Method, system, apparatus and device for determining an office area to which a device belongs

By using the device identifier of network equipment during the network access authentication process, the problems of cumbersome and misidentification in the existing technology of office area identification are solved, and stable and efficient office area identification is achieved.

CN116390025BActive Publication Date: 2026-04-28ALIBABA CLOUD COMPUTING CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ALIBABA CLOUD COMPUTING CO LTD
Filing Date
2023-03-29
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

In existing technologies, methods for identifying the office area to which a user device belongs are cumbersome and prone to errors, especially in scenarios with multiple office areas where wireless network names and probe service port addresses are easily changed, leading to frequent misidentifications.

Method used

By utilizing the device identifiers of network devices, especially NAS devices, switches, and routers, during the network access authentication process, the office area to which the user's device belongs can be determined, thus leveraging the existing network access authentication process to achieve office area identification.

Benefits of technology

This reduces the need for manually configuring signage information for different office areas, improves the stability and processing efficiency of identification, and reduces development difficulty and the probability of misidentification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116390025B_ABST
    Figure CN116390025B_ABST
Patent Text Reader

Abstract

The embodiment of the present specification provides a method for determining the office area to which a device belongs, an access control method, a system, an apparatus and a device. The correspondence relationship between the device identifier of the network device and the office area range can be preconfigured. In the process of network authentication of the user device, the device identifier of the network device is sent to the server through the network device, so that the server determines the office area range to which the user device belongs based on the preconfigured correspondence relationship and the device identifier of the network device. Since the device identifier of the network device does not need to be manually configured by the user and will not change, misidentification can be reduced. Moreover, by realizing the identification of the office area range in the network authentication process, the development process can be reduced and the processing efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments in this specification relate to the field of computer technology, and in particular to a method, system, apparatus, and device for determining the office area to which a device belongs. Background Technology

[0002] In certain scenarios, different management or control policies are needed for user devices located in different office areas. For example, suppose a company has three different office areas in Beijing, Shanghai, and Guangzhou. Employees in different office areas have different access to internal company resources and files. Therefore, different access control policies need to be set for devices in the three office areas. The prerequisite for implementing differentiated management or control policies is accurately identifying the office area to which the device belongs. Currently, identifying the office area of ​​a user device usually involves setting different wireless network names or probe service port addresses for different office areas, and then determining the office area based on the wireless network name or probe service port address. These methods are cumbersome to manage wireless network names or probe service port addresses, especially in scenarios with many office areas. Furthermore, because wireless network names or probe service port addresses are prone to change, these methods are also prone to misidentification. Summary of the Invention

[0003] To overcome the problems existing in related technologies, embodiments of this specification provide a method, access control method, system, apparatus, and device for determining the office area to which a device belongs.

[0004] According to a first aspect of the embodiments of this specification, a method for determining the office area to which a device belongs is provided, applicable to a server, the method comprising:

[0005] During the network access authentication process for user equipment, an authentication request sent by a client on the user equipment through a network device is received. The authentication request carries the network access certificate of the user equipment and the device identifier of the network device. The device identifier of the network device is used to identify the office area to which the user equipment belongs.

[0006] The network access certificate is used to verify the network access rights of the user equipment; and,

[0007] Based on the pre-configured correspondence between the device identifier of the network device and the scope of the office area, and the device identifier of the network device carried in the authentication request, the scope of the office area to which the user device belongs is determined.

[0008] In some embodiments, the device identifier of the pre-configured network device includes the device identifier of the network control device and / or the device identifier of the network access point device, wherein the device identifier of the pre-configured network control device is used to identify the first office area range to which the user equipment belongs, and the device identifier of the pre-configured network access point device is used to identify the second office area range to which the user equipment belongs, the second office area range being a sub-range within the first office area range.

[0009] In some embodiments, the authentication request carries a device identifier of a network control device and a device identifier of a network access point device. Determining the office area to which the user equipment belongs based on a pre-configured correspondence between the device identifiers of the network devices and the office area range, and the device identifiers of the network devices carried in the authentication request, includes:

[0010] Based on the pre-configured correspondence between the device identifiers of network devices and the scope of office areas, and the device identifier of the network control device carried in the authentication request, the scope of the third office area is determined.

[0011] Based on the pre-configured correspondence between the device identifiers of network devices and the scope of office areas, and the device identifiers of network access point devices carried in the authentication request, the scope of the fourth office area is determined.

[0012] If the fourth office area is a sub-area of ​​the third office area, then the third office area or the fourth office area shall be taken as the office area to which the user equipment belongs.

[0013] If the fourth office area is not a sub-area of ​​the third office area, an error message will be issued.

[0014] In some embodiments, the network control device includes a NAS device, and the network access point device includes a router and / or a switch.

[0015] In some embodiments, the network access certificate carries the device identifier of the user equipment, and the method further includes:

[0016] Extract the device identifier of the user device from the network access certificate;

[0017] The device identifier of the user device is bound to the office area to which the user device belongs.

[0018] In some embodiments, the method further includes:

[0019] When a user logs into the client for the first time, the client sends a network access certificate request, which carries the device identifier of the user's device.

[0020] Generate a network access certificate containing the device identifier of the user device and return it to the client.

[0021] According to a second aspect of the embodiments of this specification, a method for determining the office area to which a device belongs is provided, applicable to a client installed on a user device, the method comprising:

[0022] During the network access authentication process for the user equipment, an authentication request is sent to the server through the network device, so that the server verifies the network access permission of the user equipment based on the network access certificate in the authentication request, and determines the office area to which the user equipment belongs based on the device identifier of the network device in the authentication request and the pre-configured correspondence between the device identifier of the network device and the office area range; wherein, the device identifier of the network device is used to identify the office area to which the user equipment belongs.

[0023] In some embodiments, the device identifier of the network device includes the device identifier of the network control device and / or the device identifier of the network access point device, wherein the device identifier of the network control device can be used to identify a first office area to which the user equipment belongs, and the device identifier of the network access point device can be used to identify a second office area to which the user equipment belongs, the second office area being a sub-area within the first office area.

[0024] According to a third aspect of the embodiments of this specification, an access control method is provided, applicable to a server, the method comprising:

[0025] Receive a resource access request sent by a client, the resource access request carrying the device identifier of the user device on which the client is installed;

[0026] Based on the binding relationship between the user device's device identifier and the office area range, the office area range to which the user device indicated by the device identifier carried in the resource access request belongs is determined, wherein the binding relationship is determined based on the method mentioned in the first aspect above.

[0027] The resource access requests are processed using an access control policy that matches the office area.

[0028] According to a fourth aspect of the embodiments of this specification, a Secure Access Service Edge (SASE) system is provided, including a SASE client and a SASE server, wherein the SASE server is used to perform the methods mentioned in the first or third aspect above, and the SASE client is used to perform the methods mentioned in the second aspect above.

[0029] According to a fifth aspect of the embodiments of this specification, an apparatus for determining the office area to which a device belongs is provided, suitable for a server, the apparatus comprising:

[0030] The receiving module is used to receive an authentication request sent by a client on the user equipment through a network device during the network access authentication process. The authentication request carries the network access certificate of the user equipment and the device identifier of the network device. The device identifier of the network device is used to identify the office area to which the user equipment belongs.

[0031] The processing module is used to verify the network access permission of the user device using the network access certificate; and to determine the office area to which the user device belongs based on the pre-configured correspondence between the device identifier of the network device and the office area range, and the device identifier of the network device carried in the authentication request.

[0032] According to a sixth aspect of the embodiments of this specification, an apparatus for determining the office area to which a device belongs is provided, applicable to a client installed on a user device, the apparatus comprising:

[0033] The sending module is used to send an authentication request to the server through the network device during the network access authentication process of the user equipment, so that the server can verify the network access permission of the user equipment based on the network access certificate in the authentication request, and determine the office area to which the user equipment belongs based on the device identifier of the network device in the authentication request and the pre-configured correspondence between the device identifier of the network device and the office area range; wherein, the device identifier of the network device is used to identify the office area to which the user equipment belongs.

[0034] According to a seventh aspect of the embodiments of this specification, an apparatus is provided, the apparatus including a processor, a memory, and a computer program stored in the memory and executable by the processor, wherein the computer program, when executed, implements the methods mentioned in the first aspect, the second aspect, and / or the third aspect above.

[0035] According to an eighth aspect of the embodiments of this specification, a computer storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the methods mentioned in the first, second, and / or third aspects above.

[0036] The beneficial effects of the embodiments in this specification are as follows: Considering that during the communication between the user equipment and the server through the client, the user equipment needs to connect to the server via network equipment in the office area. That is, network equipment located in the same office area as the user equipment can be used to identify the office area to which the user equipment belongs. Furthermore, since the device identifier of a network device is usually unique, it can be used as identification information to distinguish different office areas. This eliminates the need for users to manually configure different identification information for different office areas, thus avoiding deployment and management inconvenience. In addition, the device identifier of a network device usually does not change and is relatively stable, thereby reducing the probability of misidentification.

[0037] Furthermore, considering that based on some current network authentication protocols, during the network access authentication process for user devices, after the client sends an authentication request, the network device adds its own device identifier to the authentication request and sends it to the server to complete the network access authentication. Therefore, the device identifier of the network device sent to the server during the network access authentication process can be reused in the embodiments of this specification to achieve office area identification. That is, through the method provided in the embodiments of this specification, the existing network access authentication process can be used to complete the identification of office areas, without the need to add a new office area identification process, reducing changes to the software process. At the same time, it can complete both network access authentication and office area identification tasks in one process, achieving two goals at once, improving processing efficiency and reducing development difficulty.

[0038] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit the embodiments of this specification. Attached Figure Description

[0039] The accompanying drawings, which are incorporated in and form part of the embodiments of this specification, illustrate embodiments consistent with those of this specification and, together with the specification, serve to explain the principles of the embodiments of this specification.

[0040] Figure 1 This is a schematic diagram illustrating an application scenario as an exemplary embodiment of this specification;

[0041] Figure 2 A timing diagram illustrating a method for determining the office area to which a user device belongs, as shown in an exemplary embodiment of this specification;

[0042] Figure 3 This is a schematic diagram illustrating the correspondence between network devices and office area ranges as shown in an exemplary embodiment of this specification;

[0043] Figure 4 This is a schematic diagram illustrating secure access control for user equipment, as shown in an exemplary embodiment of this specification.

[0044] Figure 5 This is a schematic diagram illustrating an exemplary embodiment of the apparatus for determining the office area to which a user device belongs;

[0045] Figure 6 This is a schematic diagram illustrating an exemplary embodiment of the apparatus for determining the office area to which a user device belongs;

[0046] Figure 7 A logic block diagram of the device is shown for an exemplary embodiment of this specification. Detailed Implementation

[0047] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those described in this specification. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the embodiments described in this specification as detailed in the appended claims.

[0048] The terminology used in the embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the embodiments of this specification. The singular forms “a,” “described,” and “the” as used in the embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.

[0049] It should be understood that although the terms first, second, third, etc., may be used to describe various information in the embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first information may also be referred to as second information without departing from the scope of the embodiments of this specification, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."

[0050] In some scenarios, it's necessary to determine the office area to which a user's device belongs, and then implement management and control policies based on that area. Taking SASE (Secure Access Service Edge) as an example, different security control policies are typically set for different office areas. For instance, suppose a company has three different office areas in Beijing, Shanghai, and Guangzhou. Employees in different office areas have access to different internal company resources and files; therefore, different security control policies need to be set for devices in each of the three office areas. The prerequisite for implementing differentiated security control policies is accurately identifying the office area to which the device belongs.

[0051] Currently, there are two main methods for identifying the office area to which a user device belongs. One method is for users to pre-configure different SSID (Service Set Identifier) ​​names for wireless networks in different office areas. Clients can then identify the office area by recognizing the different SSID names. This method requires users to configure different wireless network names for different office areas, increasing the complexity of managing, deploying, and using wireless networks. Furthermore, if users subsequently modify the SSID names, it may lead to incorrect office area identification. In addition, if a potential risk arises, a user could easily bypass some security policies by creating a wireless network with the same name. This method is also unsuitable for wired network scenarios.

[0052] Another approach is for users to pre-deploy detection services with different IP addresses and ports in different office areas. Clients can use these detection services' IP addresses and ports to determine the office area to which the user's device belongs. While this approach is applicable to wired network scenarios, it increases the difficulty of managing and deploying detection services because it requires deploying different IP addresses and ports for different office areas. Furthermore, the stability of the detection services is uncertain, and if the detection services fail to function properly, it will cause errors in office area identification.

[0053] It is evident that current office area identification methods all require manually setting differentiated identification information for different office areas. As the number of office areas increases, the deployment and management of identification information becomes cumbersome. Furthermore, identification information such as SSID name and probe service port address are prone to change or instability, which can easily lead to errors in office area identification.

[0054] Based on this, this disclosure provides a method for determining the office area to which a device belongs. Considering that user devices need to connect to the server via network devices in the office area during communication between the client and server, network devices located in the same office area as the user device can be used to identify the office area to which the user device belongs. Furthermore, since network device identifiers are typically unique, they can be used to distinguish different office areas, eliminating the need for users to manually configure different identifiers for different office areas, thus avoiding deployment and management inconvenience. In addition, network device identifiers are usually stable and do not change, thereby reducing the probability of misidentification.

[0055] Furthermore, considering that based on some current network authentication protocols, during the network access authentication process for user devices, after the client sends an authentication request, the network device adds its own device identifier to the authentication request and sends it to the server to complete the network access authentication. Therefore, the device identifier of the network device sent to the server during the network access authentication process can be reused in the embodiments of this specification to achieve office area identification. That is, through the method provided in the embodiments of this specification, the existing network access authentication process can be used to complete the identification of office areas, without the need to add a new office area identification process, reducing changes to the software process. At the same time, it can complete both network access authentication and office area identification tasks in one process, achieving two goals at once, improving processing efficiency and reducing development difficulty.

[0056] The client and server in the embodiments of this specification can be clients and servers of some network security services. The network security services can be SASE services, or other services with similar functions.

[0057] For example, such as Figure 1 The diagram illustrates an application scenario of an embodiment of this specification. It demonstrates a scenario where SASE service is used for secure access control of user devices. For example, different security control policies can be set for user devices in different office areas (e.g., office area 1, office area 2). SASE clients can be installed on user devices in different office areas. The SASE client can send resource access requests to the SASE server. The SASE server can determine whether the user device has access to the resource based on the pre-set security control policy. If it does, the request is forwarded to an internal server to obtain the corresponding resource; otherwise, the access request is rejected.

[0058] The method for determining the office area to which a device belongs, as provided in the embodiments of this specification, can be completed through collaboration between the client and the server. The specific process is as follows: Figure 2 As shown:

[0059] S202. During the network access authentication process for the user equipment, the client sends an authentication request to the server through the network device. The authentication request carries the network access certificate of the user equipment and the device identifier of the network device. The device identifier of the network device is used to identify the office area to which the user equipment belongs.

[0060] Generally, to ensure the security of internal resources, schools, companies, and other organizations require user devices to establish a connection with the organization's internal network and obtain network access before accessing internal resources. This network access is obtained through a network authentication process. During authentication, the client installed on the user device sends an authentication request to the server through network devices (such as routers and switches). This authentication request can carry the user device's network access certificate, allowing the server to determine whether the user device has network access rights. Furthermore, based on current network authentication protocols, such as the RADIUS protocol, the network device automatically adds attributes such as its device identifier to the authentication request sent by the client, and then forwards it to the server along with the network access certificate. Therefore, the final authentication request sent by the client to the server through the network device can carry the network device's device identifier.

[0061] Network devices can be any equipment required for user devices to access the internet, such as NAS (Network Attached Storage) devices, switches, and routers. Since the network devices used by user devices to access the internet are usually deployed in the same area as the user devices—for example, within the same campus, building, or floor—the network devices can be used to identify the office area to which the user devices belong.

[0062] A network device's identifier can be information that uniquely identifies the device, such as the network device's MAC address, or it can be an identifier obtained by combining the network device's MAC address with other information. Since different network devices generally have different identifiers, users do not need to manually make differentiated settings for different office areas. Moreover, network device identifiers usually do not change and are relatively stable, thus reducing the problem of misidentification due to changes in network identifiers.

[0063] S204. The server receives the authentication request sent by the client;

[0064] In step S204, the server may receive authentication requests forwarded by the client through network devices.

[0065] S206. The server obtains the network access certificate from the authentication request and authenticates the network access permission of the user device based on the network access certificate;

[0066] In step S206, after receiving the authentication request, the server can obtain the network access certificate from the authentication request and verify the network access permission of the user device based on the network access certificate.

[0067] S208. The server can obtain the device identifier of the network device from the authentication request, and determine the office area range to which the user device belongs based on the pre-configured correspondence between the device identifier of the network device and the office area range, as well as the device identifier of the network device currently obtained.

[0068] In step S208, the user can pre-configure the correspondence between different network device identifiers and office area ranges. The size of the office area range corresponding to each network device can be determined based on the distribution range of user devices managed by that network device. For example, suppose a company has three office areas in Guangzhou, Shanghai, and Beijing, and the three office areas are connected to the Internet through switches 1, 2, and 3 respectively. Therefore, a correspondence can be established between the device identifiers of the switches and the office area ranges, such as: switch 1 - Guangzhou, switch 2 - Shanghai, switch 3 - Beijing. For example, suppose the Guangzhou office area has three floors, and the user devices on the three floors are equipped with three switches: switch A, switch B, and switch C. Then, a correspondence can be established between the identifiers of the three switches and the three floors: switch A - floor 1, switch B - floor 2, switch 3 - floor 3. That is, the correspondence between network devices and office area ranges can be configured based on the deployment of network devices in the office area.

[0069] When the server receives an authentication request, it can obtain the device identifier of the network device. Based on the above correspondence and the device identifier of the network device obtained, it can determine the office area to which the user device belongs.

[0070] The execution order of steps S206 and S208 is not limited; step S206 can be executed first, step S208 can be executed first, or both can be executed simultaneously.

[0071] In some embodiments, such as Figure 3As shown, when configuring the correspondence between the device identifier of a network device and the scope of an office area, the device identifier of the network device may include the device identifier of a network control device and / or the device identifier of a network access point device. The device identifier of the network control device is used to identify the first scope of the office area where the user device is located, and the device identifier of the network access point device is used to identify the second scope of the office area where the user device is located. The second scope of the office area is a sub-scope of the first scope of the office area.

[0072] Considering that the required precision of defining the office area varies depending on the scenario, the type of network device used to identify the office area can be selected based on the required precision. For example, network control devices (such as NAS devices) typically cover a large office area, and one device can be deployed for an entire campus; therefore, network control devices can be used to identify the entire campus. On the other hand, network access point devices (such as switches and routers) typically need to be deployed in each building or on each floor within the campus; therefore, network access point devices can be used to identify a smaller office area, such as a building or a floor.

[0073] Therefore, if a unified control or management strategy is required for devices within the same campus when controlling or managing user equipment, network control devices can be used to define the scope of office areas by using the device identifiers of network devices. Conversely, if different control or management strategies are required for devices in different buildings or floors within the same campus, network access point devices can be used to define the scope of office areas by using the device identifiers of network devices.

[0074] Of course, in some scenarios, considering that determining the office area using the device identifier of network devices may lead to misidentification, to ensure a more accurate determination of the office area, the pre-set device identifiers of network devices can include both the device identifiers of network control devices and network access point devices. Upon receiving an authentication request, if the authentication request also includes these two types of device identifiers, two office area ranges can be determined based on these identifiers respectively. These two determined office area ranges are then matched to verify their accuracy. For example, if the fourth office area range determined based on the network access point device identifier is a sub-range of the third office area range determined based on the network control device identifier, it indicates that the two determined office area ranges are relatively accurate, and one of them can be used as the office area to which the user equipment belongs, depending on the requirements. If the fourth office area range determined based on the network access point device identifier is not a sub-range of the third office area range determined based on the network control device identifier, then one of the determined office area ranges may be incorrect, or both may be incorrect. In this case, an error message can be issued.

[0075] For example, suppose a company comprises two campuses, each with two buildings, and each building requires different management and control strategies for its equipment. Each campus has one NAS device, and each building in each campus has one switch. Therefore, the following mapping relationship can be established between network device identifiers and office area ranges:

[0076] NAS device 1 - Campus 1, NAS device 2 - Campus 2

[0077] Switch 1 - Building A, Campus 1; Switch 2 - Building B, Campus 1; Switch 3 - Building C, Campus 2; Switch 4 - Building D, Campus 2.

[0078] Upon receiving an authentication request from a user device, assuming the network device identifiers obtained from the authentication request are the identifiers of NAS device 1 and switch 1, the office area can be determined to be either Campus 1 or Building A. In this case, the two determined office area ranges match, meaning Building A is a building within Campus 1. Conversely, if the determined building is not within Campus 1, one of the two might be incorrect, and an error message can be issued.

[0079] In some embodiments, the network control device includes a NAS device, and the network access point device includes a switch and / or a router. Of course, other devices with similar functions may also be included, and this specification does not limit them.

[0080] In some embodiments, considering that the network access authentication process is only performed when the client first connects to the intranet, and that this process is not required when the client accesses resources on the intranet after connection, subsequent access requests typically only carry the user device's device identifier, not the network device's identifier, the following steps are taken to facilitate processing subsequent access requests from the user device based on its office area. After determining the scope of the user device's office area, the device identifier can be extracted from the network access certificate and bound to the scope of the user device's office area. This allows the server to directly determine the scope of the user device's office area based on the device identifier in the access request and the binding relationship when receiving resource access requests from the user device, and then perform access control on the user device based on that scope.

[0081] In some embodiments, to obtain a network access certificate for a user device, the client can automatically send a network access certificate request to the server upon the user's first login to the client installed on the user device. This request may include the device identifier of the user device. Upon receiving the network access certificate request, the server can generate a network access certificate containing the device identifier and issue the certificate to the client. Subsequently, before accessing internal resources through the server, the client can send this network access certificate to the server to complete network access authentication.

[0082] Furthermore, this specification also provides an access control method for controlling access to user devices located in different office areas. This method can be applied to a server, such as a SASE server. During the network access authentication process for a user device, the server first determines the office area to which the user device belongs based on the device identifier of the network device carried in the authentication request and the pre-configured correspondence between the device identifier of the network device and the office area. Then, the server binds the device identifier of the user device to the office area. Subsequently, upon receiving a resource access request sent by the user device through a client, the server can directly determine the office area to which the user device belongs based on the binding relationship between the device identifier of the user device and the office area, and then process the access request based on the office area.

[0083] Specifically, the method may include the following steps:

[0084] Step S402: Receive a resource access request sent by the client, wherein the resource access request carries the device identifier of the user device on which the client is installed;

[0085] In step S402, after the user equipment completes network access authentication and obtains network access permission, the server can receive resource access requests sent by the client installed on the user equipment. The resource access requests carry the device identifier of the user equipment.

[0086] Step S404: Based on the binding relationship between the user device's device identifier and the office area range, determine the office area range to which the user device indicated by the device identifier carried in the resource access request belongs, wherein the binding relationship is determined based on the method described in any of the above embodiments.

[0087] In step S404, the server can determine the office area to which the user device indicated by the device identifier carried in the resource access request belongs based on the binding relationship between the user device's device identifier and the office area range.

[0088] The binding relationship between the user device's device identifier and the office area range can be determined based on the method described in the above embodiments, and will not be repeated here.

[0089] Step S406: Process the resource access request using the access control policy that matches the determined office area.

[0090] In step S406, after determining the office area to which the current user device belongs, the resource access request can be processed using an access control policy that matches the determined office area. For example, the resource access request can be forwarded to an internal server, or the resource access request can be rejected.

[0091] Furthermore, this specification also provides a SASE system, including a SASE client and a SASE server. The SASE server is used to execute the method and / or access control method executed by the server in any of the above embodiments for determining the office area to which a device belongs. The SASE client is used to execute the method and / or access control method executed by the client in any of the above embodiments for determining the office area to which a device belongs.

[0092] The specific details of the methods and / or access control methods implemented by the SASE client and SASE server to determine the office area to which the device belongs are described in the above embodiments and will not be repeated here.

[0093] To further explain the methods and systems provided in the embodiments of this specification, the following explanation is given in conjunction with a specific embodiment. For example... Figure 4 The diagram illustrates a method for secure access control of user devices located in different office areas using the SASE service, specifically including the following steps:

[0094] Step S502: When a user logs in to the SASE client installed on the user's device for the first time, the SASE client automatically sends a network access certificate request to the SASE server. The network access certificate request carries the device identifier of the user's device.

[0095] After receiving the network access certificate request, the S504 and SASE servers generate a network access certificate containing the device identifier of the user device and return it to the SASE client.

[0096] S506 When a user equipment needs to access internal resources, it can send a network access authentication request to the network device through the SASE client. The authentication request includes the network access certificate.

[0097] S508: The network device adds the device identifier of the NAS device and the device identifier of the switch or router to the authentication request, and then sends the authentication request to the SASE server. The authentication request includes the network access certificate, the device identifier of the NAS device, and the device identifier of the switch or router.

[0098] The S510 and SASE servers authenticate the network access permissions of user devices based on the network access certificate.

[0099] The S512 and SASE servers determine the office area to which the user's device belongs based on the pre-configured correspondence between the device identifier of the NAS device, the device identifier of the switch or router, and the office area range.

[0100] The S514 and SASE servers extract the device identifier of the user device from the network access certificate, bind it to the office area range to which the user device belongs, and obtain the binding relationship.

[0101] The S516 and SASE clients send resource access requests to the SASE server, and the resource access requests carry the device identifier of the user device.

[0102] The S518 and SASE servers determine the office area range to which the user device belongs based on the binding relationship and the device identifier of the currently received user device, and process resource access requests using security control policies corresponding to the office area range.

[0103] Corresponding to the method embodiment for determining the office area to which a device belongs provided in the embodiments of this specification, the embodiments of this specification also provide an apparatus for determining the office area to which a device belongs, applicable to the server side, such as... Figure 5 As shown, the device 50 includes:

[0104] The receiving module 52 is used to receive an authentication request sent by a client on the user equipment through a network device during the network access authentication process of the user equipment. The authentication request carries the network access certificate of the user equipment and the device identifier of the network device. The device identifier of the network device is used to identify the office area range to which the user equipment belongs.

[0105] Processing module 54 is used to verify the network access permission of the user equipment using the network access certificate; and to determine the office area range to which the user equipment belongs based on the pre-configured correspondence between the device identifier of the network device and the office area range, and the device identifier of the network device carried in the authentication request.

[0106] Corresponding to the method embodiment for determining the office area to which a device belongs provided in the embodiments of this specification, the embodiments of this specification also provide an apparatus for determining the office area to which a device belongs, applicable to client devices, applicable to client devices installed on user devices, such as... Figure 6 As shown, the device 60 includes:

[0107] The sending module 62 is used to send an authentication request to the server through the network device during the network access authentication process of the user equipment, so that the server verifies the network access permission of the user equipment based on the network access certificate in the authentication request, and determines the office area to which the user equipment belongs based on the device identifier of the network device in the authentication request and the pre-configured correspondence between the device identifier of the network device and the office area range; wherein, the device identifier of the network device can be used to identify the office area to which the user equipment belongs.

[0108] The specific implementation process of the functions and roles of each unit in the above-mentioned device can be found in the implementation process of the corresponding steps in the method for determining the office area to which the equipment belongs, and will not be repeated here.

[0109] For the apparatus embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The apparatus embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the embodiments in this specification, depending on actual needs. Those skilled in the art can understand and implement this without creative effort.

[0110] From a hardware perspective, such as Figure 7The diagram shown is a hardware structure diagram of a device for determining the office area to which the device belongs, according to an embodiment of this specification. Except for... Figure 7 In addition to the processor 72 and memory 74 shown, the device may also include other hardware, such as a forwarding chip responsible for processing messages; from a hardware structure perspective, the device may also be a distributed device, possibly including multiple interface cards to extend message processing at the hardware level. The memory 74 stores computer instructions, and when the processor 72 executes the computer instructions, it implements the methods mentioned in any of the above embodiments.

[0111] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0112] Since the parts of the embodiments in this specification that contribute to the prior art, or all or part of the technical solution, can be embodied in the form of a software product, the computer software product is stored in a storage medium and includes several instructions to cause a terminal device to execute all or part of the steps of the methods in the various embodiments of this specification. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0113] The above description is merely a preferred embodiment of the embodiments of this specification and is not intended to limit the embodiments of this specification. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of this specification should be included within the scope of protection of the embodiments of this specification.

Claims

1. A method for determining the office area to which a device belongs, applicable to a server, the method comprising: During the network access authentication process for user equipment, an authentication request sent by a client on the user equipment through a network device is received. The authentication request carries the network access certificate of the user equipment and the device identifier of the network device. The device identifier of the network device is used to identify the office area range to which the user equipment belongs. The device identifier of the network device carried in the authentication request is added to the authentication request by the network device after receiving the authentication request. The network access certificate is used to verify the network access rights of the user equipment; and, Based on the pre-configured correspondence between network device identifiers and office area ranges, and the network device identifiers carried in the authentication request, the office area range to which the user device belongs is determined, so as to perform access control on the user device based on the office area range of the user device. The size of the office area range corresponding to each network device is determined based on the distribution range of the user devices under the jurisdiction of that network device.

2. The method according to claim 1, wherein the device identifier of the pre-configured network device includes the device identifier of the network control device and / or the device identifier of the network access point device, wherein, The device identifier of the pre-configured network control device is used to identify the first office area range to which the user equipment belongs, and the device identifier of the pre-configured network access point device is used to identify the second office area range to which the user equipment belongs, wherein the second office area range is a sub-range within the first office area range.

3. The method according to claim 2, wherein the authentication request carries a device identifier of the network control device and a device identifier of the network access point device, and the step of determining the office area to which the user equipment belongs based on the pre-configured correspondence between the device identifiers of the network devices and the office area range, and the device identifiers of the network devices carried in the authentication request, includes: Based on the pre-configured correspondence between the device identifiers of network devices and the scope of office areas, and the device identifier of the network control device carried in the authentication request, the scope of the third office area is determined. Based on the pre-configured correspondence between the device identifiers of network devices and the scope of office areas, and the device identifiers of network access point devices carried in the authentication request, the scope of the fourth office area is determined. If the fourth office area is a sub-area of ​​the third office area, then the third office area or the fourth office area shall be taken as the office area to which the user equipment belongs. If the fourth office area is not a sub-area of ​​the third office area, an error message will be issued.

4. The method according to claim 2 or 3, wherein the network control device includes a NAS device, and the network access point device includes a router and / or a switch.

5. The method according to any one of claims 1-3, wherein the network access certificate carries the device identifier of the user equipment, and the method further comprises: Extract the device identifier of the user device from the network access certificate; The device identifier of the user device is bound to the office area to which the user device belongs.

6. The method according to claim 5, further comprising: When a user logs into the client for the first time, the client sends a network access certificate request, which carries the device identifier of the user's device. Generate a network access certificate containing the device identifier of the user device and return it to the client.

7. A method for determining the office area to which a device belongs, applicable to a client installed on a user device, the method comprising: During the network access authentication process for the user equipment, the network device sends an authentication request to the server. The server verifies the user equipment's network access permissions based on the network access certificate in the authentication request. Furthermore, based on the network device's device identifier in the authentication request and a pre-configured correspondence between the network device's device identifier and the office area range, the server determines the office area range to which the user equipment belongs. Access control for the user equipment is then performed based on this office area range. The network device's device identifier identifies the office area range to which the user equipment belongs. The size of the office area range corresponding to each network device is determined based on the distribution range of the user equipment under its jurisdiction. The network device's device identifier carried in the authentication request is added to the authentication request by the network device upon receiving it.

8. The method according to claim 7, wherein the device identifier of the network device includes the device identifier of the network control device and / or the device identifier of the network access point device, wherein, The device identifier of the network control device can be used to identify the first office area to which the user equipment belongs, and the device identifier of the network access point device can be used to identify the second office area to which the user equipment belongs, wherein the second office area is a sub-area within the first office area.

9. An access control method, applicable to a server, the method comprising: Receive a resource access request sent by a client, the resource access request carrying the device identifier of the user device on which the client is installed; Based on the binding relationship between the device identifier of the user device and the scope of the office area, the scope of the office area to which the user device indicated by the device identifier carried in the resource access request belongs is determined, wherein the binding relationship is determined based on the method of claim 5 or 6. The resource access requests are processed using the access control policy corresponding to the defined office area.

10. A Secure Access Service Edge (SASE) system, comprising a SASE client and a SASE server, wherein the SASE server is used to execute the method described in any one of claims 1-6 and 9, and the SASE client is used to execute the method described in any one of claims 7-8.

11. An apparatus for determining the office area to which a device belongs, suitable for a server, the apparatus comprising: The receiving module is used to receive an authentication request sent by a client on the user equipment through a network device during the network access authentication process. The authentication request carries the network access certificate of the user equipment and the device identifier of the network device. The device identifier of the network device is used to identify the office area range to which the user equipment belongs. The device identifier of the network device carried in the authentication request is added to the authentication request by the network device after receiving the authentication request. The processing module is used to verify the network access permission of the user device using the network access certificate; and to determine the office area range to which the user device belongs based on the pre-configured correspondence between the device identifier of the network device and the office area range, and the device identifier of the network device carried in the authentication request, so as to perform access control on the user device based on the office area range of the user device, wherein the size of the office area range corresponding to each network device is determined based on the distribution range of the user devices under the jurisdiction of the network device.

12. An apparatus for determining the office area to which a device belongs, applicable to a client installed on a user device, the apparatus comprising: The sending module is used to send an authentication request to the server through a network device during the network access authentication process of the user equipment. This allows the server to verify the user equipment's network access permissions based on the network access certificate in the authentication request, and to determine the office area to which the user equipment belongs based on the network device's device identifier in the authentication request and a pre-configured correspondence between the network device's device identifier and the office area range. Access control for the user equipment is then performed based on the office area range defined by the network device. The network device's device identifier identifies the office area to which the user equipment belongs. The size of the office area range corresponding to each network device is determined based on the distribution range of the user equipment under its jurisdiction. The network device's device identifier carried in the authentication request is added to the authentication request by the network device upon receiving it.

13. An apparatus comprising a processor, a memory, and a computer program stored in the memory executable by the processor, the processor being configured to perform the method according to any one of claims 1-6, 9, or 7-8.

14. A computer storage medium storing a computer program that, when executed by a processor, implements the method described in any one of claims 1-6, 9, or 7-8.

Citation Information

Patent Citations

  • Realizing method for positioning user terminal and related equipment

    CN101860791A

  • Method, apparatus and system for making access control strategy

    CN106411878A

  • Terminal admission control method, devcie, apparatus, system, and storage medium

    CN109067937A

  • Network access request processing method and device, server and medium

    CN115150831A