. In one embodiment, the second request message may include data required to establish a link with the network device.
[0020] In one embodiment, the communication module 220 may transmit the second request information to the remote device via a communication protocol for information transmission (e.g., Message Queuing Telemetry Transport (MQTT), Advanced Message Queuing Protocol (AMQP), or Constrained Application Protocol (CoAP), but not limited thereto), and the communication module 220 may receive a response message transmitted by the remote device. In the above embodiment, the communication module 220 may include (e.g., have installed) a Message Queuing Telemetry Transport broker (MQTT broker) application, and may establish the identity of the remote device (e.g., client identity (client ID)) and data required to establish a link with the remote device, such as a client secret (client secret) or a credential, but not limited thereto. In addition, the remote device may include (e.g., have installed) a Message Queuing Telemetry Transport client (MQTT client) application, and may input the identity of the remote device (e.g., received from the communication module 220) and data required to establish a link with the remote device. A firewall (e.g., a firewall) between the communication module 220 and the remote device may be configured to communicate with the remote device. Figure 1The firewall 110 of the network device can open a communication port (e.g., communication port 8883) for message queue telemetry transmission. When the message queue telemetry transmission client application is started, the remote device can link to the message queue telemetry agent application of the communication module 220 to establish a link. With the link established, the communication module 220 and the network device can transmit and receive data.
[0021] In an embodiment, the third request information can include a source Internet Protocol address of the administrator device and be determined (e.g., set) as an external Internet Protocol address of the administrator device. That is, the administrator device can access the network device through the source Internet Protocol address of the administrator device. In an embodiment, the third request information includes a destination Internet Protocol address of the administrator device and is determined as an Internet Protocol address of the remote device. In an embodiment, the third request information includes a destination communication port of the administrator device and is determined as a communication port (e.g., a secure shell (SSH) communication port 22) of the remote device.
[0022] In an embodiment, the integration module 230 can transmit fourth request information to the network device for interrupting the link of the remote device and the network device. In an embodiment, the integration module 230 can transmit fifth request information to the network device for removing the configuration of the communication port forwarding of the network device. In an embodiment, the integration module 230 can transmit sixth request information to the network device for causing the network device to return a list of devices accessible to the network device and link data thereof. In an embodiment, the integration module 230 can transmit a response message to the network device for verifying the administrator device in response to a request of the network device.
[0023] In an embodiment, the integration module 230 can receive a first path from the network device in response to the third request information. According to the first path and an access token, the integration module 230 can generate a second path and transmit the second path to the administrator device. In an embodiment, the administrator device 20 can generate the access token according to the credential of the network device. For example, the administrator device 20 can encrypt data to generate the access token by using the credential of the network device. In an embodiment, the credential can include a public key credential, such as X.509, but is not limited thereto. In an embodiment, the first path and the second path can include a uniform resource locator (URL), but are not limited thereto.
[0024] In one embodiment, the administrator device can connect to the web application service of the network device by opening (e.g., typing) the second path in a browser. In one embodiment, the network device can determine whether the administrator device is the correct one. For example, through the web application service, the network device can send a seventh request message to the management device to verify whether the administrator device is the correct one (e.g., requesting the management device to compare the administrator device's Internet Protocol address to an allowed list). Furthermore, the network device can generate data based on the network device's private key and the access token. For example, using the network device's private key, the network device decrypts the access token to generate data. The network device can compare the data with the second path. In one embodiment, the data can include a session ID of the management device, and the network device can compare the session ID with the second path to see if it is the same. In one embodiment, the data can include an expiration date of the access token, and the network device can compare the expiration date of the access token with the time the administrator device accessed the remote device (e.g., whether the expiration date of the access token is within the expiration date of the access token) to prevent the administrator device from accessing the remote device using a path with an expired expiration date. In one embodiment, the data may include a renewal path for the access token, which allows the network device to transmit an eighth request message to the management device for a renewed access token (e.g., within the validity period) when the validity period of the access token expires. When the network device completes verification (e.g., confirming that the administrator device is correct) and comparison (e.g., the comparison result is identical or matching), the network device may determine that the administrator device is correct.
[0025] In one embodiment, when the network device determines that the administrator device is correct, the network device may connect to the remote device through the network application service and provide application layer services (eg, secure shell protocol) to the remote device.
[0026] In the above embodiment, the administrator device and the management device can transmit and receive data via a transmission protocol for secure communication (eg, HyperText Transfer Protocol Secure (HTTPS) or Transport Layer Security (TLS)).
[0027] In one embodiment, the management device 20 may include an operation audit module. The operation audit module may be coupled to the integration module 230 and may be used to store records of the administrator device's access to remote devices (e.g., in an operation audit log). In one embodiment, the records of the administrator device's access to remote devices may include all of the operations described in the above embodiments.
[0028] Figure 3 This is a schematic diagram of a network device 30 according to an embodiment of the present invention, which can be used to implement Figure 1 The network device 1004 is used to process access control. The network device 30 may include a connection module 300, an integration module 310 and a network service module 320. In detail, from a remote device (such as Figure 1 The connection module 300 may receive the ninth request information for establishing a connection, and according to the ninth request information, the connection module 300 may establish a connection with the remote device. In other words, a channel (tunnel) between the connection module 300 and the remote device may be established, and the connection module 300 and the remote device may transmit and receive data through the channel. The integration module 310 may be coupled to the connection module 300, and from the management device (e.g. Figure 1 The integration module 310 may receive a tenth request message for setting up a communication port forwarding to a remote device. Based on the tenth request message, the integration module 310 may establish a communication port forwarding and may transmit a first path to the management device in response to the tenth request message. The network service module 320 may be coupled to the integration module 310 and may be connected to the management device (e.g., the administrator device). Figure 1 The network service module 320 may receive an eleventh request message for accessing the remote device. According to the eleventh request message, the network service module 320 may perform an application layer service with the remote device.
[0029] In one embodiment, if the ninth request message for establishing a connection is not received from the remote device, the connection module 300 may wait for receipt of the ninth request message for establishing a connection. In one embodiment, the connection module 300 may receive a fourth request message from the management device for terminating the connection with the remote device. Based on the fourth request message, the connection module 300 may terminate the connection with the remote device. In one embodiment, the integration module 310 may receive a fifth request message from the management device for removing the communication port forwarding configuration of the network device. Based on the fifth request message, the integration module 310 may remove the communication port forwarding configuration of the network device. In one embodiment, the integration module 310 may receive a sixth request message from the management device for causing the network device to transmit a list of devices accessing the network device and their connection data. Based on the sixth request message, the integration module 310 may transmit the list of devices accessing the network device and their connection data to the management device. In one embodiment, the integration module 310 may transmit a seventh request message to the management device for verifying whether the administrator device is the correct one.
[0030] The operation of the aforementioned management device 20 can be summarized as follows: Figure 4 The process 40 can be used to implement the management device 20 and includes the following steps:
[0031] Step 400: Start.
[0032] Step 402: Receive a first message (eg, from an administrator device), and perform a first determination based on the first message whether the administrator device is correct.
[0033] Step 404: When the first determination is yes and when a first request message for accessing a remote device is received, perform a second determination of whether the administrator device includes an access qualification for the remote device.
[0034] Step 406: When the second determination is yes and when it is determined to establish a link with a network device, transmit a second request message for establishing the link with the network device to the remote device.
[0035] Step 408: When the second determination is yes, transmit a third request message for configuring a communication port forwarding to the network device.
[0036] Step 410: End.
[0037] The process 40 can be used to illustrate the operation of the management device 20. The details and variations of the process 40 can be found in the above description and will not be repeated here.
[0038] The operation of the aforementioned network device 30 can be summarized as follows: Figure 5 The process 50 can be used to implement the network device 30 and includes the following steps:
[0039] Step 500: Start.
[0040] Step 502: Receive a ninth request message for establishing a link from a remote device, and establish the link with the remote device according to the ninth request message.
[0041] Step 504: Receive a tenth request message from a management device for setting a communication port forwarding to the remote device, and establish the communication port forwarding and transmit a first path to the management device in response to the tenth request message based on the tenth request message.
[0042] Step 506: Receive an eleventh request message for accessing the remote device from the administrator device, and execute an application-level service with the remote device according to the eleventh request message.
[0043] Step 508: End.
[0044] The process 50 can be used to illustrate the operation of the network device 30. The details and variations of the process 50 can be found in the above description and will not be repeated here.
[0045] The tenth request information and the third request information may be the same information.
[0046] The above-mentioned term numbers, such as "first", "second", ..., "eleventh", are only used to distinguish similar terms and are not used to limit the order of appearance of the terms.
[0047] The term "including" mentioned above can be replaced by "for." The operation of "determining" mentioned above can be replaced by "compute," "calculate," "obtain," "generate," "output," or "use." The term "according to" mentioned above can be replaced by "by using." The term "via" mentioned above can be replaced by "on" or "in."
[0048] Those skilled in the art may combine, modify, and / or vary the above-described embodiments in accordance with the spirit of the present invention, without limitation. The aforementioned statements, modules, and / or processes (including the suggested steps) may be implemented by a device, which may be hardware, software, firmware (a combination of a hardware device and computer instructions and data, where the computer instructions and data are read-only software on the hardware device), an electronic system, or a combination of the above. The present invention may be implemented as a management device 20. The management device 20 (and the first authentication module 200, authorization module 210, communication module 220, and integration module 230 therein) may be implemented in a variety of ways. For example, the above modules may be integrated into one or more modules. The present invention may be implemented as a network device 30. The network device 30 (and the connection module 300, integration module 310, and network service module 320 therein) may be implemented in a variety of ways. For example, the above modules may be integrated into one or more modules. The present invention may be implemented as one or more of the administrator device 1000 , the management device 1002 , the network device 1004 , the firewall 110 , and the remote device 1200 , or a combination thereof.
[0049] Embodiments of the hardware may include analog circuits, digital circuits, and / or hybrid circuits. For example, the hardware may include application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), programmable logic devices (PLDs), coupled hardware components, or a combination of the foregoing. In one embodiment, the hardware includes general-purpose processors (GPs), microprocessors (microprocessors), controllers (controllers), digital signal processors (DSPs), or a combination of the foregoing.
[0050] Embodiments of software may include a set of program codes, instructions, and / or functions that may be retained (e.g., stored) in a storage unit, such as a computer-readable medium. The computer-readable medium may include a Subscriber Identity Module (SIM), a Read-Only Memory (ROM), a Flash memory, a Random-Access Memory (RAM), a CD-ROM / DVD-ROM / BD-ROM, a magnetic tape, a hard disk, an optical data storage device, a non-volatile storage device, or a combination thereof. The computer-readable medium (e.g., a storage unit) may be internally (e.g., integrated) or externally (e.g., separate) coupled to at least one processor. The at least one processor, including one or more modules, may (e.g., be configured to) execute the software from the computer-readable medium. A set of program codes, a set of instructions, and / or a set of functions may enable at least one processor, module, hardware, and / or electronic system to execute related steps.
[0051] In summary, the present invention provides a device and method for access control. Compared to conventional technologies, the device manager of the present invention cannot access remote devices based solely on the remote device's access information. Instead, it must access the remote device through a management device and a network device. This improves network security.
[0052] The above descriptions are merely preferred embodiments of the present invention. All equivalent changes and modifications made within the scope of the claims of the present invention should fall within the scope of the present invention.
[0053]
Explanation of symbols
[0054] 10: Network
[0055] 100: External network
[0056] 1000:Administrator device
[0057] 1002: Management device
[0058] 1004: Network device
[0059] 110: Firewall
[0060] 120: Internal network
[0061] 1200: Remote device
[0062] 20: Management Device
[0063] 200: First authentication module
[0064] 210: Authorization module
[0065] 220: Communication module
[0066] 230: Integration Module
[0067] 30: Network Device
[0068] 300: Online module
[0069] 310: Integration module
[0070] 320: Network service module
[0071] 40, 50: Process
[0072] 400, 402, 404, 406, 408, 410, 500, 502, 504, 506, 508: Steps
Claims
1. A management device for processing access control, the management device being disposed in an external network and communicating with a remote device in an internal network through a firewall, the management device comprising: a first authentication module configured to receive a first message from an administrator device in the external network and perform a first determination based on the first message whether the administrator device is correct; an authorization module, coupled to the first authentication module, configured to, when the first determination is yes and when receiving a first request message from the administrator device for accessing the remote device, perform a second determination as to whether the administrator device has access rights to the remote device; a communication module, coupled to the authorization module, for transmitting a second request message for establishing the link with a network device in the external network to the remote device when the second determination is yes and when it is determined to establish a link with the network device in the external network; as well as an integration module coupled to the authorization module, configured to transmit a third request message for setting a communication port forwarding to the network device when the second determination is yes; The administrator device accesses the remote device through the management device and the network device.
2. The management device as claimed in claim 1, wherein the first information includes an account name and a password for the administrator device to access the management device.
3. The management device as claimed in claim 1, wherein the first authentication module comprises: A second authentication module is used to determine whether to perform a multi-factor authentication on the administrator device when the first determination is yes. The management device as claimed in claim 1 , wherein the first request information comes from the administrator device. 5 . The management device of claim 1 , wherein the access qualification comprises at least one of an access right to access the remote device, access to the remote device during a permitted time, and access to the remote device in a permitted area.
6. The management device of claim 1 , wherein the authorization module is further configured to perform the following operations: when the first determination is yes, performing a third determination of whether the administrator device has access rights to the remote device; and When the third determination is yes, transmitting a second message of the remote device to the administrator device, The second information includes an identity of the remote device. 7 . The management device as claimed in claim 1 , wherein the communication module is further configured to perform the following operation: when the link with the network device is not established, determine to establish the link with the network device.
8. The management device as claimed in claim 1, wherein the second request information includes an Internet Protocol address of the network device.
9. The management device as described in claim 1, wherein the third request information includes at least one of the following information: a source Internet Protocol address of the administrator device, a destination Internet Protocol address of the administrator device, or a destination communication port of the administrator device, wherein the source Internet Protocol address of the administrator device is determined to be an external Internet Protocol address of the administrator device, the destination Internet Protocol address of the administrator device is determined to be an Internet Protocol address of the remote device, or the destination communication port of the administrator device is determined to be a communication port of the remote device.
10. The management device as claimed in claim 1, wherein the integration module is further configured to perform the following operations: receiving a first path from the network device in response to the third request information; and A second path is generated according to the first path and an access token, and the second path is transmitted to the administrator device. The management device as claimed in claim 10 , wherein the access token is generated according to a certificate of the network device.
12. The management device according to claim 1, further comprising: An operation audit module is coupled to the integration module and is used for storing a record of the administrator device accessing the remote device.
13. The management device as claimed in claim 1, wherein the network device comprises a virtual private network server.
14. A method for processing access control, for a management device, the management device being disposed in an external network and communicating with a remote device in an internal network through a firewall, the method comprising: receiving a first message from an administrator device in the external network, and performing a first determination based on the first message whether the administrator device is correct; When the first determination is yes and a first request message for accessing the remote device is received from the administrator device, performing a second determination of whether the administrator device has access rights to the remote device; When the second determination is yes and when it is determined to establish a link with a network device in the external network, transmitting a second request message for establishing the link with the network device to the remote device; When the second determination is yes, transmitting a third request message for setting a communication port forwarding to the network device; and The administrator device accesses the remote device through the management device and the network device. 15 . The method of claim 14 , wherein the first information includes an account name and a password for the administrator device to access the management device.
16. The method of claim 14, further comprising: When the first determination is yes, it is determined whether to perform a multi-factor authentication on the administrator device.
17. The method of claim 14, further comprising: The first request information is received from the administrator device.
18. The method of claim 14, wherein the access qualification comprises at least one of an access right to access the remote device, access to the remote device during a permitted time, and access to the remote device in a permitted area.
19. The method of claim 14, further comprising: When the first determination is yes, performing a third determination of whether the administrator device has an access permission for the remote device; and When the third determination is yes, transmitting a second message of the remote device to the administrator device, The second information includes an identity of the remote device.
20. The method of claim 14, further comprising: When the link is not established with the network device, it is decided to establish the link with the network device.
21. The method of claim 14, wherein the second request information includes an Internet Protocol address of the network device.
22. The method of claim 14, wherein the third request information includes at least one of the following information: a source Internet Protocol address of the administrator device, a destination Internet Protocol address of the administrator device, or a destination communication port of the administrator device, wherein the source Internet Protocol address of the administrator device is determined to be an external Internet Protocol address of the administrator device, the destination Internet Protocol address of the administrator device is determined to be an Internet Protocol address of the remote device, or the destination communication port of the administrator device is determined to be a communication port of the remote device.
23. The method of claim 14, further comprising: receiving a first path from the network device in response to the third request message; and A second path is generated according to the first path and an access token, and the second path is transmitted to the administrator device.
24. The method of claim 23, further comprising: The access token is generated according to a certificate of the network device.
25. The method of claim 14, further comprising: A record of the administrator device accessing the remote device is stored.
26. A system for processing access control, comprising: A management device and a network device, wherein the management device is configured in an external network and communicates with a remote device in an internal network through a firewall, and the management device includes: a first authentication module configured to receive a first message from an administrator device in the external network and perform a first determination of whether the administrator device is correct based on the first message; an authorization module, coupled to the first authentication module, configured to, when the first determination is yes and when receiving a first request message from the administrator device for accessing the remote device, perform a second determination as to whether the administrator device has access rights to the remote device; a communication module, coupled to the authorization module, for transmitting a second request message for establishing the first link with the network device to the remote device when the second determination is yes and when it is determined to establish a first link with the network device in the external network; as well as an integration module, coupled to the authorization module, for transmitting a third request message for setting a communication port forwarding to the network device when the second determination is yes; and The network device includes: a connection module configured to receive a fourth request message for establishing a second link from the remote device, and to establish the second link with the remote device according to the fourth request message; an integration module, coupled to the connection module, configured to receive the third request message for setting the communication port forwarding to the remote device from the management device, establish the communication port forwarding according to the third request message, and transmit a first path to the management device in response to the third request message; as well as a network service module, coupled to the integration module, configured to receive a fifth request message for accessing the remote device from the administrator device, and execute an application-level service with the remote device according to the fifth request message; The administrator device accesses the remote device through the management device and the network device.
Citation Information
Patent Citations
Method and System for Providing Secure Remote External Client Access to Device or Service on a Remote Network
US20150150114A1