Firewall mobile client authentication method and system
By loading an SDK into the firewall to generate a QR code, users can scan the code with a mobile client and communicate with the cloud middleware server. This solves the problem of the internal firewall's inability to interact, enabling a convenient and secure authentication process and improving the firewall's authentication efficiency and security.
Patent Information
- Application Number
- CN202310807223.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-03
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2043-07-03
AI Technical Summary
In existing technologies, firewalls located on internal networks cannot interact with other authentication servers, forcing users to rely on traditional authentication methods, which are insecure, inefficient, and negatively impact user experience.
By loading an SDK into the firewall to generate a QR code, users can scan the QR code with their mobile clients. The mobile clients then communicate with the cloud middleware server, which verifies the encrypted data and interactively confirms the user's authentication information. Finally, the firewall completes the authentication process.
It enables users to complete a convenient and secure authentication process through mobile clients, improving the flexibility and security of authentication and enhancing the authentication efficiency of the firewall.
Smart Images

Figure CN116684189B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of firewall authentication technology, specifically to a firewall mobile client authentication method and system. Background Technology
[0002] With the rapid development of information technology, authentication technology has also developed significantly, becoming a primary means of enterprise security protection. Currently, authentication technology is widely used in government, finance, telecommunications, and other industries, and has become an important tool for internet security protection.
[0003] The development trend of authentication technology is towards simplification, intelligence, and enhanced security. Simpler operation methods will be adopted, making authentication faster and more convenient for users. More advanced intelligent technologies will be used, allowing the system to better automatically identify users and improve authentication efficiency. At the same time, further technical improvements will be made to the system's security to enhance its stability.
[0004] Existing firewall authentication methods, such as username / password authentication, require users to remember complex usernames and passwords, and forgetting them may lead to authentication failure. Furthermore, if usernames and passwords are leaked, they could be maliciously used by others, resulting in account theft, firewall privilege breaches, and other security risks. SMS authentication may also lead to account theft and firewall privilege breaches; additionally, due to the limited concurrency capabilities of SMS service providers, SMS sending delays may occur when a large number of users log in simultaneously via SMS, thus affecting user authentication.
[0005] Because the firewall on the internal network cannot interact with other authentication servers, users can only use traditional authentication methods, which are not very secure, have low authentication efficiency, and affect the user experience. Summary of the Invention
[0006] In view of this, the purpose of the present invention is to provide a firewall mobile client authentication method and system to solve the problem in the prior art that, because firewalls located on the intranet cannot interact with other authentication servers, users can only use traditional authentication methods, which result in low security, low authentication efficiency, and a negative impact on user experience.
[0007] According to a first aspect of the present invention, a firewall mobile client authentication method is provided, comprising:
[0008] When a user is detected accessing the firewall authentication interface on the authenticated device, the firewall automatically allows the client authentication domain traffic to pass through, and the authentication interface automatically loads the SDK to generate a QR code containing encrypted data and user authentication information.
[0009] When the user scans the two-dimensional code by using the two-dimensional code scanning function of the mobile client, the mobile client automatically requests communication with the cloud middleware server by using the encrypted communication link generated by the identification and authentication interface, and sends an authentication request containing encrypted data and user authentication information to the cloud middleware server;
[0010] The cloud middleware server verifies the encrypted data, and interacts with the client authentication server to confirm the user authentication information.
[0011] If the verification and confirmation are successful, the cloud middleware server sends the user authentication information to the firewall, so that the firewall completes the authentication process after processing the internal logic according to the user authentication information.
[0012] Preferably, the client is a WeChat client, the client authentication domain name traffic is WeChat authentication domain name traffic, and the client authentication server is a WeChat authentication server.
[0013] Preferably, the method further comprises:
[0014] Obtaining the encrypted data from the firewall and storing the encrypted data in a preset database.
[0015] Obtaining the user authentication information from the WeChat authentication server and storing the user authentication information in a preset database.
[0016] Preferably, the verification of the encrypted data by the cloud middleware server comprises:
[0017] The encrypted data received from the mobile client is verified with the encrypted data stored in the preset database, and if the encrypted data is consistent, the verification is successful.
[0018] Preferably, the completion of the authentication process by the firewall after processing the internal logic comprises:
[0019] The user authentication information sent by the cloud middleware server is obtained by the front end of the firewall, and the user authentication information is sent to the back end of the firewall for login.
[0020] The login information fed back by the back end of the firewall is received.
[0021] Preferably, after receiving the login information fed back by the back end of the firewall, the method further comprises:
[0022] If the login information is login success, the front end of the firewall displays login success.
[0023] The login status is triggered to be checked every preset time, and the login information is updated.
[0024] According to a second aspect of an embodiment of the application, a firewall mobile client authentication system is provided, comprising:
[0025] The firewall in the mobile client, the cloud middleware server, the client authentication server and the authenticated device;
[0026] The firewall in the authenticated device is used for automatically releasing the client authentication domain name traffic to allow the authentication interface to automatically load the SDK to generate a two-dimensional code containing encrypted data and user authentication information when detecting that the user accesses the firewall authentication interface of the authenticated device;
[0027] The mobile client is used for scanning the two-dimensional code to identify the encrypted communication link generated by the authentication interface to automatically request communication with the cloud middleware server and send an authentication request containing encrypted data and user authentication information to the cloud middleware server;
[0028] The cloud middleware server is used for verifying the encrypted data and interacting with the client authentication server to confirm the user authentication information, and if the verification and confirmation are successful, the cloud middleware server sends the user authentication information to the firewall;
[0029] The firewall in the authenticated device is further used for completing the authentication process after processing the internal logic according to the user authentication information.
[0030] The technical scheme provided by the embodiment of the application can include the following beneficial effects:
[0031] It can be understood that the technical scheme shown in the application can allow the firewall to release the client authentication domain name traffic to allow the loading of the SDK to generate a two-dimensional code when the user accesses the firewall authentication interface, allow the mobile client to identify the encrypted communication link generated by the authentication interface to automatically request communication with the cloud middleware server and send an authentication request to the cloud middleware server after the user scans the two-dimensional code by using the mobile client, allow the cloud middleware server to verify the encrypted data and interact with the client authentication server to confirm the user authentication information, and if the verification and confirmation are successful, allow the cloud middleware server to send the user authentication information to the firewall to complete the authentication process after the firewall processes the internal logic. The technical scheme shown in the application can allow the user to authenticate the firewall by using the mobile client, which is more convenient in operation, provides the intermediate layer scheduling authentication of the mobile client, the authentication server and the firewall, realizes the security and convenience of user authentication, and increases the flexibility of the firewall authentication.
[0032] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and cannot limit the application. BRIEF DESCRIPTION OF DRAWINGS
[0033] The accompanying drawings incorporated in the specification and constituting a part hereof illustrate embodiments consistent with the application and, together with the description, serve to explain the principles of the application.
[0034] Figure 1 is a step schematic diagram of a firewall mobile client authentication method according to an example embodiment;
[0035] Figure 2 is a flow schematic diagram of a firewall mobile client authentication method according to an example embodiment. DETAILED DESCRIPTION
[0036] The example embodiments will be described in detail herein with reference to the attached drawings. The following description is made with reference to the accompanying drawings in which like reference numerals refer to like elements, unless the context of use indicates otherwise. The following description of example embodiments is not representative of all embodiments consistent with the present application. Rather, it is merely an example of apparatus and methods consistent with some aspects of the present application as detailed in the appended claims.
[0037] Embodiment One
[0038] Figure 1 is a step schematic diagram of a firewall mobile client authentication method according to an example embodiment, see Figure 1 , a firewall mobile client authentication method is provided, comprising:
[0039] Step S11, when detecting that a user accesses a firewall authentication interface on an authenticated device, the firewall automatically releases client authentication domain name traffic to allow the authentication interface to automatically load SDK to generate a two-dimensional code containing encrypted data and user authentication information;
[0040] Step S12, after the user scans the two-dimensional code using the mobile client two-dimensional code scanning function, the mobile client automatically requests communication with the cloud middleware server using the encrypted communication link generated by the authentication interface, and sends an authentication request containing encrypted data and user authentication information to the cloud middleware server;
[0041] Step S13, the cloud middleware server verifies the encrypted data, and interacts with the client authentication server to confirm the user authentication information;
[0042] Step S14, if the verification is successful and the confirmation is successful, the cloud middleware server sends the user authentication information to the firewall, so that the firewall completes the authentication process after processing the internal logic according to the user authentication information.
[0043] It can be understood that the technical solutions shown in the present application can allow the firewall to load the SDK to generate a two-dimensional code when the user accesses the firewall authentication interface; after the user scans the two-dimensional code using the mobile client, the mobile client identifies the encrypted communication link generated by the authentication interface and automatically requests communication with the cloud middleware server, and sends the authentication request to the cloud middleware server; the cloud middleware server checks the encrypted data, and interacts with the client authentication server to confirm the user authentication information; if the verification is successful and the confirmation is successful, the cloud middleware server sends the user authentication information to the firewall, so that the firewall completes the authentication process after processing the internal logic. The technical solutions shown in the present application can allow the user to authenticate the firewall through the mobile client, which is more convenient in operation, and provides mobile client and authentication server and firewall intermediate layer scheduling authentication, which not only realizes the security and convenience of user authentication, but also increases the flexibility of firewall authentication.
[0044] It should be noted that the client is a WeChat client; the client authentication domain name traffic is a WeChat authentication domain name traffic; and the client authentication server is a WeChat authentication server.
[0045] It can be understood that through the technical solutions provided in this embodiment, the user can directly scan the code to log in to the firewall for authentication through WeChat, which is convenient, fast and safe.
[0046] Figure 2 It is a flowchart of a firewall mobile client authentication method according to an exemplary embodiment, which is shown in FIG. 1. Figure 2 When the user wants to log in to the firewall of the authenticated device, the user first performs code scanning authentication. When the user enters the code scanning authentication in the firewall, the firewall automatically releases the client authentication domain name traffic to allow the authentication interface to automatically load the SDK to generate a two-dimensional code containing encrypted data and user authentication information. Preferably, WeChat authentication can be used to generate iframe (HTML tag) through JSSDK, and the two-dimensional code login logic is nested.
[0047] If the user fails to log in by scanning the code, a prompt information of scanning code login failure will be prompted.
[0048] If the user successfully logs in by scanning the code, the firewall calls back the middleware server. The user uses the two-dimensional code scanning function of the WeChat mobile client to identify the encrypted communication link generated by the authentication interface, and the WeChat client automatically requests the encrypted link to communicate with the middleware server after identification.
[0049] It should be noted that the method further comprises:
[0050] The encrypted data is obtained from the firewall and stored in a preset database;
[0051] Obtain the user authentication information from the WeChat authentication server and store it in a preset database.
[0052] In specific practice, the database stores the openid (unique identification of the user), nickname (user nickname) and user IP of the user authentication information, and encrypted data including source IP, target IP, device SN (serial number) and OEM information.
[0053] After the cloud middleware server obtains the authentication request of the WeChat mobile client, it performs intermediate processing, verifies the encrypted data through the database, and confirms the user authentication information through the WeChat authentication server. It should be noted that the cloud middleware server verifies the encrypted data, including: verifying the encrypted data received from the mobile client with the encrypted data stored in the preset database, if consistent, then the verification is successful. Preferably, when the WeChat authentication server fails to confirm the user authentication information, the related information of the confirmation failure is prompted.
[0054] It should be noted that the firewall completes the authentication process after processing the internal logic, including:
[0055] The firewall front end obtains the user authentication information sent by the cloud middleware server, and sends the user authentication information to the firewall back end for login;
[0056] Receive the login information fed back by the firewall back end.
[0057] In specific practice, after the cloud middleware server verifies successfully and confirms successfully, the firewall is called back and the user authentication information is encrypted and transmitted to the firewall front end, the firewall front end sends the user authentication information to the firewall back end, including issuing a login mark: user type, IP, nickname (user nickname) and openid (unique identification of the user). The firewall back end authenticates and logs in according to the above information, and returns the login information to the firewall front end.
[0058] It should be noted that after receiving the login information fed back by the firewall back end, it also includes:
[0059] If the login information is login success, the firewall front end displays login success;
[0060] Trigger the login status check to the firewall back end every preset time to update the login information.
[0061] In specific practice, if the authentication fails, the related failure information is prompted; if the authentication succeeds, the firewall front end displays login success, and the login status check to the firewall back end can be triggered every 30 seconds to update the login information.
[0062] Embodiment two
[0063] Provided is a firewall mobile client authentication system, comprising:
[0064] a firewall in the mobile client, a cloud middleware server, a client authentication server and an authenticated device;
[0065] The firewall in the authenticated device is used to automatically release the client authentication domain name traffic when detecting that a user accesses the firewall authentication interface in the authenticated device, allowing the authentication interface to automatically load the SDK to generate a two-dimensional code containing encrypted data and user authentication information.
[0066] The mobile client is used to scan the two-dimensional code to identify the encrypted communication link generated by the authentication interface and automatically request communication with the cloud middleware server, and send an authentication request containing encrypted data and user authentication information to the cloud middleware server.
[0067] The cloud middleware server is used to verify the encrypted data, and interact with the client authentication server to confirm the user authentication information; if the verification and confirmation are successful, the cloud middleware server sends the user authentication information to the firewall.
[0068] The firewall in the authenticated device is also used to complete the authentication process after processing the internal logic according to the user authentication information.
[0069] Preferably, the client is a WeChat client; the client authentication domain name traffic is WeChat authentication domain name traffic; and the client authentication server is a WeChat authentication server.
[0070] The present embodiment is based on a WeChat mobile client, and proposes a cloud middleware authentication mechanism. This method contains WeChat authentication Oauth2 (a continuation version of the OAuth protocol) and a firewall self-authentication mechanism, and the middleware server is used for pre-dispatching the firewall user and the WeChat user to bind and verify the identity. The present embodiment not only realizes the mode of using the WeChat mobile client to scan the two-dimensional code and perform identity authentication with the firewall, thereby increasing the operation convenience, but also can perform cloud middleware server scheduling authentication for different multiple firewall devices distributed in different geographical locations.
[0071] It can be understood that the technical solution shown in the embodiment can allow the firewall to load the SDK to generate a two-dimensional code when a user accesses a firewall authentication interface; after the user scans the two-dimensional code using the mobile client, the mobile client identifies the encrypted communication link generated by the authentication interface and automatically requests communication with the cloud middleware server, and sends an authentication request to the cloud middleware server; the cloud middleware server verifies the encrypted data, and interacts with the client authentication server to confirm the user authentication information; if the verification and confirmation are successful, the cloud middleware server sends the user authentication information to the firewall, so that the firewall completes the authentication process after processing the internal logic. The technical solution shown in the embodiment can allow the user to authenticate the firewall through the mobile client, which is more convenient in operation, and provides mobile client and authentication server and firewall intermediate layer scheduling authentication, which not only realizes the security and convenience of user authentication, but also increases the flexibility of firewall authentication.
[0072] It can be understood that the same or similar parts in the above embodiments can be mutually referred to, and the contents not described in detail in some embodiments can be referred to the same or similar contents in other embodiments.
[0073] It should be noted that, in the description of the present application, the terms "first", "second", etc. are only for the purpose of description, and cannot be understood as indicating or implying relative importance. In addition, in the description of the present application, unless otherwise specified, "a plurality of" means at least two.
[0074] Any process or method descriptions in flow charts or otherwise described herein, represent an example of embodiments of the present application that can be implemented as code means of a computer program or code means stored on a computer-readable storage medium. The program or code means can be implemented in a processor or processor arrangement, which performs the functions of the described embodiments.
[0075] It should be understood that the parts of the present application can be realized by hardware, software, firmware or their combination. In the above embodiments, a plurality of steps or methods can be realized by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if realized by hardware, and as in another embodiment, it can be realized by any one or their combination of the following technologies known in the art: discrete logic circuit with logic gate circuit for implementing logic function on data signal, special integrated circuit with suitable combination logic gate circuit, programmable gate array (PGA), field programmable gate array (FPGA) and the like.
[0076] Those skilled in the art can understand that all or part of the steps of the method carried out by the above-mentioned embodiments can be instructed by a program to the relevant hardware, and the program can be stored in a computer readable storage medium. When the program is executed, it includes one of the steps of the method embodiment or a combination thereof.
[0077] In addition, each functional unit in each embodiment of the present application can be integrated into one processing module, or each unit can exist physically independently, or two or more units can be integrated into one module. The integrated module can be realized in the form of hardware or in the form of a software functional module. When the integrated module is realized in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer readable storage medium.
[0078] The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc.
[0079] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example" or "some examples" means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily mean the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0080] Although the embodiments of the present application have been shown and described above, it can be understood that the above-mentioned embodiments are exemplary and cannot be understood as limiting the present application. Those skilled in the art can make changes, modifications, replacements and variations to the above-mentioned embodiments within the scope of the present application.
Claims
1. A firewall mobile client authentication method, characterized by, The application comprises the following steps: When it is detected that a user accesses a firewall authentication interface of an authenticated device, the firewall automatically releases client authentication domain name traffic, allowing the authentication interface to automatically load a two-dimensional code generated by an SDK, which contains encrypted data and user authentication information; After the user scans the two-dimensional code using a mobile client two-dimensional code scanning function, the mobile client identifies an encrypted communication link generated by the authentication interface, automatically requests communication with a cloud middleware server, and sends an authentication request containing encrypted data and user authentication information to the cloud middleware server; The client is a WeChat client, and the client authentication domain name traffic is WeChat authentication domain name traffic. The cloud middleware server verifies the encrypted data, and interacts with a client authentication server to confirm the user authentication information. If the verification and confirmation are successful, the cloud middleware server sends the user authentication information to the firewall, so that the firewall completes the authentication process after processing internal logic according to the user authentication information.
2. The method of claim 1, wherein, The application further comprises the following steps: Obtain the encrypted data from the firewall and store it in a preset database. Obtain user authentication information from the WeChat authentication server and store it in a preset database.
3. The method of claim 2, wherein, The cloud middleware server verifies the encrypted data, including the following steps: Verify the encrypted data received from the mobile client with the encrypted data stored in the preset database. If they are consistent, the verification is successful.
4. The method of claim 2, wherein, The firewall completes the authentication process after processing internal logic, including the following steps: The front end of the firewall obtains the user authentication information sent by the cloud middleware server, sends the user authentication information to the back end of the firewall for login, and receives login information fed back by the back end of the firewall. After receiving the login information fed back by the back end of the firewall, the application further comprises the following steps:
5. The method of claim 4, wherein, If the login information is login success, the front end of the firewall displays login success. Trigger a login status check to the back end of the firewall every preset time, and update the login information. The application comprises the following steps:
6. A firewall mobile client authentication system, characterized by, A mobile client, a cloud middleware server, a client authentication server, and a firewall in an authenticated device. When it is detected that a user accesses a firewall authentication interface of an authenticated device, the firewall automatically releases client authentication domain name traffic, allowing the authentication interface to automatically load a two-dimensional code generated by an SDK, which contains encrypted data and user authentication information. The mobile client scans the two-dimensional code to identify an encrypted communication link generated by the authentication interface, automatically requests communication with a cloud middleware server, and sends an authentication request containing encrypted data and user authentication information to the cloud middleware server. The client is a WeChat client, and the client authentication domain name traffic is WeChat authentication domain name traffic. The cloud middleware server verifies the encrypted data, and interacts with a client authentication server to confirm the user authentication information. If the verification and confirmation are successful, the cloud middleware server sends the user authentication information to the firewall; the client authentication server is a WeChat authentication server. The firewall in the authenticated device also completes the authentication process after processing internal logic according to the user authentication information.
Citation Information
Patent Citations
Mobile Internet hospital secure interaction method
CN104899817A
Two-dimensional code scanning authentication login method and correlation apparatus thereof
CN106936803A