Multi-level access control method, module, medium and system

By using multi-level access control methods and modules, the system receives terminal authentication information and performs customized authentication and authorization, solving the problem of the lack of independent and controllable strategies in AAA authentication. This enables secure and controllable terminal access, adapting to the security needs of different vertical industries.

CN116566713BActive Publication Date: 2026-04-17CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA UNITED NETWORK COMM GRP CO LTD
Filing Date
2023-05-29
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

The existing AAA authentication technology lacks an independent and controllable access control strategy and cannot be customized according to the needs of vertical industries, resulting in insufficient security for terminal access in enterprise campuses.

Method used

Through multi-level access control methods and modules, the system receives multi-level access authentication information from terminals, authenticates terminal login methods and access permissions, formulates access authorization and audit logging modes based on authentication results, and controls the secure access of terminals to the data network.

Benefits of technology

It implements customized access control policies based on the needs of vertical industries, improving the security and controllability of terminal access in enterprise campuses and meeting the security needs of different users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116566713B_ABST
    Figure CN116566713B_ABST
Patent Text Reader

Abstract

This invention provides a multi-level access control method, module, medium, and system, relating to the field of communication technology. It addresses the problem in existing AAA authentication systems that lack autonomously controllable access control policies configured by the AAA system. The method includes: receiving terminal multi-level access authentication information from a standard AAA module of a customized AAA system; performing multi-level access mode authentication on the terminal based on the terminal's multi-level access authentication information, including: terminal login method authentication and terminal access permission authentication; authorizing access to the terminal and entering audit log mode based on the result of the multi-level access mode authentication; and controlling the terminal to access the data network according to the access authorization and in audit log mode. This invention enables the AAA system to formulate autonomously controllable access control policies for terminal access to the data network, allowing the terminal to securely access the data network according to the access control policies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and in particular to a multi-level access control method, a multi-level access control module, a standard AAA module, a computer-readable storage medium, and a customized AAA system. Background Technology

[0002] Currently, the standard for secondary authentication mainly adopts the 3GPP (3rd Generation Partnership Project) standard: when the user initiates a PDU (Protocol Data Unit) establishment request, a third-party DN (Data Network)-AAA (Authentication, Authorization) method is used.

[0003] The Accounting (verification, authorization, and accounting) server authenticates and authorizes user PDU creation requests.

[0004] Therefore, existing technologies are limited to standard AAA authentication. As enterprises evolve towards digitalization and intelligence, there is a lack of customized development for how terminals can securely access enterprise campuses based on the needs of vertical industries, and there is a lack of access control policies that can be allocated by the AAA system and are autonomously controllable. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the prior art by providing a multi-level access control method, a multi-level access control module, a standard AAA module, a computer-readable storage medium, and a customized AAA system, so as to solve the problem that the AAA authentication in the prior art lacks an access control strategy that is allocated by the AAA system and is autonomously controllable.

[0006] In a first aspect, the present invention provides a multi-level access control method applied to a multi-level access control module of a customized authentication, authorization, and accounting (AAA) system, the method comprising:

[0007] Receive terminal multi-level access authentication information from the standard AAA module of the customized AAA system;

[0008] The terminal performs multi-level access mode authentication based on the terminal's multi-level access authentication information, including: terminal login method authentication and terminal access permission authentication;

[0009] Based on the results of the multi-level access mode authentication, the terminal is authorized to access and enters the audit log mode;

[0010] The control terminal accesses the data network based on access authorization and in audit log mode.

[0011] Optionally, the terminal login method authentication is specifically terminal single sign-on authentication;

[0012] Terminal access permission authentication specifically includes: terminal identifier access permission authentication, terminal login time access permission authentication, and / or terminal login address access permission authentication.

[0013] Optionally, the terminal multi-level access authentication information includes the Extensible Authentication Protocol (EAP) response data packet and the terminal identifier;

[0014] The terminal performs multi-level access mode authentication based on the terminal's multi-level access authentication information, specifically including:

[0015] Obtain the vertical industry to which the terminal belongs;

[0016] The terminal's single sign-on method is obtained from the EAP-Response data packet, and the single sign-on method of the terminal is authenticated according to the single sign-on method customized for the vertical industry.

[0017] Access permissions for terminals are authenticated by comparing terminal identifiers with the terminal whitelists established by vertical industries.

[0018] Optionally, access permissions for the terminal can be authenticated by comparing the terminal identifier with a terminal whitelist defined by the vertical industry, specifically including:

[0019] Obtain the terminal's login time and login address based on the EAP-Response data packet;

[0020] Obtain the fixed terminal whitelist defined by the vertical industry, the time-segment terminal whitelist corresponding to the login time, and the regional terminal whitelist corresponding to the login address;

[0021] If the terminal is identified in the fixed terminal whitelist, time-based terminal whitelist, or regional terminal whitelist, the terminal will pass access permission authentication; otherwise, the terminal will not pass access permission authentication.

[0022] Optionally, based on the result of multi-level access mode authentication, the terminal is authorized to access and enters audit logging mode, specifically including:

[0023] If the terminal is authenticated through multi-level access mode, an authorized traffic range is allocated to the terminal according to the terminal access mode, and the terminal is put into audit logging mode to audit and log the terminal's access to data network information.

[0024] Optionally, after authorizing access to the terminal and entering audit log mode based on the result of multi-level access mode authentication, the method further includes:

[0025] Send a terminal login authentication identifier to the standard AAA module so that the standard AAA module allows the terminal to access the data network based on the terminal login authentication identifier.

[0026] Secondly, this invention provides a multi-level access control method applied to the standard AAA module of a customized authentication, authorization, and accounting AAA system, the method comprising:

[0027] The terminal multi-level access authentication information is sent to the multi-level access control module of the customized AAA system so that the multi-level access control module can perform multi-level access mode authentication on the terminal based on the received terminal multi-level access authentication information, including terminal login method authentication and terminal access permission authentication. Based on the result of the multi-level access mode authentication, the module can authorize the terminal to access the data network and enter the audit log mode. The terminal can then access the data network according to the access authorization and in the audit log mode.

[0028] Optionally, terminal multi-level access authentication information is sent to the multi-level access control module, specifically including:

[0029] Receive terminal secondary authentication request from the Session Management Function (SMF) network element. The terminal secondary authentication request is sent by the SMF network element based on the access data network request from the terminal, and carries the terminal identifier.

[0030] Based on the terminal's secondary authentication request, send an Extensible Authentication Protocol Request (EAP-Request) data packet to the terminal;

[0031] Receive the Extensible Authentication Protocol (EAP) response data packet from the terminal. The EAP-Response data packet is sent by the terminal according to the EAP-Request data packet, and carries the terminal's single sign-on method, terminal login time, and terminal login address.

[0032] Send terminal multi-level access authentication information, including EAP-Response data packets and terminal identifier, to the multi-level access control module.

[0033] Optionally, after sending the terminal multilevel access authentication information to the multilevel access control module, the method further includes:

[0034] It receives a terminal login authentication identifier from the multi-level access control module and allows the terminal to access the data network based on the terminal login authentication identifier.

[0035] Thirdly, the present invention provides a multi-level access control module for a customized authentication and authorization accounting (AAA) system, comprising:

[0036] The first receiving unit is used to receive terminal multi-level access authentication information from the standard AAA module of the customized AAA system;

[0037] A multi-level authentication unit, connected to the first receiving unit, is used to perform multi-level access mode authentication on the terminal based on the terminal's multi-level access authentication information, including: terminal login method authentication and terminal access permission authentication.

[0038] The authorization audit unit, connected to the multi-level authentication unit, is used to authorize access to the terminal and enter the audit log mode based on the result of the multi-level access mode authentication.

[0039] The control unit, connected to the authorized audit unit, is used to control the terminal to access the data network according to the access authorization and in audit log mode.

[0040] Fourthly, the present invention provides a standard AAA module for a customized authentication and authorization accounting AAA system, comprising:

[0041] The authentication activation unit is used to send terminal multi-level access authentication information to the multi-level access control module of the customized AAA system, so that the multi-level access control module can perform multi-level access mode authentication on the terminal based on the received terminal multi-level access authentication information, including terminal login method authentication and terminal access permission authentication, and authorize the terminal to access and enter the audit log mode based on the result of the multi-level access mode authentication, and control the terminal to access the data network according to the access authorization and in the audit log mode.

[0042] Fifthly, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, it implements the multi-level access control method as described above.

[0043] Sixthly, the present invention provides a customized authentication and authorization accounting AAA system, comprising:

[0044] The multi-level access control module is used to execute the multi-level access control method described above.

[0045] The standard AAA module, connected to the multi-level access control module, is used to execute the multi-level access control method described above.

[0046] This invention provides a multi-level access control method, a multi-level access control module, a standard AAA module, a computer-readable storage medium, and a customized AAA system. The multi-level access control module of the customized AAA system receives terminal multi-level access authentication information from the standard AAA module of the customized AAA system. Based on the terminal multi-level access authentication information, it performs multi-level access mode authentication on the terminal, including terminal login method authentication and terminal access permission authentication. Based on the results of the multi-level access mode authentication, it formulates access control policies including access authorization and audit log modes, controlling the terminal to securely access the data network according to the access control policies. This enables the AAA system to formulate autonomous and controllable access control policies for terminal access to the data network, allowing terminals to securely access enterprise campuses and other scenarios according to the access control policies. Attached Figure Description

[0047] Figure 1 This is a flowchart of a multi-level access control method according to an embodiment of the present invention;

[0048] Figure 2 This is an interaction diagram of a multi-level access control method according to an embodiment of the present invention;

[0049] Figure 3 This is a flowchart of another multi-level access control method in an embodiment of the present invention;

[0050] Figure 4 This is a flowchart of another multi-level access control method in an embodiment of the present invention;

[0051] Figure 5 This is a schematic diagram of the structure of a multi-level access control module in an embodiment of the present invention;

[0052] Figure 6 This is a schematic diagram of the structure of a standard AAA module in an embodiment of the present invention. Detailed Implementation

[0053] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0054] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.

[0055] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.

[0056] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.

[0057] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.

[0058] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.

[0059] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of this invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.

[0060] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.

[0061] Example 1:

[0062] like Figure 1-3 As shown, Embodiment 1 of the present invention provides a multi-level access control method, which can be applied to, for example... Figure 2 The multi-level access control module of the customized authentication and authorization accounting AAA system shown herein, the method of which includes at least the following: Figure 1 The steps shown are as follows:

[0063] S11. Receive terminal multi-level access authentication information from the standard AAA module of the customized AAA system;

[0064] S12. Perform multi-level access mode authentication on the terminal based on the terminal multi-level access authentication information, including: terminal login method authentication and terminal access permission authentication;

[0065] S13. Based on the results of the multi-level access mode authentication, authorize the terminal to access and enter the audit log mode;

[0066] S14. The control terminal accesses the data network according to the access authorization and in audit log mode.

[0067] Specifically, in this embodiment, the customized AAA system adds a multi-level access control module to the standard AAA module. This allows the standard AAA module to perform standard AAA authentication first, followed by customized AAA authentication via the multi-level access control module. For terminals with different security protection levels, the standard AAA module forwards the terminal's multi-level access authentication information to the corresponding multi-level access control module based on the terminal identifier, thus meeting the security needs of different user terminals and enabling access control for terminals accessing the data service network. The customized AAA authentication process involves the customized AAA system's multi-level access control module receiving terminal multi-level access authentication information from the standard AAA module. Based on this information, the module performs multi-level access mode authentication on the terminal, including terminal login method authentication and terminal access permission authentication. Based on the results of the multi-level access mode authentication, it formulates access control policies including access authorization and audit log modes, controlling the terminal to securely access the data network according to the access control policies. This allows the AAA system to formulate autonomous and controllable access control policies for terminal access to the data network, enabling terminals to securely access scenarios such as enterprise parks according to these policies. It should be noted that the standard AAA module and the multi-level access control module can be configured on the same server or on different servers. They can be a dedicated device or a functional module of a multi-functional device; maintaining a communication connection between them is sufficient. To establish this communication connection, the following steps must be executed first. Figure 2 The steps 1a-1d shown are as follows: 1a. The standard AAA module initiates an access request to the multi-level access control module; 1b. The multi-level access control module confirms the access request; 1c. The standard AAA module sends an authentication and authorization request to the multi-level access control module; 1d. After completing the authentication and authorization of the standard AAA module, the multi-level access control module sends authentication and authorization information to the standard AAA module. Steps 1a-1d should be completed before step 3a, but there is no order restriction between them and steps 2a-2d.

[0068] Optionally, the terminal login method authentication is specifically terminal single sign-on authentication;

[0069] Terminal access permission authentication specifically includes: terminal identifier access permission authentication, terminal login time access permission authentication, and / or terminal login address access permission authentication.

[0070] Specifically, in this embodiment, multi-level access mode authentication includes, for example, the following: Figure 3 The steps shown are: S004 terminal login method authentication, S006 terminal identifier authentication, S007 terminal login time authentication, and S008 terminal login address authentication. Specifically, step S004 is terminal single sign-on authentication.

[0071] Optionally, the terminal multi-level access authentication information includes the Extensible Authentication Protocol (EAP) response data packet and the terminal identifier;

[0072] The terminal performs multi-level access mode authentication based on the terminal's multi-level access authentication information, specifically including:

[0073] Obtain the vertical industry to which the terminal belongs;

[0074] The terminal's single sign-on method is obtained from the EAP-Response data packet, and the single sign-on method of the terminal is authenticated according to the single sign-on method customized for the vertical industry.

[0075] Access permissions for terminals are authenticated by comparing terminal identifiers with the terminal whitelists established by vertical industries.

[0076] Specifically, in this embodiment, the access control policy can be customized and developed by the vertical industry according to its own needs, and the multi-level authentication process can include, for example... Figure 3 The following steps are shown:

[0077] S001, the standard AAA module receives the authentication request, specifically by... Figure 2 In step 2a, the UE (User Equipment) sends an access data network request to the 5G (5th Generation Mobile Communication Technology) core network. In step 2b, the SMF (Session Management Function) of the 5G core network sends a terminal secondary authentication request to the standard AAA module based on the access data network request. After the 5G core network completes the primary authentication and authorization of the terminal, when establishing a user plane data channel for the terminal, the SMF will decide whether to initiate secondary authentication with the standard AAA module based on the terminal's subscription information, including sending the terminal identifier, which may specifically be the terminal serial number.

[0078] S002, The standard AAA module sends an authentication request. Specifically, after receiving the terminal's secondary authentication request, the standard AAA module executes... Figure 2In step 2c, the standard AAA module sends an EAP (Extensible Authentication Protocol)-Request data packet to the UE; step 2c, the standard AAA module receives an EAP-Response data packet returned by the UE based on the EAP-Request data packet; and step 3a, the standard AAA module sends multi-level authentication information of the terminal to the multi-level access control module based on the EAP-Response data packet. The standard AAA module defines the EAP-Request data packet according to the access mode parameters to be authenticated as needed, thereby carrying the access mode parameters in the EAP-Response data packet, and enabling the multi-level access control module to perform multi-level access mode authentication based on the access mode parameters in the subsequent process. The access mode parameters specifically include the terminal's single sign-on method, login time, and login address. The multi-level access mode authentication specifically includes terminal single sign-on method authentication, terminal identifier access permission authentication, terminal login time access permission authentication, and / or terminal login address access permission authentication.

[0079] S003. The multi-level access control module enables authentication. The multi-level access control module can determine the access mode of the terminal based on the terminal identifier and enable multi-level authentication. Customized multi-level access mode authentication information for vertical industries can be pre-configured in the multi-level access control module. After receiving the terminal multi-level access authentication information from the standard AAA module, the multi-level access control module compares the terminal multi-level access authentication information with the customized multi-level access mode authentication information for the vertical industry to obtain the multi-level access mode authentication result, specifically including:

[0080] S004. Terminal Login Method Authentication: The multi-level access control module performs single sign-on (SSO) authentication on the terminal. The terminal can choose different SSO methods according to different scenarios. For example, for SSO within the same domain, a vertical industry may have only one domain name, using subdomains to distinguish different systems. Cookies (small text files) of the primary domain can be written using the subdomain, and the cookie can be set to the top domain, allowing the subdomain to access the top domain's cookie. For SSO across different domains, an SSO (Single Sign-On) authentication center (such as the open-source project CAS, where CAS stands for Central Authentication Service) can be deployed. The authentication center is responsible for handling login requests. The multi-level access control module receives the EAP-Response data packet to obtain the terminal's SSO method information and determines whether the terminal's SSO method conforms to the vertical industry's customized SSO method for the corresponding scenario. Selecting different SSO methods for different scenarios can reduce the time users spend logging into different systems, reduce the possibility of login errors, and achieve security while avoiding the processing and storage of authentication information for multiple systems. If this authentication step is successful, the terminal access permission authentication process begins; otherwise, step S005, "End Authentication Process," is executed.

[0081] Optionally, access permissions for the terminal can be authenticated by comparing the terminal identifier with a terminal whitelist defined by the vertical industry, specifically including:

[0082] Obtain the terminal's login time and login address based on the EAP-Response data packet;

[0083] Obtain the fixed terminal whitelist defined by the vertical industry, the time-segment terminal whitelist corresponding to the login time, and the regional terminal whitelist corresponding to the login address;

[0084] If the terminal is identified in the fixed terminal whitelist, time-based terminal whitelist, or regional terminal whitelist, the terminal will pass access permission authentication; otherwise, the terminal will not pass access permission authentication.

[0085] Specifically, in this embodiment, the multi-level access control module can set up a terminal serial number whitelist, a time-limited terminal access whitelist, and a region-specific terminal access whitelist when customizing AAA for the vertical industry. Upon receiving multi-level access authentication information from the terminal, it can complete terminal access permission authentication at these three levels, which may include, for example... Figure 3 The following steps are shown:

[0086] S006. Terminal Identification Authentication: The multi-level access control module authenticates the terminal based on its serial number. In some vertical industries, only specific terminals are required to access the network. To enhance security authentication in these industries, the module compares the terminal serial number against the vertical industry's whitelist to determine if the terminal passes this authentication step. If it passes, the module proceeds to the next authentication step; otherwise, it executes step S005. End Authentication Process.

[0087] S007. Terminal Login Time Authentication: The multi-level access control module authenticates the terminal based on a pre-defined time period. For example, some terminals can access the network from 8:00 AM to 6:00 PM, while others can access it from 12:00 PM to 8:00 AM. This is because, depending on the work requirements of vertical industries, such as early morning and late evening shifts, access to the company network may only be possible during specific time periods. The terminal whitelist based on the access time period defined by the vertical industry determines whether the terminal passes this authentication step. If it passes this authentication step, it proceeds to the next authentication step; otherwise, it executes step S005. End Authentication Process.

[0088] S008. Terminal login address authentication: The multi-level access control module authenticates the terminal's identity according to the pre-defined area. Because of the security requirements of vertical industries, some terminals can only access the network within the industrial park, or within the head office, subsidiary, or branch office. If the terminal is outside the area, the authentication will fail and network access will not be allowed. If the authentication passes this step, the authorization audit process will begin; otherwise, step S005 will be executed to end the authentication process.

[0089] Optionally, based on the result of multi-level access mode authentication, the terminal is authorized to access and enters audit logging mode, specifically including:

[0090] If the terminal is authenticated through multi-level access mode, an authorized traffic range is allocated to the terminal according to the terminal access mode, and the terminal is put into audit logging mode to audit and log the terminal's access to data network information.

[0091] Specifically, in this embodiment, after the multi-level access control module authenticates the terminal through all multi-level access modes, it enters the authorization audit process, which may include, for example: Figure 3 The following steps are shown:

[0092] S009. The multi-level access control module authorizes the terminal. The multi-level access control module authorizes the successfully authenticated terminal to allow the terminal to access the data network according to the authenticated access mode.

[0093] S010. The multi-level access control module allocates terminal traffic ranges. Based on the security requirements of the terminal, and to prevent DDoS (Distributed Denial of Service) attacks, the multi-level access control module can pre-set different authorized traffic ranges and authorization rules for different traffic ranges. The traffic range allocated to a successfully authenticated terminal is fixed.

[0094] S011. The multi-level access control module audits and records terminal access. During the process of a terminal accessing the data network, the multi-level access control module verifies the terminal information and records the terminal access log. The log is then checked a second time to ensure that the information access is accurate.

[0095] Optionally, after authorizing access to the terminal and entering audit log mode based on the result of multi-level access mode authentication, the method further includes:

[0096] Send a terminal login authentication identifier to the standard AAA module so that the standard AAA module allows the terminal to access the data network based on the terminal login authentication identifier.

[0097] Specifically, in this embodiment, after the multi-level access control module completes multi-level access mode authentication and authorization auditing for the terminal, the terminal accesses the data network according to the authorization, and the multi-level access control module records the audit results, i.e. Figure 3 The step S012 shown, where the terminal accesses the data network, may include, for example: Figure 2 The steps shown are: 3b. The multi-level access control module sends a terminal login authentication identifier to the standard AAA module; 3c. The standard AAA module allows the terminal to access the data network; and 3d. The multi-level access control module audits the terminal's access to the data network information.

[0098] Specifically, in this embodiment, to ensure controllable access for diverse terminals, prevent unauthorized terminals from accessing the private network, and accurately control terminal access behavior, a multi-level access control method is designed. This method adds a multi-level access control module to the standard AAA, responsible for controlling terminal access to the data service network. Different multi-level access control policies can be customized according to the needs of different vertical industries. For different vertical industries, the standard AAA forwards authentication information to the corresponding multi-level access control module based on the terminal identifier, meeting the security needs of different vertical users. This satisfies the need for enhanced secondary authentication while maximizing adaptation to the current development status of the industry chain, facilitating the implementation and promotion of multi-level access control functions for secondary authentication. It provides safer and more convenient control over terminal access for the security needs of vertical industries, ensuring the 5G security requirements of these industries.

[0099] Example 2:

[0100] like Figure 2-4 As shown, Embodiment 2 of the present invention provides a multi-level access control method, which can be applied to, for example... Figure 2 The standard AAA module of the customized AAA authorization accounting system shown herein, the method includes at least the following: Figure 4 The steps shown are as follows:

[0101] S21. Send terminal multi-level access authentication information to the multi-level access control module of the customized AAA system, so that the multi-level access control module performs multi-level access mode authentication on the terminal based on the received terminal multi-level access authentication information, including terminal login method authentication and terminal access permission authentication, and authorizes the terminal to access and enters audit log mode based on the result of multi-level access mode authentication, and controls the terminal to access the data network according to the access authorization and in audit log mode.

[0102] Optionally, terminal multi-level access authentication information is sent to the multi-level access control module, specifically including:

[0103] Receive terminal secondary authentication request from the Session Management Function (SMF) network element. The terminal secondary authentication request is sent by the SMF network element based on the access data network request from the terminal, and carries the terminal identifier.

[0104] Based on the terminal's secondary authentication request, send an Extensible Authentication Protocol Request (EAP-Request) data packet to the terminal;

[0105] Receive the Extensible Authentication Protocol (EAP) response data packet from the terminal. The EAP-Response data packet is sent by the terminal according to the EAP-Request data packet, and carries the terminal's single sign-on method, terminal login time, and terminal login address.

[0106] Send terminal multi-level access authentication information, including EAP-Response data packets and terminal identifier, to the multi-level access control module.

[0107] Optionally, after sending the terminal multilevel access authentication information to the multilevel access control module, the method further includes:

[0108] It receives a terminal login authentication identifier from the multi-level access control module and allows the terminal to access the data network based on the terminal login authentication identifier.

[0109] Specifically, in this embodiment, the method executed on the standard AAA module is the corresponding method that interacts with Embodiment 1, which can be understood in conjunction with Embodiment 1.

[0110] Example 3:

[0111] like Figure 5 As shown, Embodiment 3 of the present invention provides a multi-level access control module for a customized authentication, authorization, and accounting (AAA) system, comprising:

[0112] The first receiving unit 11 is used to receive terminal multi-level access authentication information from the standard AAA module of the customized AAA system;

[0113] The multi-level authentication unit 12 is connected to the first receiving unit 11 and is used to perform multi-level access mode authentication on the terminal according to the terminal multi-level access authentication information, including: terminal login method authentication and terminal access permission authentication.

[0114] The authorization audit unit 13 is connected to the multi-level authentication unit 12 and is used to authorize the terminal to access and enter the audit log mode based on the result of the multi-level access mode authentication.

[0115] The control unit 14, connected to the authorization audit unit 13, is used to control the terminal to access the data network according to the access authorization and in audit log mode.

[0116] Optionally, the terminal login method authentication is specifically terminal single sign-on authentication;

[0117] Terminal access permission authentication specifically includes: terminal identifier access permission authentication, terminal login time access permission authentication, and / or terminal login address access permission authentication.

[0118] Optionally, the terminal multi-level access authentication information includes the Extensible Authentication Protocol (EAP) response data packet and the terminal identifier;

[0119] Multi-level authentication unit 12, specifically includes:

[0120] Get sub-units, used to obtain the vertical industry to which the terminal belongs;

[0121] The first authentication subunit, connected to the acquisition subunit, is used to obtain the terminal's single sign-on method based on the EAP-Response data packet, and to authenticate the terminal's single sign-on method based on the single sign-on method customized for the vertical industry.

[0122] The second authentication subunit, connected to the acquisition subunit, is used to authenticate the terminal's access permissions by comparing the terminal identifier with a terminal whitelist defined by the vertical industry.

[0123] Optionally, the second authentication subunit is specifically used for:

[0124] Obtain the terminal's login time and login address based on the EAP-Response data packet;

[0125] Obtain the fixed terminal whitelist defined by the vertical industry, the time-segment terminal whitelist corresponding to the login time, and the regional terminal whitelist corresponding to the login address;

[0126] If the terminal is identified in the fixed terminal whitelist, time-based terminal whitelist, or regional terminal whitelist, the terminal will pass access permission authentication; otherwise, the terminal will not pass access permission authentication.

[0127] Optionally, the authorized audit unit 13 is specifically used for:

[0128] If the terminal is authenticated through multi-level access mode, an authorized traffic range is allocated to the terminal according to the terminal access mode, and the terminal is put into audit logging mode to audit and log the terminal's access to data network information.

[0129] Optionally, the multi-level access control module also includes:

[0130] The first sending unit is used to send a terminal login authentication identifier to the standard AAA module, so that the standard AAA module allows the terminal to access the data network based on the terminal login authentication identifier.

[0131] Example 4:

[0132] like Figure 6 As shown, Embodiment 4 of the present invention provides a standard AAA module for a customized authentication and authorization accounting AAA system, comprising:

[0133] The authentication activation unit 21 is used to send terminal multi-level access authentication information to the multi-level access control module of the customized AAA system, so that the multi-level access control module performs multi-level access mode authentication on the terminal based on the received terminal multi-level access authentication information, including terminal login method authentication and terminal access permission authentication, and authorizes the terminal to access and enters the audit log mode based on the result of the multi-level access mode authentication, and controls the terminal to access the data network according to the access authorization and in the audit log mode.

[0134] Optionally, the authentication activation unit 21 specifically includes:

[0135] The second receiving unit is used to receive a terminal secondary authentication request from the Session Management Function (SMF) network element. The terminal secondary authentication request is sent by the SMF network element according to the access data network request from the terminal, and carries the terminal identifier.

[0136] The second sending unit, connected to the second receiving unit, is used to send an Extensible Authentication Protocol Request (EAP-Request) data packet to the terminal based on the terminal's secondary authentication request.

[0137] The second receiving unit is also used to receive an Extensible Authentication Protocol (EAP) response data packet from the terminal. The EAP-Response data packet is sent by the terminal according to the EAP-Request data packet, and carries the terminal's single sign-on method, terminal login time, and terminal login address.

[0138] The second sending unit is also used to send terminal multi-level access authentication information, including EAP-Response data packets and terminal identifiers, to the multi-level access control module.

[0139] Optionally,

[0140] The second receiving unit is also used to receive a terminal login authentication identifier from the multi-level access control module, and allow the terminal to access the data network based on the terminal login authentication identifier.

[0141] Example 5:

[0142] Embodiment 5 of the present invention provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it implements the multi-level access control method as described in Embodiment 1 or 2.

[0143] Specifically, in this embodiment, the computing program stored in the computer-readable storage medium can run on a device including a multi-level access control module or a device including a standard AAA module. It is used to perform multi-level access mode authentication on the secondary authentication information of the terminal accessing the data network, and to formulate an access control policy including access authorization and audit log modes based on the results of the multi-level access mode authentication, controlling the terminal to securely access the data network according to the access control policy. The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules, or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), DVD or other optical disc storage, cartridges, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer.

[0144] In addition, the present invention may also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the processor runs the computer program stored in the memory, the processor executes the multi-level access control method as described in Embodiment 1 or 2.

[0145] The memory is connected to the processor. The memory can be flash memory, read-only memory or other types of memory. The processor can be a central processing unit or a microcontroller.

[0146] Example 6:

[0147] Embodiment 6 of the present invention provides a customized authentication authorization accounting AAA system, comprising:

[0148] A multi-level access control module is used to execute the multi-level access control method as described in Example 1.

[0149] A standard AAA module, connected to a multi-level access control module, is used to execute the multi-level access control method as described in Example 2.

[0150] Specifically, in this embodiment, the customized AAA system can be provided by, for example... Figure 2 The system consists of a multi-level access control module and a standard AAA module. These modules can be located on different servers or on the same server. The system can be a dedicated device or a functional module of a multi-functional device. For a more detailed description, please refer to Example 1.

[0151] Embodiments 1-6 of this invention provide a multi-level access control method, a multi-level access control module, a standard AAA module, a computer-readable storage medium, and a customized AAA system. The multi-level access control module of the customized AAA system receives terminal multi-level access authentication information from the standard AAA module of the customized AAA system. Based on the terminal multi-level access authentication information, it performs multi-level access mode authentication on the terminal, including terminal login method authentication and terminal access permission authentication. Based on the results of the multi-level access mode authentication, it formulates access control policies including access authorization and audit log modes, controlling the terminal to securely access the data network according to the access control policies. This enables the AAA system to formulate autonomous and controllable access control policies for terminal access to the data network, allowing the terminal to securely access scenarios such as enterprise parks according to the access control policies.

[0152] It is understood that the above embodiments are merely exemplary embodiments used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.

Claims

1. A multi-level access control method, characterized in that, A multi-level access control module applied to a customized authentication, authorization, and accounting (AAA) system, the method comprising: Receive terminal multi-level access authentication information from the standard AAA module of the customized AAA system. The terminal multi-level access authentication information includes an Extensible Authentication Protocol Response (EAP-Response) data packet and a terminal identifier. The EAP-Response data packet carries the terminal single sign-on method, terminal login time, and terminal login address. The terminal performs multi-level access mode authentication based on the terminal's multi-level access authentication information, including: terminal login method authentication and terminal access permission authentication. Terminal login authentication specifically refers to single sign-on (SSO) authentication, which includes: obtaining the vertical industry to which the terminal belongs; obtaining the terminal's SSO method based on the EAP-Response data packet; and determining whether the terminal's SSO method conforms to the vertical industry's customized SSO method for the corresponding scenario. This includes: SSO within the same domain (the vertical industry has only one domain, different systems are distinguished by subdomains, and a small text cookie is written to the primary domain using the subdomain, setting the cookie as the top-level domain, allowing the subdomain to access the top-level domain's cookie); and SSO across different domains (deploying a single sign-on (SSO) authentication center, which is responsible for handling login requests). The terminal access permission authentication specifically includes: obtaining three terminal whitelists defined by the vertical industry, including: a fixed terminal whitelist, a time period terminal whitelist corresponding to the login time, and a regional terminal whitelist corresponding to the login address; comparing the terminal identifier with the three terminal whitelists respectively; and passing access permission authentication only when the terminal identifier exists in all three terminal whitelists simultaneously. Based on the results of multi-level access mode authentication, the terminal is authorized to access and enters audit logging mode, specifically including: If the terminal is authenticated through multi-level access mode, a pre-set authorized traffic range is allocated to the terminal according to the terminal access mode, and the terminal is put into audit logging mode to audit and log the terminal's access to data network information. The control terminal accesses the data network according to the authorized traffic range and in the audit log mode, including auditing terminal access, verifying terminal information and recording terminal access logs, and performing secondary verification on the records.

2. The method according to claim 1, characterized in that, After authorizing access to the terminal and entering audit log mode based on the result of multi-level access mode authentication, the method further includes: Send a terminal login authentication identifier to the standard AAA module so that the standard AAA module allows the terminal to access the data network based on the terminal login authentication identifier.

3. A multi-level access control method, characterized in that, A standard AAA module applied to a customized AAA authorization accounting system, the method comprising: The system sends terminal multi-level access authentication information to the multi-level access control module of the customized AAA system. This information includes an Extensible Authentication Protocol (EAP) response data packet and a terminal identifier. The EAP response data packet carries the terminal's single sign-on method, login time, and login address. This enables the multi-level access control module to perform multi-level access mode authentication on the terminal based on the received terminal multi-level access authentication information, including: terminal login method authentication and terminal access permission authentication, wherein: Terminal login authentication specifically refers to single sign-on (SSO) authentication, which includes: obtaining the vertical industry to which the terminal belongs; obtaining the terminal's SSO method based on the EAP-Response data packet; and determining whether the terminal's SSO method conforms to the vertical industry's customized SSO method for the corresponding scenario. This includes: SSO within the same domain (the vertical industry has only one domain, different systems are distinguished by subdomains, and a small text cookie is written to the primary domain using the subdomain, setting the cookie as the top-level domain, allowing the subdomain to access the top-level domain's cookie); and SSO across different domains (deploying a single sign-on (SSO) authentication center, which is responsible for handling login requests). The terminal access permission authentication specifically includes: obtaining three terminal whitelists defined by the vertical industry, including: a fixed terminal whitelist, a time-based terminal whitelist corresponding to the login time, and a regional terminal whitelist corresponding to the login address; comparing the terminal identifier with each of the three terminal whitelists; and passing access permission authentication only when the terminal identifier exists in all three terminal whitelists simultaneously. Based on the results of multi-level access mode authentication, the terminal is authorized to access and enters audit logging mode, specifically including: If the terminal is authenticated via multi-level access mode, a pre-set authorized traffic range is allocated to the terminal according to the terminal's access mode, and the terminal enters audit logging mode to audit and log the terminal's access to data network information. Furthermore, the control terminal accesses the data network according to the authorized traffic range and in the audit log mode, including auditing terminal access, verifying terminal information and recording terminal access logs, and performing secondary verification on the records.

4. The method according to claim 3, characterized in that, Send terminal multi-level access authentication information to the multi-level access control module, specifically including: Receive terminal secondary authentication request from the Session Management Function (SMF) network element. The terminal secondary authentication request is sent by the SMF network element based on the access data network request from the terminal, and carries the terminal identifier. Based on the terminal's secondary authentication request, send an Extensible Authentication Protocol Request (EAP-Request) data packet to the terminal; Receive the Extensible Authentication Protocol (EAP) response data packet from the terminal. The EAP-Response data packet is sent by the terminal according to the EAP-Request data packet, and carries the terminal's single sign-on method, terminal login time, and terminal login address. Send terminal multi-level access authentication information, including EAP-Response data packets and terminal identifier, to the multi-level access control module.

5. The method according to claim 3, characterized in that, After sending the terminal multilevel access authentication information to the multilevel access control module, the method further includes: It receives a terminal login authentication identifier from the multi-level access control module and allows the terminal to access the data network based on the terminal login authentication identifier.

6. A multi-level access control module for a customized authentication and authorization accounting (AAA) system, characterized in that, include: The first receiving unit is used to receive terminal multi-level access authentication information from the standard AAA module of the customized AAA system. The terminal multi-level access authentication information includes an Extensible Authentication Protocol Response (EAP-Response) data packet and a terminal identifier. The EAP-Response data packet carries the terminal single sign-on method, terminal login time, and terminal login address. A multi-level authentication unit, connected to the first receiving unit, is used to perform multi-level access mode authentication on the terminal based on the terminal's multi-level access authentication information, including: terminal login method authentication and terminal access permission authentication. Terminal login authentication specifically refers to single sign-on (SSO) authentication, which includes: obtaining the vertical industry to which the terminal belongs; obtaining the terminal's SSO method based on the EAP-Response data packet; and determining whether the terminal's SSO method conforms to the vertical industry's customized SSO method for the corresponding scenario. This includes: SSO within the same domain (the vertical industry has only one domain, different systems are distinguished by subdomains, and a small text cookie is written to the primary domain using the subdomain, setting the cookie as the top-level domain, allowing the subdomain to access the top-level domain's cookie); and SSO across different domains (deploying a single sign-on (SSO) authentication center, which is responsible for handling login requests). The terminal access permission authentication specifically includes: obtaining three terminal whitelists defined by the vertical industry, including: a fixed terminal whitelist, a time period terminal whitelist corresponding to the login time, and a regional terminal whitelist corresponding to the login address; comparing the terminal identifier with the three terminal whitelists respectively; and passing access permission authentication only when the terminal identifier exists in all three terminal whitelists simultaneously. The authorization audit unit, connected to the multi-level authentication unit, is used to authorize access to the terminal and enter audit logging mode based on the results of multi-level access mode authentication. Specifically, it includes: If the terminal is authenticated through multi-level access mode, a pre-set authorized traffic range is allocated to the terminal according to the terminal access mode, and the terminal is put into audit logging mode to audit and log the terminal's access to data network information. The control unit, connected to the authorized audit unit, is used to control the terminal to access the data network according to the authorized traffic range and in the audit record mode, including auditing terminal access, verifying terminal information and recording terminal access record logs, and performing secondary verification on the records.

7. A standard AAA module for a customized authentication and authorization accounting AAA system, characterized in that, include: The authentication activation unit is used to send terminal multi-level access authentication information to the multi-level access control module of the customized AAA system. The terminal multi-level access authentication information includes an Extensible Authentication Protocol (EAP) response data packet and a terminal identifier. The EAP response data packet carries the terminal's single sign-on method, terminal login time, and terminal login address. This enables the multi-level access control module to perform multi-level access mode authentication on the terminal based on the received terminal multi-level access authentication information, including: terminal login method authentication and terminal access permission authentication. Terminal login authentication specifically refers to single sign-on (SSO) authentication, which includes: obtaining the vertical industry to which the terminal belongs; obtaining the terminal's SSO method based on the EAP-Response data packet; and determining whether the terminal's SSO method conforms to the vertical industry's customized SSO method for the corresponding scenario. This includes: SSO within the same domain (the vertical industry has only one domain, different systems are distinguished by subdomains, and a small text cookie is written to the primary domain using the subdomain, setting the cookie as the top-level domain, allowing the subdomain to access the top-level domain's cookie); and SSO across different domains (deploying a single sign-on (SSO) authentication center, which is responsible for handling login requests). The terminal access permission authentication specifically includes: obtaining three terminal whitelists defined by the vertical industry, including: a fixed terminal whitelist, a time-based terminal whitelist corresponding to the login time, and a regional terminal whitelist corresponding to the login address; comparing the terminal identifier with each of the three terminal whitelists; and passing access permission authentication only when the terminal identifier exists in all three terminal whitelists simultaneously. Based on the results of multi-level access mode authentication, the terminal is authorized to access and enters audit logging mode, specifically including: If the terminal is authenticated via multi-level access mode, a pre-set authorized traffic range is allocated to the terminal according to the terminal's access mode, and the terminal enters audit logging mode to audit and log the terminal's access to data network information. Furthermore, the control terminal accesses the data network according to the authorized traffic range and in the audit log mode, including auditing terminal access, verifying terminal information and recording terminal access logs, and performing secondary verification on the records.

8. A computer-readable storage medium, characterized in that, It stores a computer program, which, when executed by a processor, implements the multi-level access control method as described in any one of claims 1-2 or 3-5.

9. A customized authentication and authorization accounting AAA system, characterized in that, include: A multi-level access control module is used to execute the multi-level access control method as described in any one of claims 1-2; A standard AAA module, connected to a multi-level access control module, is used to execute the multi-level access control method as described in any one of claims 3-5.

Citation Information

Patent Citations

  • Network side AAA design method and system for realizing secondary authentication function

    CN111818014A