Method, device, computer device and storage medium for remotely accessing intranet
By using multi-factor authentication based on biometric information, trusted detection, and intranet login credentials, the problem of insufficient authentication factors and unknown security in remote access to the intranet is solved, thus achieving more secure remote access.
Patent Information
- Application Number
- CN202310330606.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-30
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2043-03-30
AI Technical Summary
Existing methods for remotely accessing intranets suffer from insufficient authentication factors and unknown login endpoint security, resulting in significant security risks.
By acquiring the user's biometric information for encrypted verification, and combining trusted detection results, device configuration information, and dynamic passwords, an intranet login credential is generated. After multi-factor authentication, access to the intranet is granted upon successful verification.
It effectively verifies the legitimacy of user access behavior, reduces the security risks of remote access to the intranet, and improves the security of the login terminal.
Smart Images

Figure CN116366335B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computers, in particular to a method and device for remotely accessing an internal network, a computer device, a storage medium and a computer program product. BACKGROUND
[0002] With the development of Internet technology and the trend of digital transformation of enterprises, the demand for business network systems that can be accessed anytime and anywhere continues to increase. A secret information channel between a personal terminal and an internal network of a financial institution can be established on a public network through a virtual private network, enabling the personal to enter the internal network system of the financial institution to complete daily office work.
[0003] However, the current method of accessing the internal network system of a subject such as a financial institution through a virtual private network has the defects of insufficient authentication factors and unknown security of the login end, resulting in a high security risk in the current technology when remotely accessing the internal network system. SUMMARY
[0004] Therefore, it is necessary to provide a method and device for remotely accessing an internal network that can reduce security risks, a computer device, a computer readable storage medium and a computer program product.
[0005] In a first aspect, the present application provides a method for remotely accessing an internal network. The method comprises:
[0006] obtaining biological feature information of a user, and sending the biological feature information to a verification end for verification after encryption;
[0007] In the case where the biological feature information is verified, performing trusted detection on a login end to obtain a trusted detection result, and sending the trusted detection result to the verification end for verification after encryption; the verification end is configured to send a dynamic password to a secure terminal bound to the user in the case where the trusted detection result is verified.
[0008] obtaining a device serial number of the secure key device, and obtaining device configuration information of the login end;
[0009] obtaining an internal network login credential according to the device configuration information, the device serial number, the biological feature information and a dynamic password input by the user on the login end;
[0010] sending the internal network login credential to the verification end for verification after encryption, and accessing the internal network in the case where the internal network login credential is verified.
[0011] In one of the embodiments, after obtaining a trusted detection result by performing trusted detection on the login end, and sending the trusted detection result to the verification end for verification after encryption, the method further comprises:
[0012] In the case that the trusted detection result is verified, a dynamic password request is generated; the dynamic password request is sent to the verification end, so that the verification end generates a dynamic password after receiving the dynamic password request.
[0013] In one of the embodiments, the method further comprises:
[0014] After accessing the intranet, the running environment of the login end is detected in real time to obtain running environment detection information; the running environment detection information is analyzed according to the running environment detection condition applied to the login end; and when it is determined that the running environment of the login end is abnormal based on the analysis result of the running environment detection information, the corresponding running environment abnormal information is reported and the connection with the intranet is disconnected.
[0015] In a second aspect, the application further provides a method for remotely accessing an intranet. The method comprises:
[0016] The biological feature information of the user sent by the login end is decrypted to obtain the biological feature information, and the biological feature information is verified to obtain and return a first verification result to a security key device; wherein the security key device is connected to the login end; and the security key device is used to perform trusted detection on the login end to obtain a trusted detection result and return the trusted detection result after encryption in the case that the first verification result indicates that the biological feature information is verified.
[0017] The trusted detection result sent by the login end is decrypted to obtain the trusted detection result, and the trusted detection result is verified to obtain a second verification result;
[0018] In the case that the second verification result indicates that the trusted detection result is verified, a dynamic password is sent to a security terminal bound to the user;
[0019] The intranet login credential sent by the login end is decrypted to obtain the intranet login credential, the intranet login credential is verified to obtain a third verification result, and in the case that the third verification result indicates that the intranet login credential is verified, the login end is connected to the intranet;
[0020] The intranet login credential is obtained by the security key device according to the device configuration information of the login end, the device serial number of the security key device, the biological feature information and the dynamic password input by the user on the login end.
[0021] In one of the embodiments, the verification of the intranet login credential to obtain the third verification result comprises:
[0022] extracting the device configuration information, the device serial number, the biometric information and the dynamic password in the decrypted intranet login credential information; matching the user access account and the access right according to the device configuration information, the device serial number and the biometric information to obtain a matching result; verifying the dynamic password to obtain a password verification result; and obtaining the third verification result according to the matching result and the password verification result.
[0023] In one of the embodiments, the method further comprises:
[0024] when it is judged according to the available credential of the security key device that the current time is not within the available time limit of the security key device, setting the security key device to a deactivated state according to the device serial number of the security key device; and in the case that the deactivated state ends and the security key device is not reactivated, logging off the security key device according to the device serial number of the security key device.
[0025] In one of the embodiments, the method further comprises:
[0026] whenever the login end accesses the intranet, updating the available time limit of the security key device by the available credential.
[0027] In a third aspect, the application further provides a device for remotely accessing an intranet. The device comprises:
[0028] a feature acquisition module configured to acquire biometric information of a user and send the biometric information to a verification end for verification after encryption;
[0029] a trusted detection module configured to, in the case that the biometric information is verified, perform trusted detection on a login end to obtain a trusted detection result, send the trusted detection result to the verification end for verification after encryption, and send a dynamic password to a security terminal bound to the user by the verification end in the case that the trusted detection result is verified.
[0030] an information acquisition module configured to acquire a device serial number of the security key device and acquire device configuration information of the login end;
[0031] a credential generation module configured to obtain an intranet login credential according to the device configuration information, the device serial number, the biometric information and a dynamic password input by the user on the login end;
[0032] an intranet access module configured to send the intranet login credential to the verification end for verification after encryption, and access the intranet in the case that the intranet login credential is verified.
[0033] In a fourth aspect, the present application provides a device for remotely accessing an internal network. The device comprises:
[0034] a first verification module configured to decrypt the biological feature information of the user sent by the login terminal, verify the biological feature information, and return a first verification result to the security key device; wherein the security key device is connected to the login terminal; and the security key device is configured to perform trusted detection on the login terminal to obtain a trusted detection result and return the trusted detection result in an encrypted manner, if the first verification result indicates that the biological feature information is verified.
[0035] a second verification module configured to decrypt the trusted detection result sent by the login terminal, verify the trusted detection result, and obtain a second verification result.
[0036] a password sending module configured to send a dynamic password to a security terminal bound to the user, if the second verification result indicates that the trusted detection result is verified.
[0037] a third verification module configured to decrypt the internal network login credential sent by the login terminal, verify the internal network login credential, and obtain a third verification result, and enable the login terminal to access the internal network, if the third verification result indicates that the internal network login credential is verified.
[0038] The internal network login credential is obtained by the security key device according to the device configuration information of the login terminal, the device serial number of the security key device, the biological feature information, and a dynamic password input by the user on the login terminal.
[0039] In a fifth aspect, the present application provides a computer device. The computer device comprises a memory and a processor, the memory stores a computer program, and the processor implements the following steps when executing the computer program:
[0040] obtain the biological feature information of the user, encrypt the biological feature information, and send the biological feature information to a verification terminal for verification; perform trusted detection on a login terminal to obtain a trusted detection result, and encrypt the trusted detection result and send the trusted detection result to the verification terminal for verification, if the biological feature information is verified; the verification terminal is configured to send a dynamic password to a security terminal bound to the user, if the trusted detection result is verified; obtain the device serial number of the security key device, and obtain the device configuration information of the login terminal; obtain an internal network login credential according to the device configuration information, the device serial number, the biological feature information, and a dynamic password input by the user on the login terminal; encrypt the internal network login credential and send the internal network login credential to the verification terminal for verification, and access the internal network, if the internal network login credential is verified.
[0041] In a sixth aspect, the present application further provides a computer device. The computer device comprises a memory and a processor, the memory stores a computer program, and the processor implements the following steps when executing the computer program:
[0042] decrypting the biological feature information of the user sent by the login terminal, verifying the biological feature information to obtain a first verification result and returning the first verification result to the security key device; wherein the security key device is connected to the login terminal; the security key device is used to perform trusted detection on the login terminal to obtain a trusted detection result and return the trusted detection result in an encrypted manner when the first verification result indicates that the biological feature information is verified; decrypting the trusted detection result sent by the login terminal, verifying the trusted detection result to obtain a second verification result; sending a dynamic password to a security terminal bound to the user when the second verification result indicates that the trusted detection result is verified; decrypting the intranet login credential sent by the login terminal, verifying the intranet login credential to obtain a third verification result, and connecting the login terminal to the intranet when the third verification result indicates that the intranet login credential is verified; wherein the intranet login credential is obtained by the security key device according to the device configuration information of the login terminal, the device serial number of the security key device, the biological feature information and the dynamic password input by the user on the login terminal.
[0043] In a seventh aspect, the present application further provides a computer readable storage medium. The computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the following steps:
[0044] obtaining biological feature information of a user, encrypting and sending the biological feature information to a verification terminal for verification; performing trusted detection on a login terminal to obtain a trusted detection result when the biological feature information is verified, and encrypting and sending the trusted detection result to the verification terminal for verification; the verification terminal is used to send a dynamic password to a security terminal bound to the user when the trusted detection result is verified; obtaining a device serial number of the security key device, and obtaining device configuration information of the login terminal; obtaining an intranet login credential according to the device configuration information, the device serial number, the biological feature information and a dynamic password input by the user on the login terminal; encrypting and sending the intranet login credential to the verification terminal for verification, and connecting to the intranet when the intranet login credential is verified.
[0045] In an eighth aspect, the present application further provides a computer readable storage medium. The computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the following steps:
[0046] decrypting the biological feature information of the user sent by the login end to obtain a first verification result, and returning the first verification result to a security key device; wherein the security key device is connected to the login end; the security key device is configured to, when the first verification result indicates that the biological feature information is verified, perform trusted detection on the login end to obtain a trusted detection result and return the trusted detection result after encryption; decrypting the trusted detection result sent by the login end to obtain a second verification result by verifying the trusted detection result; when the second verification result indicates that the trusted detection result is verified, sending a dynamic password to a security terminal bound to the user; decrypting the intranet login credential sent by the login end to obtain a third verification result by verifying the intranet login credential, and when the third verification result indicates that the intranet login credential is verified, connecting the login end to the intranet; wherein the intranet login credential is obtained by the security key device according to device configuration information of the login end, a device serial number of the security key device, the biological feature information and a dynamic password input by the user on the login end.
[0047] In a ninth aspect, the present application further provides a computer program product. The computer program product comprises a computer program which, when executed by a processor, implements the following steps:
[0048] obtaining biological feature information of a user, and sending the biological feature information to a verification end for verification after encryption; when the biological feature information is verified, performing trusted detection on a login end to obtain a trusted detection result, and sending the trusted detection result to the verification end for verification after encryption; the verification end is configured to, when the trusted detection result is verified, send a dynamic password to a security terminal bound to the user; obtaining a device serial number of a security key device, and obtaining device configuration information of the login end; obtaining an intranet login credential according to the device configuration information, the device serial number, the biological feature information and a dynamic password input by the user on the login end; and sending the intranet login credential to the verification end for verification after encryption, and connecting to an intranet when the intranet login credential is verified.
[0049] In a tenth aspect, the present application further provides a computer program product. The computer program product comprises a computer program which, when executed by a processor, implements the following steps:
[0050] decrypt the user's biometric information sent by the login end, verify the biometric information to obtain a first verification result and return the first verification result to the secure key device; wherein the secure key device is connected to the login end; the secure key device is used to perform trusted detection on the login end to obtain a trusted detection result and return the trusted detection result in an encrypted manner in a case where the first verification result indicates that the biometric information passes the verification; decrypt the trusted detection result sent by the login end, verify the trusted detection result to obtain a second verification result; in a case where the second verification result indicates that the trusted detection result passes the verification, send a dynamic password to a secure terminal bound to the user; decrypt the intranet login credential sent by the login end, verify the intranet login credential to obtain a third verification result, and in a case where the third verification result indicates that the intranet login credential passes the verification, enable the login end to access the intranet; wherein the intranet login credential is obtained by the secure key device according to device configuration information of the login end, a device serial number of the secure key device, the biometric information and a dynamic password input by the user on the login end.
[0051] The method, device, computer device, storage medium and computer program product for remotely accessing an intranet, by obtaining biometric information of a user, encrypting and sending the biometric information to a verification end for verification; in a case where the biometric information passes the verification, performing trusted detection on the login end to obtain a trusted detection result, encrypting and sending the trusted detection result to the verification end for verification; obtaining an intranet login credential according to device configuration information, a device serial number, biometric information and a dynamic password input by the user on the login end; encrypting and sending the intranet login credential to the verification end for verification, and in a case where the intranet login credential passes the verification, accessing the intranet. In this way, when verifying the legality of the user's remote access behavior, the user and the login end are verified by using multiple authentication factors such as biometric information, trusted detection results and intranet login credentials, which makes up for the defects of insufficient authentication factors and unknown security of the login end in traditional technologies, and can accurately and effectively verify whether the user's access behavior is legal and compliant, thereby reducing the security risk of remotely accessing the intranet. BRIEF DESCRIPTION OF DRAWINGS
[0052] Figure 1 An application environment diagram of the method for remotely accessing an intranet in an embodiment;
[0053] Figure 2 A flowchart of the method for remotely accessing an intranet in an embodiment;
[0054] Figure 3 A flowchart of the step of detecting the running environment of the login end in an embodiment;
[0055] Figure 4A flowchart of a method for remotely accessing an intranet in another embodiment;
[0056] Figure 5 A flowchart of a step for obtaining a third verification result in an embodiment;
[0057] Figure 6 A flowchart of a method for remotely accessing an intranet in another embodiment;
[0058] Figure 7 A flowchart of a method for remotely accessing an intranet in another embodiment;
[0059] Figure 8 A structural block diagram of an apparatus for remotely accessing an intranet in an embodiment;
[0060] Figure 9 A structural block diagram of an apparatus for remotely accessing an intranet in an embodiment;
[0061] Figure 10 An internal structural diagram of a computer device in an embodiment;
[0062] Figure 11 An internal structural diagram of a computer device in another embodiment. DETAILED DESCRIPTION
[0063] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.
[0064] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions.
[0065] The method for remotely accessing an intranet provided by the embodiments of the present application can be applied to an application environment as shown in Figure 1 The security key device 101 can be connected to the login end 102 by wire and is in communication connection with the verification end 103 through a network. The data storage system can store data required to be processed by the verification end 103. The data storage system can be integrated on the verification end 103, or can be placed on a cloud or other network server.
[0066] Specifically, the security key device 101 acquires the biometric information of the user, encrypts the biometric information and sends it to the verification end 103 for verification; in the case where the biometric information is verified, the trusted detection result of the login end 102 is obtained, the trusted detection result is encrypted and sent to the verification end 103 for verification; the verification end 103 is configured to send a dynamic password to the security terminal bound to the user in the case where the trusted detection result is verified; acquire the device serial number of the security key device 101, and acquire the device configuration information of the login end 102; according to the device configuration information, the device serial number, the biometric information and the dynamic password input by the user on the login end 102, the intranet login credential is obtained; the intranet login credential is encrypted and sent to the verification end 103 for verification, and in the case where the intranet login credential is verified, the intranet is accessed.
[0067] The login end 102 can be, but is not limited to, various personal computers, notebook computers, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The verification end 103 can be implemented by an independent server or a server cluster composed of multiple servers.
[0068] In one embodiment, as shown in Figure 2 , a method for remotely accessing an intranet is provided. The method is applied to the security key device 101 in Figure 1 , and includes the following steps:
[0069] Step S201, acquiring the biometric information of the user, encrypting the biometric information and sending it to the verification end for verification.
[0070] The biometric information includes physiological characteristics inherent to the human body, such as facial features, fingerprints, palm prints, finger vein features, etc.
[0071] Specifically, the security key device 101 acquires the biometric information of the user in response to the remote access request of the intranet initiated by the user on the login end 102, and encrypts the biometric information and sends it to the verification end 103 for verification through the login end 102; the verification end 103 receives and decrypts the biometric information of the user sent by the login end 102, verifies the biometric information and returns the first verification result to the security key device 101.
[0072] Step S202, in the case where the biometric information is verified, the trusted detection result of the login end is obtained, the trusted detection result is encrypted and sent to the verification end for verification.
[0073] Among them, the trusted detection is mainly the detection of the operating system, for example: a. User representation and identification, requiring that the terminal operating system user should have a unique identification, and enabling the device unlock password, and then making the device lock screen to make the user log in again; b. Log audit; c. Configuration check, including operating system, kernel version and other information, and the operating system should be upgraded to a secure version; d. Abnormal process detection; e. Port scanning and firewall detection.
[0074] Specifically, the security key device 101 acquires the first verification result returned by the verification end 103, and in the case where it is identified that the biometric information verification is passed, detects the operating system of the login end 102 to obtain a trusted detection result, and sends the trusted detection result to the verification end 103 for verification after encryption; the verification end 103 receives and decrypts the trusted detection result sent by the login end 102, and verifies the trusted detection result to obtain a second verification result, and in the case where the second verification result indicates that the trusted detection result verification is passed, sends a dynamic password to the security terminal (such as the user's bound mobile phone) bound by the user.
[0075] Step S203, acquiring the device serial number of the security key device, and acquiring the device configuration information of the login end; according to the device configuration information, the device serial number, the biometric information and the dynamic password input by the user on the login end, obtaining an intranet login credential.
[0076] Among them, the device configuration information refers to the hardware configuration information of the login end device.
[0077] Among them, the intranet login credential is composed of four parts of device configuration information, device serial number, biometric information and dynamic password.
[0078] Specifically, the security key device 101 acquires the device serial number of the security key device 101 in response to the intranet login credential generation request, and acquires the device configuration information of the login end 102; the device configuration information, the device serial number, the biometric information and the dynamic password input by the user on the login end 102 are fused to obtain the intranet login credential.
[0079] Step S204, the intranet login credential is sent to the verification end for verification, and in the case where the intranet login credential verification is passed, access to the intranet.
[0080] Specifically, the security key device 101 sends the intranet login credential to the verification end 103 for verification after encryption; the verification end 103 receives and decrypts the intranet login credential sent by the login end 102, and verifies the intranet login credential to obtain a third verification result, and in the case where the third verification result indicates that the intranet login credential verification is passed, the login end 102 is accessed to the intranet.
[0081] The method for remotely accessing the internal network in the embodiment, by acquiring the biometric information of the user, encrypts the biometric information and sends it to the verification end for verification; in the case that the biometric information verification is passed, performs trusted detection on the login end to obtain a trusted detection result, encrypts the trusted detection result and sends it to the verification end for verification; according to the device configuration information, the device serial number, the biometric information and the dynamic password input by the user on the login end, obtains the internal network login credential; encrypts the internal network login credential and sends it to the verification end for verification, in the case that the internal network login credential verification is passed, accesses the internal network. In this way, when verifying the legality of the remote access behavior of the user, by using the biometric information, the trusted detection result and the internal network login credential and other authentication factors to verify the user and the login end, the defects of insufficient authentication factors and unknown security of the login end in the traditional technology are made up, the access behavior of the user can be accurately and effectively verified to be legal and compliant, thereby reducing the security risk of remotely accessing the internal network.
[0082] In one of the embodiments, after the trusted detection result is obtained by performing trusted detection on the login end 102, the trusted detection result is encrypted and sent to the verification end 103 for verification, the following steps are further included:
[0083] In the case that the trusted detection result verification is passed, a dynamic password request is generated; the dynamic password request is sent to the verification end 103, so that the verification end 103 generates a dynamic password after receiving the dynamic password request.
[0084] The dynamic password can be a random number combination generated according to a general / special algorithm, each password can be used only once, and is widely used in online banking, online games, telecom operators, e-commerce and other fields.
[0085] Specifically, the security key device 101 identifies the verification result information of the trusted detection result, generates a dynamic password request in the case that the trusted detection result verification is passed; the dynamic password request is sent to the verification end 103, so that the verification end 103 generates a dynamic password after receiving the dynamic password request.
[0086] In the embodiment, in the case that the trusted detection result verification is passed, a dynamic password request is generated and sent to the verification end; so that the verification end generates a dynamic password after receiving the dynamic password request, the dynamic password is sent to the security mobile phone submitted by the user in advance and passed the authentication, thereby reducing the security risk of remotely accessing the internal network.
[0087] In one of the embodiments, as shown in Figure 3 the following steps are further included:
[0088] Step S301, after accessing the intranet, the running environment of the login terminal is detected in real time to obtain running environment detection information.
[0089] Step S302, the running environment detection information is analyzed according to the running environment detection condition applied to the login terminal.
[0090] Step S303, when the running environment of the login terminal is determined to be abnormal, the corresponding running environment abnormal information is reported and the connection with the intranet is disconnected based on the analysis result of the running environment detection information.
[0091] The running environment of the login terminal refers to whether the login terminal has operation overreach and malicious attack behavior, and system and antivirus software alarm conditions.
[0092] The running environment detection condition refers to an index for detecting whether the running environment of the login terminal is abnormal, which is preset according to the relevant experience of a person skilled in the art.
[0093] Specifically, the security key device 101 detects the running environment of the login terminal 102 in real time after accessing the intranet to obtain running environment detection information, obtains the running environment detection condition applied to the login terminal 102, analyzes the running environment detection information according to the running environment detection condition, and reports the corresponding running environment abnormal information to the intranet access control center and disconnects the connection between the login terminal 102 and the intranet based on the analysis result of the running environment detection information.
[0094] In this embodiment, the running environment of the login terminal is detected in real time, the running environment detection information is analyzed, and the corresponding running environment abnormal information is reported and the connection with the intranet is disconnected when the running environment of the login terminal is determined to be abnormal, thereby reducing the threat of penetration attack when the running environment of the login terminal is abnormal.
[0095] In one embodiment, as shown in Figure 4 , the application also provides a method for remotely accessing an intranet, which is applied to the verification terminal 103 in Figure 1 for example, and includes the following steps:
[0096] Step S401, decrypting the user's biological feature information sent by the login terminal to obtain the biological feature information, verifying the biological feature information to obtain a first verification result and returning the first verification result to the security key device.
[0097] Step S402, decrypting the trusted detection result sent by the login terminal to obtain the trusted detection result, verifying the trusted detection result to obtain a second verification result.
[0098] Step S403, in the case that the second verification result indicates that the trusted detection result passes the verification, a dynamic password is sent to the security terminal bound to the user.
[0099] In step S404, the login end sent internal network login credentials are decrypted, the internal network login credentials are verified to obtain a third verification result, and in the case where the third verification result indicates that the internal network login credentials pass the verification, the login end is connected to the internal network.
[0100] The first verification result refers to the verification result information obtained by verifying the biometric information.
[0101] The second verification result refers to the verification result information obtained by verifying the trusted detection result.
[0102] The third verification result refers to the verification result information obtained by verifying the internal network login credentials.
[0103] Specifically, the security key device 101 acquires the biometric information of the user, and sends the biometric information to the verification end 103 through the login end 102 for verification. The verification end 103 decrypts the biometric information sent by the login end 102, verifies the biometric information, obtains the first verification result, and returns the first verification result to the security key device 101. The security key device 101 acquires the first verification result returned by the verification end 103, and in the case where the biometric information passes the verification, detects the operating system of the login end 102 to obtain a trusted detection result, encrypts the trusted detection result, and sends the trusted detection result to the verification end 103 for verification. The verification end 103 decrypts the trusted detection result sent by the login end 102, verifies the trusted detection result, obtains the second verification result, and in the case where the trusted detection result passes the verification, sends a dynamic password to the security terminal (such as a mobile phone) bound by the user. The security key device 101 acquires the device serial number of the security key device 101 and the device configuration information of the login end 102, fuses the device configuration information, the device serial number, the biometric information, and the dynamic password input by the user on the login end 102, encrypts the obtained internal network login credentials, and sends the internal network login credentials to the verification end 103 for verification. The verification end 103 decrypts the internal network login credentials sent by the login end 102, verifies the internal network login credentials, obtains the third verification result, and in the case where the internal network login credentials pass the verification, connects the login end 102 to the internal network.
[0104] In this embodiment, the user's biometric information sent by the login terminal 102, the trusted detection result sent by the login terminal 102, and the intranet login credential sent by the login terminal 102 are obtained by being decrypted in sequence, and the first verification result, the second verification result, and the third verification result are obtained by verifying them. That is, when verifying the legality of the user's remote access behavior, the user and the login terminal are verified by using multiple authentication factors such as biometric information, trusted detection results, and intranet login credentials, which makes up for the defects of insufficient authentication factors and unknown login terminal security in the traditional technology, and can accurately and effectively verify whether the user's access behavior is legal and compliant, thereby reducing the security risk of remote access to the intranet.
[0105] In one of the embodiments, as shown in Figure 5 The step S404 of verifying the intranet login credential to obtain the third verification result specifically includes the following steps.
[0106] Step S501: Extract the device configuration information, device serial number, biometric information, and dynamic password in the decrypted intranet login credential information.
[0107] Step S502: Match the user access account and access authority according to the device configuration information, device serial number, and biometric information to obtain a matching result.
[0108] Step S503: Verify the dynamic password to obtain a password verification result.
[0109] Step S504: Obtain the third verification result according to the matching result and the password verification result.
[0110] The access authority refers to a mechanism for limiting access to certain information items or certain controls according to the user's identity and membership in various predefined groups. Access control is usually used by system administrators to control user access to network resources (such as servers, directories, and files), and is usually implemented by granting users and groups the right to access specific objects.
[0111] Specifically, the verification terminal 103 extracts the device configuration information, device serial number, biometric information, and dynamic password in the decrypted intranet login credential information; matches the user access account and access authority according to the device configuration information, device serial number, and biometric information to obtain a matching result; verifies the dynamic password to obtain a password verification result; and fuses the matching result and the password verification result to form the third verification result.
[0112] In this embodiment, the user access account and access right are matched according to the device configuration information, the device serial number and the biometric information, a matching result is obtained, the dynamic password is verified, a password verification result is obtained, and a third verification result is obtained according to the matching result and the password verification result. Thus, the login terminal 102 is verified by four elements, i.e., the device configuration information, the device serial number, the biometric information and the dynamic password, and the reliability of the third verification result is improved.
[0113] In one of the embodiments, the following is further included: when it is judged according to the available credential of the security key device that the current time is not within the available time limit of the security key device, the security key device is set to a deactivated state according to the device serial number of the security key device; and in the case that the deactivated state ends and the security key device is not reactivated, the security key device is deregistered according to the device serial number of the security key device. The available time limit of the security key device is updated by the available credential each time the login terminal accesses the intranet.
[0114] Specifically, the verification terminal 103 monitors the available credential of the security key device 101 in real time, when it is judged that the current time is not within the available time limit of the security key device 101, the device serial number of the security key device 101 is queried, and the security key device 101 is set to a deactivated state according to the device serial number; in the case that the deactivated state ends and the security key device 101 is not reactivated, the security key device 101 is deregistered according to the device serial number of the security key device 101. The verification terminal 103 updates the available time limit of the security key device 101 by the available credential each time the login terminal 102 accesses the intranet.
[0115] In this embodiment, when it is judged according to the available credential of the security key device that the current time is not within the available time limit of the security key device, the security key device is set to a deactivated state; and in the case that the deactivated state ends and the security key device is not reactivated, the security key device is deregistered; thus, the threat of penetration attack on the intranet system and the security risk of remote access to the intranet are reduced.
[0116] In one embodiment, as shown in Figure 6 , applied to the security key device 101 and the verification terminal 103, another method for remotely accessing the intranet is provided, which specifically includes the following steps:
[0117] In step S601, the security key device obtains the biometric information of the user, and sends the biometric information to the verification terminal for verification after encryption.
[0118] In step S602, the verification terminal decrypts the biometric information of the user sent by the login terminal, verifies the biometric information, obtains a first verification result, and returns the first verification result to the security key device.
[0119] In step S603, if the biometric information verification is successful, the security key device performs a trust detection on the login terminal to obtain a trust detection result, and then encrypts and sends the trust detection result to the verification terminal for verification.
[0120] Step S604: If the trusted detection result is verified, the security key device generates a dynamic password request; and sends the dynamic password request to the verification end so that the verification end can generate a dynamic password after receiving the dynamic password request.
[0121] Step S605: The verification terminal decrypts the trusted detection result sent by the login terminal, verifies the trusted detection result to obtain a second verification result; if the second verification result indicates that the trusted detection result has been verified, a dynamic password is sent to the user's bound security terminal.
[0122] Step S606: The security key device obtains the device serial number of the security key device and the device configuration information of the login terminal; based on the device configuration information, device serial number, biometric information and dynamic password entered by the user on the login terminal, an intranet login credential is obtained; the intranet login credential is encrypted and sent to the verification terminal for verification.
[0123] Step S607: The verification end decrypts the intranet login credential sent by the login end and extracts the device configuration information, device serial number, biometric information and dynamic password from the decrypted intranet login credential information; based on the device configuration information, device serial number and biometric information, the user access account and access permissions are matched to obtain the matching result; the dynamic password is verified to obtain the password verification result.
[0124] In step S608, the verification end obtains a third verification result based on the matching result and the password verification result; if the third verification result indicates that the intranet login credential verification is successful, the login end is connected to the intranet.
[0125] Step S609: After the security key device is connected to the intranet, it detects the operating environment of the login terminal in real time and obtains the operating environment detection information; it analyzes the operating environment detection information based on the operating environment detection conditions applied to the login terminal; based on the analysis results of the operating environment detection information, if it is determined that there is an abnormality in the operating environment of the login terminal, it reports the corresponding operating environment abnormality information and disconnects the connection with the intranet.
[0126] In step S610, when the verification end determines that the current time is not within the available time limit of the security key device based on the available credentials of the security key device, it sets the security key device to a disabled state according to the device serial number of the security key device; if the disabled state ends and the security key device is not reactivated, it cancels the security key device according to the device serial number of the security key device.
[0127] Step S611, the authentication end updates the available time limit of the security key device through the available credentials whenever the login end accesses the intranet.
[0128] The method for remotely accessing an intranet of the embodiment, when verifying the legitimacy of the remote access behavior of a user, verifies the user and the login end by using multiple authentication factors such as biometric information, trusted detection results, and intranet login credentials, which makes up for the defects of insufficient authentication factors and unknown security of the login end in traditional technologies, can accurately and effectively verify whether the access behavior of the user is legitimate and compliant, and thus reduces the security risk of remotely accessing the intranet.
[0129] In order to more clearly illustrate the method for remotely accessing an intranet provided by the embodiments of the present application, the method for remotely accessing an intranet is specifically described below with one specific embodiment. In one embodiment, as shown in Figure 7 The present application also provides another method for remotely accessing an intranet, specifically including the following steps:
[0130] After the login terminal accesses the security key device, the user needs to perform fingerprint recognition to enable the security key device, and the fingerprint feature a is saved in this session. Then the security key device performs trusted detection on the terminal, the detection result is signed and encrypted, and then sent to the authentication end. After the trusted detection result is passed, the authentication end sends the dynamic password b to the user's security mobile phone; then the login credential generation module obtains the device serial number (tamper-proof) c, terminal configuration information d, forms the login credential {a+b+c+d}, signs and encrypts, and sends to the authentication end. After completing the multi-factor authentication, the user terminal successfully accesses the enterprise internal network, at this time the user terminal monitoring module monitors the terminal running environment and detects whether the user has malicious attack behavior in the session, and if there is an exception, it will immediately alarm and disconnect. The device deactivation and logout module of the authentication end can set the security key device accessed by the terminal showing abnormal to the "deactivation period" state through the serial number, and if the device owner does not activate it at the administrator before the "deactivation period" ends, the device will be logged out.
[0131] The beneficial effects brought by the above embodiments are as follows: (1) solving the risk brought by the exposure of enterprise intranet office application to the outside, using security key for identity authentication and device trusted detection; (2) proposing to obtain dynamic password through fingerprint recognition, and combining multi-factor authentication mode of security key tamper-proof serial number information, fingerprint information and security mobile phone, solving the risk that static password may be leaked, and reducing the trouble of users saving static password; (3) proposing continuous running environment monitoring and user behavior monitoring, avoiding the attack risk of internal system caused by possible hijacking of user terminal in remote office scenario.
[0132] It should be understood that although each step in the flowchart involved in each embodiment as described above is shown in sequence according to the direction of the arrow, these steps are not necessarily executed in the order indicated by the arrow. Unless explicitly stated herein, there is no strict order limitation for the execution of these steps, and these steps can be executed in other orders. Moreover, at least part of the steps in the flowchart involved in each embodiment as described above can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily sequential, but can be alternately executed with at least part of other steps or steps or stages in other steps.
[0133] Based on the same inventive concept, the embodiments of the present application also provide a device for implementing the method of remotely accessing an internal network as described above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme described in the above method, so the specific limitations in one or more device embodiments for remotely accessing an internal network provided below can refer to the limitations of the method for remotely accessing an internal network described above, which will not be repeated here. Both the method and the device can be used in the field of financial technology or other related fields.
[0134] In one embodiment, as shown in Figure 8 a device for remotely accessing an internal network is provided, comprising:
[0135] The feature acquisition module 801 is configured to acquire biological feature information of a user, and encrypt the biological feature information and send it to a verification end for verification.
[0136] The trusted detection module 802 is configured to, in the case that the biological feature information passes the verification, perform trusted detection on the login end to obtain a trusted detection result, encrypt the trusted detection result and send it to the verification end for verification; and the verification end is configured to, in the case that the trusted detection result passes the verification, send a dynamic password to a security terminal bound to the user.
[0137] The information acquisition module 803 is configured to acquire a device serial number of a security key device, and acquire device configuration information of the login end.
[0138] The credential generation module 804 is configured to obtain an internal network login credential according to the device configuration information, the device serial number, the biological feature information and a dynamic password input by the user on the login end.
[0139] The internal network access module 805 is configured to encrypt the internal network login credential and send it to the verification end for verification, and in the case that the internal network login credential passes the verification, access the internal network.
[0140] In one embodiment, the device for remotely accessing the intranet further comprises a password request module configured to generate a dynamic password request if the trusted detection result is verified; and send the dynamic password request to the verification end, so that the verification end generates a dynamic password after receiving the dynamic password request.
[0141] In one embodiment, the device for remotely accessing the intranet further comprises an environment detection module configured to, after accessing the intranet, detect a running environment of the login end in real time to obtain running environment detection information; analyze the running environment detection information according to a running environment detection condition applied to the login end; and based on an analysis result of the running environment detection information, report corresponding running environment abnormal information and disconnect the connection with the intranet if the running environment of the login end is determined to be abnormal.
[0142] In one embodiment, as shown in FIG. 9, a device for remotely accessing an intranet is provided, comprising: Figure 9
[0143] A first verification module 901 is configured to decrypt the biological feature information of the user sent by the login end, verify the biological feature information, obtain a first verification result, and return the first verification result to a security key device; wherein the security key device is connected to the login end; and the security key device is configured to, if the first verification result indicates that the biological feature information is verified, perform trusted detection on the login end to obtain a trusted detection result and encrypt the trusted detection result for return.
[0144] A second verification module 902 is configured to decrypt the trusted detection result sent by the login end, verify the trusted detection result, and obtain a second verification result.
[0145] A password sending module 903 is configured to, if the second verification result indicates that the trusted detection result is verified, send a dynamic password to a security terminal bound to the user.
[0146] A third verification module 904 is configured to decrypt the intranet login credential sent by the login end, verify the intranet login credential, obtain a third verification result, and make the login end access the intranet if the third verification result indicates that the intranet login credential is verified.
[0147] The intranet login credential is obtained by the security key device according to the device configuration information of the login end, the device serial number of the security key device, the biological feature information, and the dynamic password input by the user on the login end.
[0148] In an embodiment, the third verification module 904 is further configured to extract the device configuration information, the device serial number, the biometric information and the dynamic password from the decrypted intranet login credential information; match the user access account and the access right according to the device configuration information, the device serial number and the biometric information to obtain a matching result; verify the dynamic password to obtain a password verification result; and obtain a third verification result according to the matching result and the password verification result.
[0149] In an embodiment, the device for remotely accessing an intranet further comprises a device monitoring module configured to, when it is determined according to the available credential of the security key device that the current time is not within the available time limit of the security key device, set the security key device to a deactivated state according to the device serial number of the security key device; and in the case that the deactivated state ends and the security key device is not reactivated, log out the security key device according to the device serial number of the security key device.
[0150] In an embodiment, the device monitoring module is further configured to update the available time limit of the security key device through the available credential each time the terminal accesses the intranet.
[0151] The above modules of the device for remotely accessing an intranet can be implemented wholly or partially by software, hardware and combinations thereof. The above modules can be embedded in or independent of a processor in a computer device in hardware form, or stored in a memory in a computer device in software form, so as to be called and executed by a processor to perform the operations corresponding to the above modules.
[0152] In an embodiment, a computer device is provided, which can be a terminal, and an internal structure diagram of the computer device can be as shown in Figure 10As shown in the figure. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. Among them, the processor, the memory and the input / output interface are connected through the system bus, the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control ability. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The input / output interface of the computer device is used to exchange information between the processor and the external device. The communication interface of the computer device is used to communicate with the external terminal in a wired or wireless manner. The wireless manner can be realized through WIFI, mobile cellular network, NFC (near field communication) or other technologies. The computer program is executed by the processor to realize a method for remotely accessing an internal network. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the computer device, or an external keyboard, touchpad or mouse, etc.
[0153] In one embodiment, a computer device, which can be a server, is provided, and an internal structure diagram of the computer device can be as shown in the figure. Figure 11 As shown in the figure. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. Among them, the processor, the memory and the input / output interface are connected through the system bus, the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control ability. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The database of the computer device is used to store dynamic password, device configuration information and device serial number and other data. The input / output interface of the computer device is used to exchange information between the processor and the external device. The communication interface of the computer device is used to communicate with the external terminal through network connection. The computer program is executed by the processor to realize a method for remotely accessing an internal network.
[0154] Those skilled in the art can understand that, Figure 10 and Figure 11The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0155] In an embodiment, a computer device is also provided, including a memory and a processor, the memory storing a computer program, and the processor implementing the steps in the above method embodiments when executing the computer program.
[0156] In an embodiment, a computer readable storage medium is provided, storing a computer program, and the computer program implementing the steps in the above method embodiments when executed by a processor.
[0157] In an embodiment, a computer program product is provided, including a computer program, and the computer program implementing the steps in the above method embodiments when executed by a processor.
[0158] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (Read-Only Memory, ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (Magnetoresistive Random Access Memory, MRAM), ferroelectric memory (Ferroelectric Random Access Memory, FRAM), phase change memory (Phase Change Memory, PCM), graphene memory, etc. Volatile memory can include random access memory (Random Access Memory, RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (Static Random Access Memory, SRAM) or dynamic random access memory (Dynamic Random Access Memory, DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.
[0159] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.
[0160] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A method for remotely accessing an intranet, characterized in that, Applied to a security key device, the method includes: Obtain the user's biometric information, encrypt the biometric information and send it to the verification terminal for verification; If the biometric information verification is successful, a trust detection is performed on the login terminal to obtain a trust detection result, and the trust detection result is encrypted and sent to the verification terminal for verification; the verification terminal is used to send a dynamic password to the user's bound security terminal if the trust detection result verification is successful. Obtain the device serial number of the security key device, and obtain the device configuration information of the login terminal; Based on the device configuration information, the device serial number, the biometric information, and the dynamic password entered by the user at the login terminal, an intranet login credential is obtained; The intranet login credentials are encrypted and sent to the verification terminal for verification. If the intranet login credentials are verified, access to the intranet is granted.
2. The method according to claim 1, characterized in that, After performing a trust check on the login terminal to obtain a trust check result, and encrypting and sending the trust check result to the verification terminal for verification, the method further includes: If the trusted detection result is verified, a dynamic password request is generated; The dynamic password request is sent to the verification terminal so that the verification terminal can generate a dynamic password after receiving the dynamic password request.
3. The method according to claim 1, characterized in that, The method further includes: After accessing the intranet, the operating environment of the login terminal is detected in real time to obtain operating environment detection information; Analyze the runtime environment detection information based on the runtime environment detection conditions applied to the login terminal; Based on the analysis results of the runtime environment detection information, if it is determined that the runtime environment of the login terminal is abnormal, the corresponding runtime environment abnormality information is reported and the connection with the intranet is disconnected.
4. A method for remotely accessing an intranet, characterized in that, Applied to the verification end, the method includes: The user's biometric information sent by the security key device is decrypted, the biometric information is verified, and a first verification result is returned to the security key device; wherein, the security key device is connected to the login terminal; the security key device is used to perform a trust detection on the login terminal when the first verification result indicates that the biometric information verification is successful, and then encrypts and returns the trust detection result to the verification terminal. The trusted detection result sent by the security key device is decrypted to obtain the second verification result. If the second verification result indicates that the trusted detection result has been verified, a dynamic password is sent to the user's bound security terminal. The intranet login credential sent by the security key device is decrypted, the intranet login credential is verified to obtain a third verification result, and if the third verification result indicates that the intranet login credential verification is successful, the login terminal is connected to the intranet. The intranet login credentials are obtained by the security key device based on the device configuration information of the login terminal, the device serial number of the security key device, the biometric information, and the dynamic password entered by the user on the login terminal.
5. The method according to claim 4, characterized in that, The verification of the intranet login credentials to obtain a third verification result includes: Extract the device configuration information, device serial number, biometric information, and dynamic password from the decrypted intranet login credentials; Based on the device configuration information, device serial number, and biometric information, the user access account and access permissions are matched to obtain the matching result; The dynamic password is verified to obtain the password verification result; The third verification result is obtained based on the matching result and the password verification result.
6. The method according to claim 4, characterized in that, The method further includes: When it is determined from the available credentials of the security key device that the current time is not within the available time limit of the security key device, the security key device is set to a disabled state according to the device serial number of the security key device; If the deactivated state ends and the security key device is not reactivated, the security key device shall be deregistered according to its device serial number.
7. The method according to claim 6, characterized in that, The method further includes: Whenever the login terminal accesses the intranet, the availability period of the security key device is updated using the available credentials.
8. A device for remotely accessing an intranet, characterized in that, Applied to a security key device, the device includes: The feature acquisition module is used to acquire the user's biometric information, encrypt the biometric information, and send it to the verification terminal for verification. The trusted detection module is used to perform trusted detection on the login terminal when the biometric information verification is successful, obtain a trusted detection result, encrypt the trusted detection result and send it to the verification terminal for verification; the verification terminal is used to send a dynamic password to the user-bound security terminal when the trusted detection result is successful. The information acquisition module is used to acquire the device serial number of the security key device and the device configuration information of the login terminal; The credential generation module is used to generate intranet login credentials based on the device configuration information, the device serial number, the biometric information, and the dynamic password entered by the user on the login terminal. The intranet access module is used to encrypt and send the intranet login credentials to the verification terminal for verification. If the intranet login credentials are verified, the user can access the intranet.
9. A device for remotely accessing an intranet, characterized in that, The device, used at the verification end, includes: The first verification module is used to decrypt the user's biometric information sent by the security key device, verify the biometric information, and return a first verification result to the security key device; wherein, the security key device is connected to the login terminal; the security key device is used to perform a trust detection on the login terminal when the first verification result indicates that the biometric information has been verified, obtain a trust detection result, and encrypt and return it to the verification terminal; The second verification module is used to decrypt the trusted detection result sent by the security key device and verify the trusted detection result to obtain a second verification result. The password sending module is used to send a dynamic password to the user-bound security terminal when the second verification result indicates that the trusted detection result has been verified. The third verification module is used to decrypt the intranet login credential sent by the security key device, verify the intranet login credential to obtain a third verification result, and enable the login terminal to access the intranet if the third verification result indicates that the intranet login credential has been verified. The intranet login credentials are obtained by the security key device based on the device configuration information of the login terminal, the device serial number of the security key device, the biometric information, and the dynamic password entered by the user on the login terminal.
10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.
12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
System and method for authentication service
CN108989278A
Information verification method and system, storage medium and electronic equipment
CN115134165A