Business data processing method, apparatus, device, and medium

By combining dynamic and static factor data from the terminal to determine access credentials and dynamically adjusting access control policies, the problems of low efficiency and insufficient security under static policies are solved, and flexible and efficient business access control is achieved.

CN116567083BActive Publication Date: 2025-12-23TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210106482.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-28
Publication Date
2025-12-23
Estimated Expiration
2042-01-28

AI Technical Summary

Technical Problem

In existing technologies, data access control in business systems uses static policies, which leads to low efficiency and insufficient security as data volume increases and business expands.

Method used

By combining dynamic and static factor data from the terminal to determine access credentials, access control policies can be dynamically adjusted, the terminal environment and security status can be monitored in real time, and access control can be implemented in advance to avoid blocking after the fact.

Benefits of technology

It enables flexible access control when the terminal environment and security status change, improving the efficiency and security of business access, and is suitable for scenarios involving sudden events and temporary resource access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116567083B_ABST
    Figure CN116567083B_ABST
Patent Text Reader

Abstract

The present disclosure provides a business data processing method and device, equipment and medium, which are related to the technical field of artificial intelligence and can be applied to various scenes such as cloud technology, artificial intelligence, intelligent transportation and auxiliary driving. The method comprises: in the case of detecting a business access request for indicating access to a first preset business object, obtaining a first access credential matched with the business access request; the first access credential is determined according to dynamic factor data and static factor data of the terminal of the business management client; sending a first credential acquisition request for indicating obtaining a second access credential to the management server, the first credential acquisition request comprising the first access credential; obtaining a first credential acquisition result determined by the management server based on the first access credential and an access control strategy list; and performing business access control based on the first credential acquisition result. Through the method, the business access efficiency and security are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the field of computers, and particularly relates to a business data processing method and device, equipment and medium. BACKGROUND

[0002] In the data access scene of a business system, the data access permission of the business system is usually controlled by a static strategy. However, with the increase of data scale and the continuous expansion of business, when adjusting the control strategy, the static strategy of such access permission control needs to be replaced as a whole, which not only reduces the business access efficiency, but also has the problem of low security of business access. SUMMARY

[0003] The present disclosure provides a business data processing method, device, equipment and medium to solve at least one technical problem in the prior art.

[0004] In one aspect, the present disclosure provides a business data processing method, comprising:

[0005] initiating a business access request through a target business process in response to a business access event;

[0006] In a case where it is detected that the business access request is used to indicate access to a first preset business object, a first access credential matched with the business access request is obtained; the first access credential is determined according to dynamic factor data and static factor data of a terminal carrying a business management client;

[0007] sending a first credential acquisition request used to indicate acquisition of a second access credential to a management server, the first credential acquisition request comprising the first access credential;

[0008] obtaining a first credential acquisition result determined by the management server based on the first access credential and an access control strategy list;

[0009] controlling the business access request based on the first credential acquisition result.

[0010] In another aspect, a business data processing method is also provided, comprising:

[0011] obtaining a first credential acquisition request sent by a terminal and used to indicate acquisition of a second access credential, the first credential acquisition request comprising a first access credential matched with a business access request and obtained in a case where it is detected that the business access request is used to indicate access to a first preset business object, the business access request being sent by a target business process in response to a business access event, and the first access credential being determined according to dynamic factor data and static factor data of a terminal carrying a business management client;

[0012] determine a first credential obtaining result based on the first access credential and an access control policy list in the first credential obtaining request;

[0013] send the first credential obtaining result, so that the terminal performs service access control on the service access request based on the first credential obtaining result.

[0014] In another aspect, a service data processing apparatus is also provided, which comprises:

[0015] a first request sending module configured to initiate a service access request through a target service process in response to a service access event;

[0016] a first obtaining module configured to, in a case where it is detected that the service access request is used to indicate access to a first preset service object, obtain a first access credential matched with the service access request, the first access credential being determined according to dynamic factor data and static factor data of a terminal carrying a service management client;

[0017] a second request sending module configured to send a first credential obtaining request used to indicate obtaining of a second access credential to a management server, the first credential obtaining request comprising the first access credential;

[0018] a second obtaining module configured to obtain a first credential obtaining result determined by the management server based on the first access credential and an access control policy list;

[0019] a processing module configured to perform service access control on the service access request based on the first credential obtaining result.

[0020] In another aspect, a service data processing apparatus is also provided, which comprises:

[0021] a first obtaining module configured to obtain a first credential obtaining request sent by a terminal and used to indicate obtaining of a second access credential, the first credential obtaining request comprising a first access credential obtained in a case where it is detected that a service access request is used to indicate access to a first preset service object, the service access request being sent by a target service process in response to a service access event, the first access credential being determined according to dynamic factor data and static factor data of a terminal carrying a service management client;

[0022] a result determining module configured to determine a first credential obtaining result based on the first access credential and an access control policy list in the first credential obtaining request;

[0023] The sending module is configured to send the first credential obtaining result, so that the terminal performs service access control on the service access request based on the first credential obtaining result.

[0024] The other aspect further provides an electronic device, which comprises a processor and a memory, and the memory stores at least one instruction or at least one program, and the at least one instruction or the at least one program is loaded and executed by the processor to implement any of the above-mentioned methods.

[0025] The other aspect further provides a computer-readable storage medium, which stores at least one instruction or at least one program, and the at least one instruction or the at least one program is loaded and executed by a processor to implement any of the above-mentioned methods.

[0026] The other aspect further provides a computer program product or a computer program, which comprises computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes any of the above-mentioned methods.

[0027] The service data processing method, device, equipment and medium provided by the present disclosure have the following technical effects:

[0028] The embodiment of the disclosure initiates a business access request through a target business process in response to a business access event; in the case of detecting that the business access request is used to indicate access to a first preset business object, a first access credential matching the business access request is obtained; the first access credential is determined according to dynamic factor data and static factor data of a terminal carrying a business management client; a first credential acquisition request used to indicate acquisition of a second access credential is sent to a management server, and the first credential acquisition request includes the first access credential; a first credential acquisition result determined by the management server based on the first access credential and an access control policy list is obtained; and business access control is performed based on the first credential acquisition result. By combining the first access credential determined according to the dynamic factor data and the static factor data of the terminal, and based on the first access credential and the access control policy list, the credential acquisition result used to acquire the second access credential is determined, and business access control is performed based on the result, so that the terminal can hit the dynamic rule item when the network, the terminal environment and the security state change, and real-time access control is realized. The processing logic for suspected abnormal behavior or the processing logic that needs to be verified before access is implemented in advance before the sensitive resource access, rather than being processed by the asynchronous blocking method after the event, not only timely, but also flexible. In addition, the business access efficiency and security are improved, and the method can be applied to various scenes such as emergency disposal, temporary resource access and specified time period resource access. BRIEF DESCRIPTION OF DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the embodiments of the disclosure or the prior art, and the advantages thereof, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the disclosure, and for those skilled in the art, other drawings can also be obtained without creative labor.

[0030] Figure 1 is an application environment schematic diagram of a business data processing method provided by the embodiment of the disclosure;

[0031] Figure 2 is a flow schematic diagram of a business data processing method provided by the embodiment of the disclosure;

[0032] Figure 3 is a partial flow schematic diagram of a business data processing method provided by the embodiment of the disclosure;

[0033] Figure 4 is an interface schematic diagram of a business data processing method provided by the embodiment of the disclosure;

[0034] Figure 5 is a flow schematic diagram of a business data processing method provided by the embodiment of the disclosure;

[0035] Figure 6 is a timing diagram of a service data processing method provided by an embodiment of the present disclosure;

[0036] Figure 7 is a structural block diagram of a service data processing apparatus provided by an embodiment of the present disclosure;

[0037] Figure 8 is a structural block diagram of a service data processing apparatus provided by an embodiment of the present disclosure;

[0038] Figure 9 is a hardware structure schematic diagram of an apparatus for implementing the method provided by the embodiment of the present disclosure. DETAILED DESCRIPTION

[0039] In order for those skilled in the art to better understand the present disclosure scheme, the technical solutions in the embodiments of the present disclosure will be described clearly and completely below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, not all. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present disclosure.

[0040] In order to make the purpose, technical solutions and advantages of the present disclosure clearer, the embodiments of the present disclosure will be described in further detail below in conjunction with the drawings.

[0041] In order to facilitate the understanding of the technical solutions and the technical effects generated by the above-mentioned embodiments of the present disclosure, the terms involved in the embodiments of the present disclosure are briefly introduced:

[0042] Cloud technology (Cloud technology) is a general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on cloud computing business model application, which can form a resource pool, and can be used as needed, flexible and convenient. Cloud computing technology will become an important support. The background service of the technical network system needs a large amount of computing and storage resources, such as video websites, picture websites and more portal websites. With the high development and application of the Internet industry, every item may have its own identification mark in the future, and it needs to be transmitted to the background system for logical processing. Different levels of data will be processed separately, and various industry data will need strong system support, which can be realized through cloud computing.

[0043] Cloud Security refers to the security software, hardware, users, institutions, and security cloud platform based on the cloud computing business model. Cloud Security combines emerging technologies and concepts such as parallel processing, grid computing, and unknown virus behavior judgment. Through the abnormal monitoring of software behavior in the network by a large number of clients in a network, the latest information of Internet viruses and malicious programs is obtained and sent to the server for automatic analysis and processing, and the virus and Trojan solution is distributed to each client.

[0044] The main research directions of Cloud Security include: 1. Cloud computing security, mainly studying how to protect the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, compliance audit, etc.; 2. Cloudification of security infrastructure, mainly studying how to build and integrate security infrastructure resources using cloud computing, optimize security protection mechanisms, including building a large-scale security event, information collection and processing platform through cloud computing technology, realizing the collection and correlation analysis of massive information, and improving the network security event control ability and risk control ability; 3. Cloud security services, mainly studying various security services provided by cloud computing platforms for users, such as antivirus services, etc.

[0045] Cloud storage is a new concept extended and developed from the concept of cloud computing. Distributed cloud storage system (hereinafter referred to as storage system) refers to a storage system that collects and cooperatively works together a large number of various types of storage devices (storage devices are also referred to as storage nodes) in the network through cluster application, grid technology, and distributed storage file system functions, and provides data storage and business access functions to the outside.

[0046] At present, the storage method of the storage system is: creating a logical volume, and allocating a physical storage space to each logical volume when creating the logical volume, which may be a disk composed of a certain storage device or several storage devices. The client stores data on a certain logical volume, that is, stores data on the file system, and the file system divides the data into many parts, each part being an object, which contains not only data but also additional information such as data identification (ID, IDentity). The file system writes each object to the physical storage space of the logical volume, and records the storage location information of each object, so that when the client requests to access the data, the file system can access the data according to the storage location information of each object.

[0047] The process of allocating physical storage space for a logical volume is as follows: according to the capacity estimation of the object stored in the logical volume (the estimation often has a large margin relative to the actual capacity of the object to be stored) and the group of Redundant Array of Independent Disk (RAID), the physical storage space is divided into sections in advance, and a logical volume can be understood as a section, so that the logical volume is allocated with physical storage space.

[0048] A database can be briefly regarded as an electronic file cabinet, i.e., a place for storing electronic files, and a user can perform operations such as adding, querying, updating, and deleting data in the files. The so-called "database" is a collection of data stored together in a certain way, shared by multiple users, with as little redundancy as possible, and independent of application programs.

[0049] A database management system (DBMS) is a computer software system designed to manage a database, and generally has basic functions such as storage, interception, security assurance, backup, etc. The database management system can be classified according to the database model it supports, such as relational, XML (Extensible Markup Language), or according to the computer type it supports, such as server cluster, mobile phone, or according to the query language it uses, such as SQL (Structured Query Language), XQuery, or according to the performance focus, such as maximum size, highest running speed, or other classification methods. Regardless of the classification method used, some DBMSs can cross categories, such as supporting multiple query languages at the same time. The scheme provided in the embodiments of the present disclosure relates to cloud technology and the like, and is specifically described as follows.

[0050] The business data processing method provided by the present disclosure can be applied to an application environment as shown in Figure 1 As shown in Figure 1 The hardware environment can at least include a terminal 10, a management service end 20, a terminal 30, a business service end 40, and a gateway device 50.

[0051] The terminal 10 and the terminal 30 can be at least one of a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, a vehicle terminal, a smart television, and the like, but are not limited thereto. The terminal 10 can be a user terminal, and a business management client and a proxy component can be installed in the terminal 10. The business management client can be used to communicate with the management server 20, and the proxy component can be used to communicate between the business management client and the business server 40 via the gateway device 50, so as to realize a business system and data access. The number of the terminal 10 can be multiple, and the disclosure does not make a specific limitation thereon. The terminal 30 can be a management terminal, and the number thereof can be one or more, and the disclosure does not make a specific limitation thereon.

[0052] The management server 20 can provide a background service for processing business data of the terminal 10 and the terminal 30, and the business server 40 can provide a business service for the terminal 10. The management server 20 and the business server 40 can be independent physical servers, or can be a server cluster or a distributed system formed by multiple physical servers, or can be a cloud server providing cloud computing services. The terminal and the server can be directly or indirectly connected through wired or wireless communication, and the disclosure does not make a limitation thereon. It should be noted that the management server 20 and the business server 40 can be implemented as a cloud server in the cloud.

[0053] In some embodiments, the management server 20 and the business server 40 can also be implemented as nodes in a blockchain system. The blockchain is a new application mode of distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithm and other computer technologies. The blockchain is essentially a decentralized database, and is a series of data blocks associated using cryptographic methods. Each data block contains information of a batch of network transactions, and is used to verify the validity (anti-fake) of the information and generate the next block. The blockchain can include a blockchain underlying platform, a platform product service layer, and an application service layer.

[0054] It should be noted that in actual application, the business data processing method can be implemented in the terminal 10, or can be implemented in the management server, or can be implemented by at least one terminal and at least one server and a gateway device.

[0055] Of course, the method provided by the embodiment of the disclosure is not limited to the above-mentioned hardware environment, and can be used in other possible hardware environments, and the embodiment of the disclosure does not make a limitation thereon. Figure 1 The functions that can be implemented by each device in the hardware environment shown in the figure will be described together in the subsequent method embodiments, and will not be described too much here. Figure 1 The functions that can be implemented by each device in the hardware environment shown in the figure will be described together in the subsequent method embodiments, and will not be described too much here.

[0056] Figure 2is a flowchart of a business data processing method provided by an embodiment of the present disclosure. The present disclosure provides method operation steps as described in the embodiments or flowcharts, but can include more or fewer operation steps based on conventional or non-creative labor. The order of steps listed in the embodiments is only one of the many execution orders of the steps, and does not represent the only execution order. The execution subject of the business data processing method can be a business data processing apparatus provided by an embodiment of the present disclosure, or a server integrated with the business data processing apparatus, wherein the business data processing apparatus can be realized in the form of hardware or software. Taking the terminal in Figure 1 as an example, as shown in Figure 2 , the method can include:

[0057] S201: In response to a business access event, initiating a business access request through a target business process.

[0058] The business access event is used to reflect that the access subject triggers access to the access object. By way of example only, the access subject can be a party initiating access in the network, a user / device / application accessing the intranet business resource, etc., which is a digital entity formed by a single factor or a combination of factors such as users, devices, and applications. The access object can be a party being accessed in the network, i.e., enterprise intranet business resources, including applications, system environments (e.g., development test environments, operation and maintenance environments, production environments, etc.), data, interfaces, functions, etc. Optionally, the access object can include data resources corresponding to the business system and the business management client, and the business access event includes but is not limited to click, input, etc. trigger operation.

[0059] The target business process is used to reflect the instance of the business management client in the running process. In the case of detecting a business access event, the target business process can be called to initiate a business access request. The business access request can be used to indicate that the requested access needs to access the business object, which can include sensitive business objects and non-sensitive business objects. By way of example only, the sensitive business object can include sensitive enterprise resources or data; the non-sensitive business object can include non-enterprise resource access (e.g., public website access, ordinary enterprise resource access, etc.

[0060] It should be noted that before responding to the business access event, a step of logging in the business management client can also be included, identity authentication and login are performed through a login ticket, and then the terminal business security access service is performed according to the business management client. The login ticket (i.e., a large ticket) is a credential issued by the management server to the terminal after the terminal user is authenticated. The terminal user can automatically obtain a login ticket after completing the login operation through various identity authentication methods such as scanning code login, account password login, Token login, IAM login, and the like. Each login ticket has a login validity period and a use frequency. After logging out or exceeding the validity period of the login ticket, the login ticket will automatically expire, and then identity authentication and login need to be performed again.

[0061] S202: In a case where it is detected that the business access request is used to indicate access to a first preset business object, a first access credential matching the business access request is obtained.

[0062] Each business access request used to indicate a business object that needs to be accessed can include a sensitive business object and a non-sensitive business object. The first preset business object herein includes a sensitive business object, that is, a sensitive business system or data, such as enterprise resources or data. In a case where it is detected that the business access request is used to indicate that a sensitive business object needs to be accessed, that is, it is determined that the business access request is used to indicate the first preset business object.

[0063] The first access credential is determined according to dynamic factor data and static factor data of the terminal carrying the business management client. The business management client is installed on the terminal device, which can be used to assist in verifying whether the identity of the access object on the device is trusted, and assisting in verifying whether the device and the application accessed by the device are trusted.

[0064] The dynamic factor data is network environment data used to represent the terminal carrying the business management client. The dynamic factor data can include application feature information of the accessed application, environment perception information, and terminal compliance information, and the like. The application feature information can include MD5 of an executable file corresponding to the application, file version information, file description, product name, process file SHA256, root certificate, signature certificate, and the like. The environment perception information can include terminal network region information (such as export IP information), network environment information (such as physical network card IP information), and dynamic factor information such as whether the terminal user is accessing a sensitive system. The terminal compliance information can include at least one of virus detection information, vulnerability repair information, security reinforcement information, data protection information, real-time protection information, and heartbeat detection information.

[0065] The static factor data is used to characterize the static factors of the access object, and can include access subject information, access application feature information, access object, etc. The access subject information can include account information of the access subject, permission information of the access subject, access operation data (such as use time and use frequency of the first access credential), etc. The access object can include specific sensitive business systems or data, etc.

[0066] The first access credential can be a special credential set for sensitive business system or data access. When detecting that the access subject accesses the sensitive business object, the management server can limit its permissions and use scenarios by issuing the first access credential. Through the first access credential, the access security can be enhanced for dynamic access to sensitive business systems and data.

[0067] When the state of the terminal and the access operation data (such as the frequency and time of accessing the sensitive business system and data) of the access subject meet the dynamic access condition, the management server triggers the terminal to perform re-authentication. Before the terminal completes the re-authentication, the sensitive business system and data cannot be accessed. After completing the re-authentication, the management server responds to the business management client with a specific first access credential for the current sensitive business system and data, including the access permissions and access frequency of the access subject for the target system or data within a specific time. The terminal stores the first access credential, and subsequent access to the target business system or data will automatically bring the first access credential. The management server determines whether the access of the access subject to the target system or data is legal according to the first access credential sent by the terminal and the terminal environment state. If the terminal security state does not meet the standard or the environment state hits the rule item that cannot access the sensitive business system or data in the access control policy, the management server will set the first access credential to be invalid, and block the current and subsequent access. Until the terminal network environment changes, the management server determines that the access control rule is met, and then allows access to the related target system or data.

[0068] In actual application, the business management client can obtain the access control policy list issued by the management server, and determine whether the access traffic corresponding to the business access request needs the gateway device based on the access control policy list. If it is for the first preset business object, that is, the sensitive business object, it is determined based on the access control policy list that the access traffic corresponding to the business access request needs the gateway device, and the business access request is forwarded to the gateway device corresponding to the business server through the proxy client. Before forwarding the business access request to the business server through the gateway device, the terminal will check whether the first access credential for accessing the sensitive system or data is stored in the local encrypted persistent storage. If the first access credential exists, the first access credential is obtained. When the corresponding first access credential is not found, the first access credential can be a null value.

[0069] S203: sending a first credential obtaining request for indicating obtaining a second access credential to a management service end, wherein the first credential obtaining request comprises the first access credential.

[0070] The second access credential can be a temporary access credential of access traffic of each access enterprise resource through the gateway device. The second access credential can be a network access ticket (ticket).

[0071] Optionally, in addition to sending the process feature information of initiating the network access, terminal information, login user information, login credential and traffic feature, the business management client checks whether the first access credential for the sensitive system or data access is stored in the local encrypted persistent storage. If the first access credential exists, the business management client further sends the first access credential to the management service end to apply for the second access credential (ticket).

[0072] In the valid period of the second access credential, the same second access credential (ticket) is reused for the same application to access the same business site. After the proxy client hijacks the traffic, it is firstly checked whether the second access credential matched with the business site accessed by the current application exists in the local cache. If the second access credential exists, it is checked whether it is in the valid period. If the second access credential is in the valid period, the proxy client directly uses the second access credential cache, and does not need to apply for the second access credential from the business management client. Otherwise, the proxy client must successfully apply for the ticket from the business management client before forwarding the access traffic to the gateway device. After the proxy client generates the ticket, the ticket valid period parameter passed by the business management client is added to the ticket cache, so as to facilitate the subsequent access traffic.

[0073] S204: obtaining a first credential obtaining result determined by the management service end based on the first access credential and an access control policy list.

[0074] The access control policy list can be a control policy configured in advance. For example, as shown in Figure 4 The access control policy list comprises a plurality of access control policies, and the business control policy configuration interface can be used to configure the policy name, policy type, hit quantity, whether to apply and corresponding operation of the access control policy. Each access control policy has a corresponding priority. For example, if the priority is high, the corresponding access control policy is arranged in the front of the access control policy list, and vice versa. Continue to refer to Figure 4As shown, the configuration personnel can adjust the priority of the access control policy and the access control policy, and control according to the priority of the adjusted access control policy.

[0075] It should be understood that, Figure 4 The specific content in the service control policy configuration interface is only exemplary, and can be adjusted according to actual conditions, and the present disclosure does not make specific limitations thereon.

[0076] Optionally, the first credential acquisition result can include: a result for indicating re-authentication of the service access event, a result for indicating adjustment of access authority of the service access event, a result for indicating that the access of the service access event is legal, or a result for indicating that the access of the service access event is illegal.

[0077] Optionally, when it is determined based on the first access credential that the terminal runtime access decision meets the requirements, it is preliminarily determined that the access is legal. If it is determined that the terminal runtime access decision does not meet the requirements, the management server cannot be accessed, and a result for indicating re-authentication, rejection, direct connection (without passing through the gateway device), etc. can be obtained according to the access control policy.

[0078] S205: Based on the first credential acquisition result, performing service access control on the service access request.

[0079] In an optional embodiment, the service access control based on the first credential acquisition result includes:

[0080] S301: In the case where the first credential acquisition result indicates that the access of the service access event is legal, obtaining a second access credential determined by the management server;

[0081] S302: Based on the obtained second access credential, performing service access control on the service access request; or,

[0082] S303: In the case where the first credential acquisition result indicates that the access of the service access event is illegal, controlling to block the service access request.

[0083] Optionally, in a case where the first credential acquisition result is used to indicate that the access to the service access event is legal, the management server determines a second access credential; and based on the acquired second access credential, the service access request is controlled for service access. Specifically, in a case where an access attribute of the second access credential meets the authentication, the access traffic corresponding to the service access request is forwarded to the gateway device through the proxy client, and the access traffic is transmitted to the service server through the gateway device, so as to realize the service data access. In a case where the first credential acquisition result is used to indicate that the access to the service access event is illegal, the service access request is controlled to be blocked.

[0084] In an optional embodiment, the service access control on the service access request based on the first credential acquisition result comprises:

[0085] S304: In a case where the first credential acquisition result is used to indicate that the service access event needs to be re-authenticated, a re-authentication instruction is generated.

[0086] Optionally, the re-authentication can include an instruction for re-authentication. The re-authentication instruction can be implemented through re-login, SMS verification, face recognition, fingerprint recognition, etc. Specifically, a verification window requiring the user to re-authenticate can be displayed on the user interface, and the verification window can display verification methods including code scanning login, Token login, SMS verification, face recognition, fingerprint recognition, etc.

[0087] S305: In response to a trigger operation of the re-authentication instruction, a management server is sent an acquisition request for generating a third access credential.

[0088] Optionally, in a case where the trigger operation is a successful login in response to the login mode indicated by the re-authentication instruction, the management server is sent the acquisition request for generating the third access credential, and the management server generates the third access credential for the current access process of the terminal.

[0089] S306: Based on the acquired third access credential, the service access request is controlled for service access.

[0090] In an optional embodiment, the service access control on the service access request based on the acquired third access credential comprises:

[0091] S3061: A second credential acquisition request for acquiring a second access credential is sent to the management server, and the credential acquisition request includes the third access credential;

[0092] S3063: A second credential acquisition result determined by the management server based on the third access credential and an access control policy list is acquired.

[0093] S3065: performing service access control on the service access request based on the second credential obtaining result.

[0094] Optionally, the second credential obtaining result can include a result indicating re-authentication of the service access event, a result indicating adjustment of access right of the service access event, a result indicating that the service access event is legally accessed, or a result indicating that the service access event is not legally accessed.

[0095] Optionally, when it is determined based on the third access credential that the terminal runtime access decision meets the requirements, it is preliminarily determined that the access is legal. If it is determined that the terminal runtime access decision does not meet the requirements, the terminal cannot reach the service end, and a result indicating re-authentication, rejection, direct connection (without passing through the gateway device), etc. can be obtained according to the access control policy.

[0096] In an optional embodiment, the service access control based on the first credential obtaining result includes:

[0097] S307: In a case where the first credential obtaining result indicates adjustment of the access right of the service access event, obtaining a target access right after adjustment;

[0098] S308: obtaining a second access credential determined by the management service end based on the target access right;

[0099] S309: performing service access control on the service access request based on the obtained second access credential.

[0100] Optionally, the adjustment of the access right of the service access event can include right degradation adjustment of the access right of the service access event, determination of a second access credential through the target access right after adjustment, and further service access control through the second access credential. Since the second access credential is a restrictive access credential, the access content of the access subject can be partially limited, and the service processing security is improved.

[0101] The embodiment of the present disclosure initiates a service access request through a target service process in response to a service access event; in the case of detecting that the service access request is used to indicate access to a first preset service object, a first access credential matching the service access request is acquired; the first access credential is determined according to dynamic factor data and static factor data of a terminal carrying a service management client; a first credential acquisition request used to indicate acquisition of a second access credential is sent to a management server, and the first credential acquisition request includes the first access credential; a first credential acquisition result determined by the management server based on the first access credential and an access control policy list is acquired; and service access control is performed based on the first credential acquisition result. By combining the first access credential determined according to the dynamic factor data and the static factor data of the terminal, and determining the credential acquisition result used to acquire the second access credential based on the first access credential and the access control policy list, and performing service access control based on the result, the terminal can hit the dynamic rule item when the network, the terminal environment and the security state change, realize real-time access control, and implement the processing logic for suspected abnormal behavior or access after verification in advance before sensitive resource access, instead of processing through an asynchronous blocking mode after the event, which not only processes in time, but also has strong flexibility. In addition, the service access efficiency and security are improved, and the method can be applied to various scenes such as emergency disposal, temporary resource access and specified time period resource access.

[0102] In an optional implementation, the method further includes:

[0103] In the case of detecting that the service access request is used to indicate access to a second preset service object, the service access request is sent to a service server.

[0104] Optionally, the service management client can acquire an access control policy list issued by the management server, and determine whether the access traffic corresponding to the service access request needs a gateway device based on the access control policy list. If it is non-enterprise resource access (for example, a public website), it is determined based on the access control policy list that the access traffic corresponding to the service access request does not need the gateway device, and the proxy client can directly respond to the service server corresponding to the direct connection service access request to acquire access information from the service server.

[0105] In an optional implementation, the method further includes:

[0106] In the case of detecting that the service access request is used to indicate access to a third preset service object, a third credential acquisition request used to indicate acquisition of a second access credential is sent to the management server;

[0107] A third credential acquisition result determined by the management server based on the third credential acquisition request and the access control policy list is acquired.

[0108] Based on the third credential acquisition result, the service access request is subjected to service access control.

[0109] Optionally, the service management client can acquire the access control policy list issued by the management server, and determine whether the access traffic corresponding to the service access request needs the gateway device based on the access control policy list. If it is an access to a normal enterprise resource, it is determined based on the access control policy list that the access traffic corresponding to the service access request needs the gateway device, and the service access request is forwarded to the gateway device corresponding to the service server through the proxy client.

[0110] The third credential acquisition request can include process feature information, terminal information, login user information, login credentials and access traffic features initiated by the service management client for collecting network access. The access traffic features can include target system, target port, source IP, source port, network protocol, etc.

[0111] Figure 5 is a flowchart of a service data processing method provided by the embodiments of the present disclosure. The present disclosure provides method operation steps as described in the embodiments or flowcharts, but more or fewer operation steps can be included based on conventional or non-inventive labor. The order of steps listed in the embodiments is only one of the many execution orders, and does not represent the only execution order. The execution subject of the service data processing method can be a service data processing apparatus provided by the embodiments of the present disclosure, or a server integrated with the service data processing apparatus, wherein the service data processing apparatus can be realized in the form of hardware or software. Taking the management server in Figure 1 as an example for description, as shown in Figure 5 , the method can include:

[0112] S501: acquiring a first credential acquisition request sent by a terminal for indicating acquisition of a second access credential, the first credential acquisition request including a first access credential acquired in a case where it is detected that the service access request is for indicating access to a first preset service object, the service access request being sent by a target service process in response to a service access event, the first access credential being determined according to dynamic factor data and static factor data of the terminal carrying the service management client.

[0113] S502: determining a first credential acquisition result based on the first access credential in the first credential acquisition request;

[0114] S503: sending the first credential acquisition result, so that the terminal performs service access control on the service access request based on the first credential acquisition result.

[0115] It should be noted that the specific content and details can refer to the foregoing embodiments, which will not be repeated here.

[0116] In an optional embodiment, the method further comprises:

[0117] Obtaining dynamic factor data obtained by the terminal in real time monitoring;

[0118] In the case where the dynamic factor data indicates that the preset access condition is not met, the service access request is rejected.

[0119] Optionally, the dynamic factor data can include application feature information of the access application, environment perception information, terminal compliance information, etc. The preset access condition can include the case where the application feature information, the environment perception information, and the terminal compliance information meet the corresponding preset condition. The following will be specifically described:

[0120] (1) Application feature information of the access application

[0121] The terminal user can perform application security detection on the application feature information when accessing the enterprise resource, including security detection on the MD5 of the executable file corresponding to the application, the file version information, the copyright information, the file description, the product name, the process file SHA256, whether it has been signed, and the root certificate, the intermediate certificate, the signature certificate, etc. The business management client can jointly detect the application with the management server, and set the process feature cache in the business management client to speed up the efficiency of application detection.

[0122] (2) Terminal environment perception information

[0123] The business management client can detect the terminal environment perception information, including detecting the change of the terminal network area (such as the change of the export IP), the change of the network environment (such as the change of the physical network card IP), whether the terminal user is accessing a sensitive system, etc. The management server allows the administrator to customize the terminal environment perception strategy, can configure multiple different perception strategies and apply them to different terminals, and controls the frequency and reporting rules of the terminal environment perception.

[0124] The management server supports issuing different access control rules for the results of the business management client environment perception. The following scenarios are listed for illustration:

[0125] Scenario one, when the terminal identifies that it is about to access a special sensitive resource, the user is forced to complete re-authentication to strengthen identity verification. If the re-authentication is successfully completed within a valid time period, the subsequent access authentication operation is allowed, otherwise the access is automatically interrupted.

[0126] Scenario two, the business management client identifies that the network environment has changed and needs to perform secondary authentication, thereby automatically sensing the off-site login and access behavior.

[0127] Scenario three, the management server sets access permissions related to the network area for some personnel. In the enterprise intranet, some resources can be accessed, and outside the enterprise network, access to some sensitive resources is limited. When the business management client identifies that the terminal network area has changed, it automatically adapts the rules subset associated with the network area in the access control rules. Different network areas have different access permissions. Users can automatically adjust access permissions according to changes in network areas, or trigger secondary identity verification to reauthorize.

[0128] (3) Terminal compliance information

[0129] The business management client resides in the device terminal and performs functions such as virus scanning, vulnerability repair, security reinforcement, data protection, real-time protection, and heartbeat detection periodically and silently. The client performs device security detection, control reinforcement, and abnormality repair according to the policies issued by the management server. When it identifies that the device has installed the business management client and passed the virus scanning, real-time protection, and other security detection, it allows the device to perform zero-trust network access. If the device has detected abnormal items that can be automatically repaired, the business management client performs automatic repair according to the management server policy. If the device has detected abnormal items that need to be repaired manually, the terminal with the business management client reminds the user by displaying the abnormal items, causes, and repair suggestions. Before the user repairs these problems, the user is prohibited from logging in to perform identity authentication and zero-trust access, or is subject to a power-down process. For example, a terminal employee is working, and the compliance detection finds that the terminal has a security baseline problem. Based on the policy setting, the terminal is subject to a power-down process and triggers the relevant enhanced authentication policy, rather than being directly disconnected from the network, affecting normal business operations. The business management client performs terminal compliance detection to enable zero-trust network access in a secure device.

[0130] When the business management client initiates a network access request, it automatically generates a runtime access decision based on the terminal compliance information and network environment results calculated during the user access request. Unlike the access control rules specified by the enterprise administrator, the runtime access decision is dynamic and real-time, with the advantages of high efficiency, strong flexibility, and low latency. If the device terminal compliance detection result or environment sensing does not meet the set requirements, access to enterprise resources is denied or terminated. If the device terminal compliance meets the requirements, subsequent traffic authentication operations are performed.

[0131] In an optional implementation, the first credential acquisition result is determined based on the first access credential in the first credential acquisition request, including:

[0132] In a case where it is determined that the service access request is used to indicate access to target data, access attribute information of the first access credential is acquired, and application feature information corresponding to a service management client corresponding to the service access request is acquired;

[0133] Based on the access attribute information and the application feature information, a first credential acquisition result is determined.

[0134] The access attribute information can include a ticket validity period or a maximum number of uses corresponding to the access credential. The application feature information can include md5, signature information, application copyright information, etc. The first credential acquisition result can include a result indicating re-authentication of the service access event, a result indicating adjustment of access rights of the service access event, a result indicating that the service access event is legally accessed, or a result indicating that the service access event is not legally accessed.

[0135] In an optional embodiment, the determination of the first credential acquisition result based on the access attribute information and the application feature information includes:

[0136] In a case where the access attribute information satisfies a first preset condition and the application feature information satisfies a second preset condition, at least one target access control strategy is acquired.

[0137] Based on at least one target access control strategy and a priority corresponding to each target access control strategy, a first credential acquisition result is determined.

[0138] The first preset condition can include that the first access credential satisfies an authentication condition, such as a use frequency and a use time that meet the authentication condition. The second preset condition can include that the application feature information satisfies a required security detection condition.

[0139] Optionally, the management server incorporates a terminal dynamic factor as a core element into the generation process of the access control rule. The terminal monitors the network, security level, and environment state in real time. When a dynamic factor concerned in the access control rule or the security strategy is identified to change, the matching logic of the dynamic rule is automatically triggered. There are the following cases:

[0140] (1) If one of the dynamic rules is hit, the access control is performed according to the content of the dynamic rule. As shown in FIG. 9, if the adjusted "order 9" is hit, the access control is performed according to the control strategy corresponding to the order 9, that is, the control strategy of verifying the access is executed. Figure 4

[0141] ​(2) If the hit dynamic rule item is not less than two, according to the policy or rule priority specified by the administrator when setting the policy or rule, the item with higher priority automatically overrides the item with lower priority. When the enterprise administrator configures the policy, the management end automatically checks the policy or rule configuration, and automatically reminds the administrator to perform priority configuration when there is a conflict or mutual override relationship between the items. If the administrator does not manually specify, the security preset algorithm specifies the priority order for the rule items, and the sorting rule is displayed to the enterprise administrator for review and modification. Continue as shown in Figure 4 If "order 6" and "order 9" are hit at the same time, access control is performed according to the control policy corresponding to order 6, that is, the control policy of prohibiting access is executed.

[0142] (3) If the dynamic rule item is not hit, the policy will be performed according to the general reference access rule, and no dynamic control will be performed.

[0143] In an optional embodiment, the target access control policy includes a first control policy for indicating re-authentication of the business access event, a second control policy for indicating adjustment of access rights of the business access event, a third control policy for indicating access legality of the business access event, or a fourth control policy for indicating access illegality of the business access event.

[0144] The embodiment of the present disclosure acquires a first credential acquisition request for indicating acquisition of a second access credential sent by a terminal, the first credential acquisition request includes a first access credential acquired in a case where it is detected that the service access request is used for indicating access to a first preset service object, the service access request is sent by a target service process in response to a service access event, and the first access credential is determined according to dynamic factor data and static factor data of a terminal carrying a service management client; a first credential acquisition result is determined based on the first access credential in the first credential acquisition request; and the first credential acquisition result is sent, so that the terminal performs service access control on the service access request based on the first credential acquisition result. By combining the first access credential determined according to the dynamic factor data and the static factor data of the terminal, and determining the credential acquisition result for acquiring the second access credential based on the first access credential and an access control policy list, and performing service access control based on the result, the terminal can hit the dynamic rule item when the network, the terminal environment and the security state change, realize real-time access control, and implement the processing logic for suspected abnormal behavior or the processing logic for access after verification before the sensitive resource access, instead of processing by the asynchronous blocking mode after the event, so that the processing is timely and flexible. In addition, the service access efficiency and security are improved, and the method can be applied to various scenes such as emergency disposal, temporary resource access and specified time period resource access.

[0145] Technical details not described in the above embodiments are described in the method provided by any of the above embodiments of the present disclosure, and will not be described here.

[0146] In an optional embodiment, the present disclosure further provides a service data processing system, which comprises a terminal, a gateway device and a management server, wherein the terminal comprises a service management client and a proxy client. The service data processing system is described in detail as follows:

[0147] The service management client, the proxy client and the management server jointly constitute a dynamic access control environment. The service management client is mainly responsible for terminal environment perception, dynamic compliance detection, traffic authentication and application security detection, etc., the proxy client is responsible for traffic hijacking and traffic forwarding, and the management server is mainly responsible for automatic analysis of terminal environment perception data, generation and delivery of access control policies, and issuance and verification of network access credentials, etc. The interaction logic between the three is mainly composed of the following aspects.

[0148] (a) The business management client can collect terminal environment information, including network area information, export IP, dynamic compliance detection results, running application information, and after triggering the reporting conditions set by the management server (such as meeting the periodic reporting conditions of time interval, changing to meet the conditions of change and reporting, etc.), the terminal environment information is sent to the management server, and the management server determines whether the security environment of the current terminal has changed based on historical data and set security policies.

[0149] (b) When the management server determines that the security level of the current terminal is reduced or changes that meet the dynamic access control policy, the business management client updates the local access control policy or executes the corresponding processing logic to affect the current and subsequent network access through the synchronous response of the client reporting or directly pushing the command to the terminal. For example, when the management server identifies that the network area of the terminal is switched from A to B based on the environment data reported by the client, the rule that the B area cannot access the sensitive business system in the dynamic access control policy is hit.

[0150] (c) After the proxy client successfully applies for a network access ticket (second access credential) from the business management client, the local ticket cache is constructed according to the ticket validity period or the maximum number of uses issued by the management server, avoiding the same application accessing the same business system in high-frequency scenarios, frequently applying for tickets from the business management client, causing delay and waste of traffic. In the case of existing and effective proxy client ticket cache, the proxy client will not initiate traffic authentication to the business management client, and will directly determine the forwarding and actual proxy of traffic according to the ticket cache.

[0151] (d) When the dynamic access control policy changes or the dynamic factor of the terminal changes to trigger the change of the policy hit rule, the business management client sends a command to the proxy client to interrupt or clear the specified ticket cache. The specified access session interruption of the terminal is suitable for the scenario where the current security environment and state of the terminal no longer meet the dynamic access rule and need to interrupt the current access immediately. Clearing the specified ticket cache is suitable for scenarios where subsequent access to enterprise resources via the intelligent gateway proxy requires re-authentication or direct access, and the proxy client needs to immediately re-initiate network access ticket application to the business management client, and the business management client makes different access control behaviors.

[0152] The business management client and the agent client are key control flow policy enforcement points of the zero-trust network access control. The agent client mainly hijacks all network access traffic initiated by the access subject on the terminal. After the access traffic is hijacked, the agent client compares the target access address of the traffic with the enterprise resource information identified in the access control policy in the zero-trust, identifies that the hijacked traffic needs to be executed by the intelligent gateway, and then the agent client needs to initiate a traffic authentication request to the business management client. After the traffic authentication request is authenticated by the business management client, the business management client is responsible for sending the actual network access traffic to the intelligent gateway through the physical network card, and the intelligent gateway proxies the actual business access. If the network traffic authentication of the business management client is not passed or the hijacked traffic is a type that does not need to be executed by the intelligent gateway, the agent client component will directly hijack the original network access traffic through the physical network card and the corresponding destination business site for network access and response process, realizing direct access.

[0153] After the agent client identifies that the hijacked traffic needs to be executed by the intelligent gateway, the agent client immediately initiates a traffic authentication request to the business management client. After the business management client component receives the traffic authentication request, the business management client component first detects the application process of the request initiator, collects the process PE file information (such as process file full path, MD5, signature information, process modification time, etc.) of the request initiator, and first compares with the local encrypted cache of application process characteristics. If an anomaly is found, the access is terminated. If no anomaly is found or no cache record is matched, the process information is cached when the access credential is applied to the management server, and the asynchronous inspection information is initiated to the management server, including the process file last modification time, MD5, SHA256, copyright information, process signature information (including digest algorithm, root certificate information, intermediate certificate information, signature certificate information, signer name, signature state) and the like. After the process inspection is performed on the management server, the result is returned to the client to update the local application process characteristic encrypted cache.

[0154] The management server policy service is the rule generation and control center of the zero-trust network access control policy. It is responsible for detecting the access ticket application request sent by the terminal and generating the ticket. The access control process is as follows:

[0155] When the business management client receives the traffic authentication request of the agent client, it collects the process PE file information (process file full path, MD5, signature information, process modification time, etc.), operating system information, URL access information, device information, user login information agent, current user login ticket and other related information when applying for a ticket from the management server through the network. The management server detects whether the network ticket application request conforms to the access permission of the corresponding user and the business system access rules. At the same time, it identifies from the management server cache whether the corresponding process is a malicious process. If there is no corresponding information of the process in the cache, it initiates an asynchronous detection of the application process to the threat intelligence cloud service. After detecting that the access ticket application request sent by the terminal is compliant, the management server ticket service will generate a ticket corresponding to the request and respond to the business management client and the agent client. The detailed steps can be as follows:

[0156] 1) Collect enterprise application process information through asynchronous detection of the client to form an application library.

[0157] 2) After the management server receives the network access ticket application request from the client, it first checks whether the process md5 in the ticket request is a trusted md5 through the management server process detection cache. If it is a trusted md5, then it checks whether the process name is in the process name list in the access control policy. If it is not, it is considered that the access request has no permission to access enterprise resources, and the ticket is denied. If it is in the list, the next step is performed.

[0158] 3) According to the process name, the process signature information of the same process name is retrieved from the application library, and then the signature in the ticket application request is compared with the signature information of the same process name. If they are consistent, the md5 of the process name is automatically added to the trusted application md5 list. If the signatures are inconsistent, the ticket is denied.

[0159] 4) The management server initiates asynchronous detection of the data in the application library at regular intervals, updates the detection results to the management server detection cache, and simultaneously issues a client update of the application process feature encryption cache.

[0160] The management server incorporates terminal dynamic factors as a core element into the generation process of access control rules. The terminal monitors the network, security level and environment state in real time. When it identifies a change in the dynamic factors concerned in the access control rules or security policy, it automatically triggers the matching logic of the dynamic rules, which has the following several cases.

[0161] (1) If one of the dynamic rules is hit, the access control is executed according to the content of the dynamic rule.

[0162] (2) If the hit dynamic rule item is not less than two, according to the policy or rule priority specified by the administrator when setting the policy or rule, the higher priority item automatically overrides the lower priority item. When the enterprise administrator configures the policy, the management side automatically checks the policy or rule configuration, and automatically reminds the administrator to perform priority configuration when there is a conflict or mutual override relationship between the items. If the administrator does not manually specify, the security preset algorithm specifies the priority order for the rule items, and the sorting rule is displayed to the enterprise administrator for review and modification.

[0163] (3) If the dynamic rule item is not hit, the policy will be accessed according to the general reference access rule, and dynamic control will not be performed.

[0164] While the terminal automatically attempts to match when the dynamic rule is generated and the dynamic factor data changes, the management service side performs flexible identity authentication and permission control through the first access credential (i.e. re-authentication ticket). The description is as follows:

[0165] The first access credential (i.e. re-authentication ticket) is a special credential set for sensitive business system or data access. Unlike the login access credential (i.e. large ticket) and the second access credential (i.e. small ticket), the first access credential is specifically designed for dynamic access to sensitive business systems and data to enhance access security. The login ticket, network access ticket, and re-authentication ticket are described in turn as follows:

[0166] The login access credential (i.e. large ticket) is a credential issued by the management service side to the terminal after the terminal user is authenticated. The terminal user can automatically obtain a login ticket after completing the login operation through multiple identity authentication methods on the client each time. The large ticket is automatically invalidated after logging out of the client or exceeding the valid period of the ticket.

[0167] The second access credential (i.e. small ticket) is a temporary access credential issued by the zero trust function for each access traffic to enterprise resources through the intelligent gateway. Within the valid period of the small ticket, the access subject accesses the same business site through the same application, which will reuse a small ticket. After the proxy client hijacks the traffic, it first checks whether there is a small ticket that matches the business site accessed by the current application in the local cache. If there is, check whether it is within the valid period. If it is within the valid period, the proxy client can directly use the small ticket cache without applying for a small ticket from the business management client. Otherwise, the proxy client must successfully apply for a small ticket from the business management client before forwarding the access traffic to the gateway device. After the proxy client generates a small ticket, it adds it to the ticket cache according to the small ticket valid period parameter passed by the business management client, which affects the subsequent access traffic.

[0168] The first access credential (i.e., re-authentication ticket) is for the scenario of accessing sensitive business systems and data by the access subject. When the environmental state of the terminal, the access behavior of the access subject (such as the frequency and time of accessing sensitive business systems and data, etc.) conforms to the dynamic access rule, the management server triggers the terminal to perform re-authentication, and the sensitive business systems and data cannot be accessed before the terminal completes the re-authentication. After completing the re-authentication, the management server responds to the client with a specific re-authentication ticket for the current sensitive business system and data, which contains the access permission and access frequency of the access subject to the target system or data within a specific time. The terminal stores the re-authentication ticket, and the subsequent access to the target business system or data will automatically bring the re-authentication ticket. The management server determines whether the access of the access subject to the target system or data is legal according to the re-authentication ticket sent by the terminal and the terminal environmental state. If the terminal security state does not meet the standard or the environmental state hits the rule item of the access control policy that cannot access the sensitive business system or data, the management server will invalidate the re-authentication ticket and block the current and subsequent access. Until the terminal environment changes, the management server determines that the access control rule is met, and then the access to the related target system or data is allowed.

[0169] For ease of understanding, Figure 6 is a timing diagram of a business data processing method provided by an embodiment of the present disclosure. As Figure 6 indicated, the process of performing dynamic trust evaluation and control by the business management client, the proxy client, the gateway device, and the management server when a user accesses sensitive business systems or data is illustrated.

[0170] The process of performing dynamic trust evaluation and control by the business management client, the proxy client, the access gateway, and the management server when a user accesses sensitive business systems or data is illustrated in combination with the above figure.

[0171] The business system initiates access to sensitive business sites or data, and the traffic is hijacked by the client full-traffic proxy client. The proxy client component initiates traffic authentication to the business management client based on information such as the target business system of the traffic, the network protocol, and the process ID initiating the access. The business management client determines whether the traffic should pass through the access gateway for access according to the dynamic access control policy issued by the management server. If it is non-enterprise resource access (such as a public website), the proxy client is directly responded with direct access information. If it is access to ordinary enterprise resources, the business management client collects process feature information, terminal information, login user information, login credentials, and traffic features (such as target system, target port, source IP, source port, network protocol, etc.) to initiate network access credentials (tickets) to the management server.

[0172] If the access is identified as access to sensitive enterprise resources or data based on the dynamic access control policy, in addition to sending process feature information, terminal information, login user information, login credentials, and traffic characteristics to initiate the network access credential (ticket) to the management server, the terminal checks whether the re-authentication ticket for the sensitive system or data access is stored in the local encrypted persistent storage. If it exists, the business management client will also send the re-authentication ticket to the management server to apply for the network access credential (ticket).

[0173] The business system initiates access to sensitive business sites or data, and the traffic is hijacked by the full-flow proxy client. The proxy client initiates traffic authentication to the business management client based on the target business system, network protocol, and process ID of the access initiation of the traffic. The business management client determines whether the traffic should be accessed through the access gateway according to the dynamic access control policy issued by the management server. If it is access to non-enterprise resources (such as public websites), the proxy client is directly responded with access information for direct connection. If it is access to ordinary enterprise resources, the business management client collects process feature information, terminal information, login user information, login credentials, and traffic characteristics (such as target system, target port, source IP, source port, network protocol, etc.) to initiate network access credentials (tickets) to the management server.

[0174] If the access is identified as access to sensitive enterprise resources or data based on the dynamic access control policy, in addition to sending process feature information, terminal information, login user information, login credentials, and traffic characteristics to initiate the network access credential (ticket) to the management server, the terminal checks whether the re-authentication ticket for the sensitive system or data access is stored in the local encrypted persistent storage. If it exists, the business management client will also send the re-authentication ticket to the management server to apply for the network access credential (ticket).

[0175] After the management server receives the ticket application request sent by the business management client, it checks whether the re-authentication ticket is expired, and determines whether to normally respond to the ticket based on the current environment and security state information reported by the terminal environment perception, and the historical access information of the access subject (such as access time period, frequency) and the dynamic access control rules specified by the enterprise administrator. The main determination process is as follows:

[0176] (1). The management server first determines whether the target access business system or data is sensitive data based on the dynamic access control policy. If it is, go to step (2); if not, go to step (4).

[0177] (2). The management service end checks whether the re-authentication ticket is legal (whether issued by the management service end, whether the format is correct, whether it is within the valid period), if it is legal and within the valid period, go to step (3), if not, go to step (11).

[0178] (3). The management service end decides whether to pass the access according to the access permission corresponding to the current sensitive system or data in the current time period according to the re-authentication ticket. If it has access permission in the current time period, go to step (4); otherwise, go to step (11).

[0179] (4). The management service end compares the application feature information (such as md5, signature information, application copyright information, etc.) in the ticket application request with the application submission cache. If it is found to be a high-risk application, go to step (5); otherwise, go to step (11).

[0180] (5). The management service end adds the application feature information (such as md5, signature information, application copyright information, etc.) in the ticket application request to the submission queue, and sends the application information in the queue to the threat intelligence cloud query service execution process according to the set strategy. And update the local application submission cache according to the service response result.

[0181] (6). The management service end determines whether the specified application has the permission to access the corresponding business system or data based on the dynamic access control strategy, if it has the permission, go to step (7); otherwise, go to step (11).

[0182] (7). The management service end decides whether to directly pass the access, or needs to adjust the access permission to allow access, or block the access based on the security access strategy, combined with the dynamic factors such as the object operation data, terminal network, security state, terminal environment of the access subject. If it is passed, go to step (9); if it needs to adjust the permission, go to step (8), otherwise, go to step (11).

[0183] (8). The management service end adjusts the correspondence between the re-authentication ticket and the access permission corresponding to the current sensitive system or data.

[0184] (9). The management service end responds to the network access ticket (small ticket) to the client, and specifies the maximum valid time and the maximum number of uses of the small ticket, which is used by the proxy client as the basis for ticket caching, and then goes to step (10).

[0185] (10). The business management client controls the traffic according to the response information of the management service end, if the management service end successfully responds to the network access ticket (small ticket), the business management client forwards the ticket to the proxy client, and the proxy client forwards the traffic and the ticket to the access gateway to execute the actual business proxy client.

[0186] (11). The management service end refuses to respond to the network access ticket (ticket) of the client, and specifies the reason for refusing to respond to the ticket as that the client does not have access permission of the related business system (block) or needs to be verified for access (re-authentication).

[0187] (12). If the management service end fails to successfully respond to the network access ticket (ticket), and the reason for refusing to respond to the ticket is that the client does not have access permission of the related business system (block), the business management client directly sends a traffic blocking command to the proxy client, and the proxy client directly blocks the current traffic without forwarding.

[0188] (13). If the management service end fails to successfully respond to the network access ticket (ticket), and the reason for refusing to respond to the ticket is that the client needs to be verified for access (re-authentication), the business management client directly sends a blocking command to the proxy client, and the proxy client directly blocks the current traffic without forwarding; at the same time, the business management client pops up a related re-authentication interface, reminding the terminal user to verify the identity again before accessing the sensitive business system or data.

[0189] (14). After the terminal user completes the re-authentication operation, the client encrypts and stores the re-authentication ticket responded by the management service end in the local persistent library.

[0190] When the business management client accesses the sensitive business system or data later, the re-authentication ticket is read from the local persistent library, and the re-authentication ticket is taken when applying for a network access ticket to the management service end. The management service end is responsible for checking the validity period and permission of the re-authentication ticket. If the re-authentication ticket is legal and within the validity period set by the administrator, the access to the sensitive business system or data does not need to be re-authenticated repeatedly; if the re-authentication ticket is illegal or not within the validity period, the management service end requires the business management client to re-initiate re-authentication, and the current access session is closed. At the same time, the management service end accesses the related sensitive system or data according to the access permission of the re-authentication ticket. If the permission of the re-authentication ticket is trimmed or adjusted, the access session accesses the business system with the effective permission.

[0191] It should be noted that technical details not described in the above embodiments can refer to the method provided by any embodiment of the present disclosure, which will not be described here.

[0192] The following is an apparatus embodiment of the present disclosure, which can be used to execute the method embodiments of the present disclosure. For details not disclosed in the apparatus embodiments of the present disclosure, please refer to the method embodiments of the present disclosure.

[0193] Please refer to Figure 7FIG. 7 is a structural block diagram of a service data processing apparatus according to an embodiment of the present disclosure. The apparatus has functions in the above method examples, which can be implemented by hardware or corresponding software executed by hardware. The service data processing apparatus can include:

[0194] The first request sending module 710 is configured to initiate a service access request through a target service process in response to a service access event.

[0195] The first obtaining module 720 is configured to, in a case where the service access request is detected to indicate access to a first preset service object, obtain a first access credential matched with the service access request; the first access credential is determined according to dynamic factor data and static factor data of a terminal carrying a service management client.

[0196] The second request sending module 730 is configured to send, to a management server, a first credential obtaining request for indicating obtaining of a second access credential, the first credential obtaining request including the first access credential.

[0197] The second obtaining module 740 is configured to obtain a first credential obtaining result determined by the management server based on the first access credential.

[0198] The processing module 750 is configured to perform service access control on the service access request based on the first credential obtaining result.

[0199] In an optional implementation, the processing module is specifically configured to:

[0200] In a case where the first credential obtaining result indicates re-authentication of the service access event, generate a re-authentication instruction;

[0201] In response to a triggering operation of the re-authentication instruction, generate a third access credential;

[0202] Perform service access control on the service access request based on the third access credential.

[0203] In an optional implementation, the processing module further specifically includes:

[0204] Send, to a management server, a second credential obtaining request for indicating obtaining of a second access credential, the credential obtaining request including the third access credential;

[0205] Obtain a second credential obtaining result determined by the management server based on the third access credential and an access control policy list;

[0206] Perform service access control on the service access request based on the second credential obtaining result.

[0207] In an optional implementation, the processing module is specifically configured to:

[0208] In a case where the first credential acquisition result is used to indicate that the access right of the business access event is adjusted, a target access right after adjustment is acquired;

[0209] A second access credential determined by the management server based on the target access right is acquired;

[0210] Based on the acquired second access credential, the business access request is controlled for business access.

[0211] In an optional implementation, the processing module is specifically configured to:

[0212] In a case where the first credential acquisition result is used to indicate that the access of the business access event is legal, a second access credential determined by the management server is acquired;

[0213] Based on the acquired second access credential, the business access request is controlled for business access; or,

[0214] In a case where the first credential acquisition result is used to indicate that the access of the business access event is illegal, the business access request is controlled to be blocked.

[0215] Please refer to Figure 8 which shows a structural block diagram of a business data processing apparatus provided by an embodiment of the present disclosure. The apparatus has functions in the above method examples, which can be implemented by hardware or corresponding software executed by hardware. The business data processing apparatus can include:

[0216] The first acquisition module 810 is configured to acquire a first credential acquisition request sent by a terminal and used to indicate acquisition of a second access credential, the first credential acquisition request including a first access credential acquired in a case where the business access request is detected to indicate access to a first preset business object, the business access request being sent by a target business process in response to a business access event, and the first access credential being determined according to dynamic factor data and static factor data of the terminal carrying a business management client;

[0217] The result determination module 820 is configured to determine a first credential acquisition result based on the first access credential in the first credential acquisition request;

[0218] The sending module 830 is configured to send the first credential acquisition result, so that the terminal controls the business access request for business access based on the first credential acquisition result.

[0219] In an optional implementation, the apparatus further includes:

[0220] The second obtaining module is configured to obtain network environment data obtained by the terminal in real time;

[0221] The rejection processing module is configured to reject the service access request in a case where the network environment data indicates that a preset access condition is not met.

[0222] In an optional implementation, the result determination module is specifically configured to:

[0223] In a case where the service access request is determined to indicate access to target data, obtain access attribute information of the first access credential, and obtain application feature information corresponding to a service management client corresponding to the service access request;

[0224] Determine the first credential obtaining result based on the access attribute information and the application feature information.

[0225] In an optional implementation, the result determination module is further specifically configured to:

[0226] In a case where the access attribute information meets a first preset condition and the application feature information meets a second preset condition, obtain at least one target access control strategy;

[0227] Determine the first credential obtaining result based on at least one of the target access control strategies and a priority corresponding to each target access control strategy.

[0228] In an optional implementation, the target access control strategy includes a first control strategy indicating re-authentication of the service access event, a second control strategy indicating adjustment of an access right of the service access event, a third control strategy indicating that the service access event is access legal, or a fourth control strategy indicating that the service access event is access illegal.

[0229] The apparatuses provided in the above embodiments can execute the corresponding methods in the embodiments of the present disclosure, and have the corresponding function modules and beneficial effects of executing the methods. Technical details that are not described in detail in the above embodiments can be referred to the methods provided by any of the embodiments of the present disclosure.

[0230] The embodiments of the present disclosure provide a computer device, which can include a processor and a memory. The memory stores at least one instruction, at least one program, a code set, or an instruction set. The at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement the method according to any of the above method embodiments.

[0231] The embodiment of the present disclosure further provides a computer readable storage medium, wherein at least one instruction, at least one program, a code set or an instruction set is stored in the storage medium, and the at least one instruction, the at least one program, the code set or the instruction set is loaded by a processor and the method described in any of the above method embodiments is executed.

[0232] The embodiment of the present disclosure further provides a computer program product or a computer program, which comprises computer instructions stored in a computer readable storage medium. A processor of a computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions, so that the computer device executes any of the above methods.

[0233] Further, Figure 9 A hardware structure schematic diagram of a device for implementing the method provided by the embodiment of the present disclosure is shown, the device can be a computer terminal, a mobile terminal or other device, and the device can also participate in constituting or containing the apparatus provided by the embodiment of the present disclosure. As shown in the figure, Figure 9 The computer terminal 11 can include one or more (in the figure, 112a, 112b, …, 112n are shown) processors 112 (the processor 112 can include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 114 for storing data, and a transmission device 116 for communication function. In addition, it can also include a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the I / O interface), a network interface, a power supply and / or a camera. Those skilled in the art can understand that, Figure 9 The structure shown in the figure is only a schematic, which does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 11 can include more or less components than those shown in the figure, or have a different configuration from that shown in the figure. Figure 9 For example, the computer terminal 11 can include more or less components than those shown in the figure, or have a different configuration from that shown in the figure. Figure 9 For example, the computer terminal 11 can include more or less components than those shown in the figure, or have a different configuration from that shown in the figure.

[0234] It should be noted that the one or more processors 112 and / or other data processing circuits described above can be referred to as "data processing circuits" herein. The data processing circuit can be embodied in whole or in part as software, hardware, firmware or any other combination. In addition, the data processing circuit can be a single independent processing module, or any one of the other elements combined into the computer terminal 11 (or mobile device) in whole or in part. As referred to in the embodiment of the present disclosure, the data processing circuit controls as a kind of processor (for example, the selection of the variable resistance terminal path connected with the interface).

[0235] The memory 114 can be used to store software programs of application software and modules, such as program instructions / data storage means corresponding to the method described in the embodiments of the present disclosure, and the processor 112 can execute various functional applications and data processing, i.e., implement the above-mentioned neural network processing method, by running the software programs and modules stored in the memory 104. The memory 114 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 114 can further include a memory remotely arranged with respect to the processor 112, which can be connected to the computer terminal 11 through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0236] The transmission device 116 is used to receive or send data via a network. Specific examples of the above-mentioned network can include a wireless network provided by a communication provider of the computer terminal 11. In one example, the transmission device 116 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to be able to communicate with the Internet. In one example, the transmission device 116 can be a radio frequency (Radio Frequency, RF) module, which is used to communicate with the Internet in a wireless manner.

[0237] The display can be, for example, a touch screen type liquid crystal display (LCD), which can enable a user to interact with the user interface of the computer terminal 11 (or a mobile device).

[0238] It should be noted that the above-mentioned sequence of the embodiments of the present disclosure is only for description, and does not represent the advantages and disadvantages of the embodiments. The above-mentioned specific embodiments of the present disclosure are described. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from the order in the embodiments and still achieve the desired result. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are possible or can be advantageous.

[0239] The various embodiments in the present disclosure are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device and server embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiment.

[0240] Those skilled in the art can understand that all or part of the steps of the above-mentioned embodiments can be completed by hardware, or can be instructed by a program to complete the related hardware, and the program can be stored in a computer readable storage medium. The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc.

[0241] The above only describes the preferred embodiments of the present disclosure and is not intended to limit the present disclosure. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present disclosure shall be included in the protection scope of the present disclosure.

Claims

1. A service data processing method characterized by, The method comprises: in response to a business access event, initiating a business access request by a target business process; in a case where it is detected that the business access request is used to indicate access to a first preset business object, obtaining a first access credential matched with the business access request; the first access credential comprises access authority and access frequency of an access subject of the business access request for the first preset business object within a specific time; the first access credential is determined according to dynamic factor data and static factor data of a terminal carrying a business management client; the dynamic factor data is network environment data for characterizing the terminal; when it is determined based on the first access credential that a runtime access decision of the terminal meets the requirements, sending a first credential obtaining request used to indicate obtaining a second access credential to a management server, the first credential obtaining request comprising the first access credential, the runtime access decision being determined based on terminal compliance information and network environment results when the terminal initiates the business access request, the second access credential being a temporary access credential for access traffic of the first preset business object through a gateway device; obtaining a first credential obtaining result determined by the management server based on the first access credential and an access control policy list; based on the first credential obtaining result, performing business access control on the business access request.

2. The method of claim 1, wherein, The business access control based on the first credential obtaining result comprises: in a case where the first credential obtaining result is used to indicate re-authentication of the business access event, generating a re-authentication instruction; in response to a triggering operation of the re-authentication instruction, generating a third access credential; based on the third access credential, performing business access control on the business access request.

3. The method of claim 2, wherein, The business access control based on the third access credential comprises: sending a second credential obtaining request used to indicate obtaining a second access credential to a management server, the second credential obtaining request comprising the third access credential; obtaining a second credential obtaining result determined by the management server based on the third access credential and an access control policy list; based on the second credential obtaining result, performing business access control on the business access request.

4. The method according to any of claims 1 to 3, characterized in that, The business access control based on the first credential obtaining result comprises: in a case where the first credential obtaining result is used to indicate adjustment of access authority of the business access event, obtaining a target access authority after adjustment; obtaining a second access credential determined by the management server based on the target access authority; based on the obtained second access credential, performing business access control on the business access request.

5. The method according to any of claims 1 to 3, characterized in that The business access control based on the first credential obtaining result comprises: in a case where the first credential obtaining result is used to indicate access legality of the business access event, obtaining a second access credential determined by the management server; based on the obtained second access credential, performing business access control on the business access request; or In a case where the first credential acquisition result indicates that the access to the service access event is not legal, the service access request is blocked.

6. A service data processing method characterized by comprising: The method comprises: acquiring a first credential acquisition request sent by a terminal when a runtime access decision of the terminal is determined to be qualified based on a first access credential, the first credential acquisition request indicating acquisition of a second access credential, the first credential acquisition request comprising, in a case where a service access request is detected to indicate access to a first preset service object, the acquired first access credential matching the service access request, the service access request being sent by a target service process in response to a service access event, the first access credential comprising access rights and access frequency of an access subject of the service access request to the first preset service object within a specific time; the first access credential being determined based on dynamic factor data and static factor data of the terminal carrying a service management client; the dynamic factor data being network environment data representing the terminal, the runtime access decision being determined based on terminal compliance information and network environment results when the terminal initiates the service access request, the second access credential being a temporary access credential for access traffic of the first preset service object via a gateway device; determining a first credential acquisition result based on the first access credential in the first credential acquisition request and an access control policy list; sending the first credential acquisition result to enable the terminal to perform service access control on the service access request based on the first credential acquisition result.

7. The method of claim 6, wherein, The method further comprises: acquiring network environment data monitored in real time by the terminal; in a case where the network environment data indicates that a preset access condition is not met, rejecting the service access request.

8. The method of claim 6, wherein, The determining of the first credential acquisition result based on the first access credential in the first credential acquisition request and the access control policy list comprises: in a case where it is determined that the service access request indicates access to target data, acquiring access attribute information of the first access credential, and acquiring application feature information corresponding to a service management client corresponding to the service access request; determining a first credential acquisition result based on the access attribute information, the application feature information, and the access control policy list.

9. The method of claim 8, wherein, The determining of the first credential acquisition result based on the access attribute information, the application feature information, and the access control policy list comprises: in a case where the access attribute information meets a first preset condition and the application feature information meets a second preset condition, determining at least one target access control policy from the access control policy list; determining a first credential acquisition result based on at least one target access control policy and a priority corresponding to each target access control policy.

10. The method of claim 9, wherein, The target access control policy comprises a first control policy indicating re-authentication of the service access event, a second control policy indicating adjustment of access rights of the service access event, a third control policy indicating that the access to the service access event is legal, or a fourth control policy indicating that the access to the service access event is not legal.

11. A service data processing apparatus characterized by comprising: The device comprises: A first request sending module is configured to initiate a service access request through a target service process in response to a service access event; A first acquisition module is configured to acquire a first access credential matched with the service access request in a case where it is detected that the service access request is used to indicate access to a first preset service object; the first access credential comprises access authority and access frequency of an access subject of the service access request for the first preset service object within a specific time; the first access credential is determined according to dynamic factor data and static factor data of a terminal carrying a service management client; the dynamic factor data is network environment data used to represent the terminal; A second request sending module is configured to send a first credential acquisition request used to indicate acquisition of a second access credential to a management server when it is determined that a runtime access decision of the terminal meets requirements based on the first access credential; the first credential acquisition request comprises the first access credential; the runtime access decision is determined based on terminal compliance information and network environment results when the terminal initiates the service access request; the second access credential is a temporary access credential of access traffic of the first preset service object accessed through a gateway device; A second acquisition module is configured to acquire a first credential acquisition result determined by the management server based on the first access credential and an access control policy list; A processing module is configured to perform service access control on the service access request based on the first credential acquisition result.

12. A service data processing apparatus characterized by comprising: The device comprises: A first acquisition module is configured to acquire a first credential acquisition request used to indicate acquisition of a second access credential sent by a terminal when it is determined that a runtime access decision of the terminal meets requirements based on a first access credential; the first credential acquisition request comprises the first access credential acquired in a case where it is detected that a service access request is used to indicate access to a first preset service object; the first access credential comprises access authority and access frequency of an access subject of the service access request for the first preset service object within a specific time; the service access request is sent by a target service process in response to a service access event; the first access credential is determined according to dynamic factor data and static factor data of a terminal carrying a service management client; the dynamic factor data is network environment data used to represent the terminal; the runtime access decision is determined based on terminal compliance information and network environment results when the terminal initiates the service access request; the second access credential is a temporary access credential of access traffic of the first preset service object accessed through a gateway device; A result determination module is configured to determine a first credential acquisition result based on the first access credential and an access control policy list in the first credential acquisition request; A sending module is configured to send the first credential acquisition result, so that the terminal performs service access control on the service access request based on the first credential acquisition result.

13. An electronic device, comprising: The electronic device comprises a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the business data processing method according to any one of claims 1-5, or the business data processing method according to any one of claims 6-10.

14. A computer-readable storage medium, characterized in that, The storage medium stores at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the business data processing method according to any one of claims 1-5, or the business data processing method according to any one of claims 6-10.

15. A computer program product, characterised in that, The computer program product comprises at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the business data processing method according to any one of claims 1-5, or the business data processing method according to any one of claims 6-10.

Citation Information

Patent Citations

  • Access certificate verification method and device, computer equipment and storage medium

    CN109992976A

  • Access control method, device and equipment and readable storage medium

    CN112653714A