A method of single package authentication and related apparatus

By providing zero-trust client downloads and encrypted knock keys through a one-way ferry gateway, the complexity and security issues of trust connections between endpoints and servers are resolved, improving both user experience and security.

CN116707955BActive Publication Date: 2026-05-29SHENZHEN SHENXIN INFORMATION SECURITY CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN SHENXIN INFORMATION SECURITY CO LTD
Filing Date
2023-06-29
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

The existing process for establishing a trusted connection between endpoints and servers is complex, increasing operational complexity, reducing user experience, and posing security risks.

Method used

The zero-trust client download information and SPA knock key are provided through a one-way ferry gateway. The knock key acquisition request is encrypted with an irreversible algorithm and forwarded directly to the zero-trust server, avoiding local storage and attack risks.

Benefits of technology

It improves the convenience of zero-trust clients and SPA knock keys, enhances the security of single-packet authentication, and avoids security risks after a one-way ferry gateway is attacked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116707955B_ABST
    Figure CN116707955B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a single package authentication method and related device, which are used to improve the convenience of obtaining a zero trust client and an SPA knocking key. The method of the embodiments of the present application comprises: receiving an access address of a zero trust server input by a user through a browser; displaying a download installation page of the zero trust client to the user according to a pointing address of the access address of the zero trust server and download information of the zero trust client; if the user installs the zero trust client, receiving a knocking key obtaining request sent by the zero trust client, wherein the knocking key obtaining request carries a knocking key identifier encrypted by an irreversible algorithm; verifying the knocking key obtaining request; if the verification of the knocking key obtaining request is passed, forwarding the knocking key obtaining request to the zero trust server according to an IP address of the access address of the zero trust server, so that the zero trust server calls a message gateway to send the knocking key to the zero trust client.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network communication technology, and in particular to a method and related apparatus for single-packet authentication. Background Technology

[0002] Software-defined perimeter (SDP), also known as "Black Cloud," is a new computer security approach that evolved from the work done by DISA under the Global Information Grid (GIG) network initiative around 2007. It was later adopted by the Cloud Security Alliance and used by its members.

[0003] SDP requires endpoint authentication and authorization before granting network access to a protected server. Then, an encrypted connection is established in real-time between the requesting system and application infrastructure. SDP hides critical IT assets such as user data and infrastructure within the user's own dark cloud, making these assets invisible to the outside world. Access to these hidden assets requires establishing a trusted connection between the endpoint and the server through SPA (Single Packet Authorization).

[0004] The existing process for establishing a trusted connection between endpoints and servers is as follows:

[0005] 1. The administrator manually notifies the server to enable SPA single package authorization and publishes the server access address, client download, and the address of the third-party system for obtaining the SPA access key;

[0006] 2. Users accessing third-party systems;

[0007] 3. Users download and install the standard client from a third-party system;

[0008] 4. The user applies for an SPA access key in a third-party system. The system calls the server's SPA access key API to obtain the SPA access key, and the server sends the SPA access key to the user.

[0009] 5. The user configures the SPA access key in the client to perform SPA single-package authorization authentication.

[0010] The above process requires administrators to manually notify users of the above information before the SPA single-package authorization authentication is passed, and to independently build a third-party system for client download and SPA access key acquisition, which greatly increases the complexity of operation and maintenance and reduces the user experience. Summary of the Invention

[0011] This invention provides a method and related apparatus for single-packet authentication, which provides users with zero-trust client download information and SPA knock-on keys through a one-way ferry gateway. This improves the convenience of obtaining zero-trust clients and SPA knock-on keys. Furthermore, because the one-way ferry gateway directly forwards the knock-on key acquisition request to the zero-trust server after the knock-on key acquisition request is verified, without performing local storage on the knock-on key acquisition request, it avoids the security risks caused by attacks on the one-way ferry gateway, thus improving the security of the single-packet authentication process.

[0012] The first aspect of this application provides a single-packet authentication method applied to a one-way bypass gateway. The one-way bypass gateway is a one-way non-controlling gateway, and the one-way bypass gateway is configured with the IP address of the zero-trust server access address, the method for obtaining the knock key, and the download information of the zero-trust client. The method includes:

[0013] Receive the access address of the zero-trust server entered by the user through the browser;

[0014] Based on the access address of the zero-trust server and the download information of the zero-trust client, the browser displays the download and installation page of the zero-trust client to the user.

[0015] If the user installs the Zero Trust Client through the download and installation page of the Zero Trust Client, then the Zero Trust Client receives a knock key acquisition request sent by the Zero Trust Client according to the knock key identifier entered by the user and in accordance with the knock key acquisition method, wherein the knock key acquisition request carries a knock key identifier encrypted using an irreversible algorithm.

[0016] The request to obtain the door knocking key is verified;

[0017] If the verification of the door-knocking key acquisition request passes, the door-knocking key acquisition request is forwarded to the zero-trust server according to the IP address of the zero-trust server access address, so that the zero-trust server calls the message gateway to send the door-knocking key to the zero-trust client.

[0018] Preferably, the access address of the zero-trust server points to the domain name of the one-way ferry gateway via a CNAME;

[0019] Based on the address pointed to by the access address of the zero-trust server and the download information of the zero-trust client, the browser displays the download and installation page of the zero-trust client to the user, including:

[0020] Based on the access address and CNAME pointing relationship of the zero-trust server, obtain the pointing address of the access address of the zero-trust server, wherein the pointing address includes the domain name of the one-way ferry gateway;

[0021] Based on the domain name of the one-way ferry gateway and the download information of the zero-trust client, the browser displays the download and installation page of the zero-trust client to the user.

[0022] Preferably, when displaying the download and installation page of the zero-trust client to the user through the browser, the method further includes:

[0023] The IP address of the Zero Trust server access address is embedded into the Zero Trust client installation package, so that after the user installs the Zero Trust client, the Zero Trust client automatically fills in the access address of the Zero Trust server and the IP address of the Zero Trust server access address.

[0024] Preferably, the one-way ferry gateway is also configured with a zero-trust server authentication method. Before displaying the download and installation page of the zero-trust client to the user through the browser, the method further includes:

[0025] The access prompt is displayed to the user according to the authentication method of the zero-trust server, wherein the access prompt is used to inform the user that the access address of the zero-trust server has enabled single packet authentication.

[0026] Preferably, the verification of the knock key acquisition request includes:

[0027] The message requesting the door key is subjected to rate limiting and frequency limiting calculation and format verification. The format verification includes at least one of message format verification, message length verification and message content verification.

[0028] Preferably, the one-way transfer gateway is set in the cloud or in the local network, and the one-way transfer gateway is a whitelist of the zero-trust server.

[0029] Preferably, the knock key identifier includes a terminal identification code, an email identification code, or a QR code identification code.

[0030] A second aspect of this application provides a single-packet authentication method applied to a zero-trust server, the method comprising:

[0031] Receive a knock key acquisition request sent by a one-way ferry gateway, wherein the knock key acquisition request carries a knock key identifier encrypted using an irreversible algorithm;

[0032] The request to obtain the door knocking key is message verified;

[0033] If the message for requesting the door knock key passes verification, then the user account is checked for a network security incident based on the correspondence between the encrypted door knock key identifier and the user account stored in the database in advance.

[0034] If the user account does not have a network security incident, the message gateway is invoked to send a knock key to the zero-trust client;

[0035] Receive a single-packet authorization and authentication request sent by the zero-trust client, wherein the single-packet authorization and authentication request includes at least a zero-trust client identifier and a user identifier encrypted using the knock key and a preset algorithm;

[0036] Perform a validity check on the single-package authorization authentication request;

[0037] If the single-packet authorization authentication request passes the verification, the zero-trust server port and / or business service are sent to the zero-trust client, enabling the user to access the zero-trust server port and / or business service through the zero-trust client.

[0038] Preferably, the step of performing a validity check on the single-package authorization authentication request includes:

[0039] Perform at least one of the following on the single-packet authorization authentication request: replay verification, forgery verification, user identification code verification, and client identification code verification.

[0040] A third aspect of this application provides a one-way ferry gateway, characterized in that the one-way ferry gateway is a one-way non-controlling gateway, and the one-way ferry gateway is configured with the IP address of the zero-trust server access address, the method for obtaining the knock key, and the download information of the zero-trust client. The one-way ferry gateway includes:

[0041] The first receiving unit is used to receive the access address of the zero-trust server input by the user through a browser;

[0042] The display unit is used to display the download and installation page of the zero-trust client to the user through the browser based on the access address of the zero-trust server and the download information of the zero-trust client;

[0043] The first receiving unit is further configured to receive a knock key acquisition request sent by the zero trust client according to the knock key identifier input by the user and in accordance with the knock key acquisition method if the user installs the zero trust client according to the download and installation page of the zero trust client. The knock key acquisition request carries a knock key identifier encrypted with an irreversible algorithm.

[0044] The first verification unit is used to verify the request to obtain the door knocking key;

[0045] The forwarding unit is used to forward the request to the zero-trust server according to the IP address of the zero-trust server access address if the verification of the request to obtain the knock key passes, so that the zero-trust server can call the message gateway to send the knock key to the zero-trust client.

[0046] A fourth aspect of this application provides a zero-trust server, the zero-trust server comprising:

[0047] The second receiving unit is used to receive a knock key acquisition request sent by the one-way ferry gateway, wherein the knock key acquisition request carries a knock key identifier encrypted with an irreversible algorithm.

[0048] The second verification unit is used to verify the message format of the door knocking key acquisition request.

[0049] The second verification unit is further configured to, if the format verification of the request to obtain the door key passes, verify whether the user account has a network security incident based on the correspondence between the encrypted door key identifier and the user account stored in the database in advance;

[0050] The calling unit is used to call the message gateway to send a knock key to the zero-trust client if the user account does not have a network security event.

[0051] The second receiving unit is further configured to receive a single-packet authorization and authentication request sent by the zero-trust client, wherein the single-packet authorization and authentication request includes at least a zero-trust client identifier and a user identifier encrypted using the knock key and a preset algorithm;

[0052] The second verification unit is also used to perform a legality verification on the single-packet authorization authentication request;

[0053] The sending unit is configured to send the zero-trust server port and / or business service to the zero-trust client if the verification of the single-packet authorization authentication request passes, so that the user can access the zero-trust server port and / or business service through the zero-trust client.

[0054] The fifth aspect of this application provides a single-package authentication system, including:

[0055] Browser, zero-trust client, message gateway, and the one-way ferry gateway provided in the third aspect of the embodiments of this application and the zero-trust server provided in the fourth aspect of the embodiments of this application.

[0056] A sixth aspect of this application provides a computer device including a processor, which, when executing a computer program stored in a memory, implements the single-packet authentication method provided in the first or second aspect of this application.

[0057] A seventh aspect of this application provides a computer-readable storage medium having a computer program stored thereon. When executed by a processor, the computer program is used to implement a method for implementing single-packet authentication provided in the first or second aspect of this application.

[0058] As can be seen from the above technical solutions, the embodiments of the present invention have the following advantages:

[0059] In this embodiment, a one-way ferry gateway is introduced. This one-way ferry gateway can only send requests in a preset format to the zero-trust server, and the server will not send a response packet. That is, the server responds to the one-way ferry gateway with zero response, thereby preventing attackers from attacking the server through the one-way ferry gateway. In other words, the one-way ferry gateway does not change the security of the server's single-packet authorization authentication. In addition, the knock key acquisition request sent by the zero-trust client to the one-way ferry gateway is encrypted using an irreversible algorithm. Therefore, the one-way ferry gateway is a minimal, zero-leakage gateway with no data residue, further ensuring the security of the one-way ferry gateway. Attached Figure Description

[0060] Figure 1 This is a schematic diagram of one embodiment of the single-packet authentication method in this application.

[0061] Figure 2 This is a schematic diagram of a client that obtains a knock key using a knock key identifier in an embodiment of this application;

[0062] Figure 3 This is a schematic diagram of another embodiment of the single-packet authentication method in this application;

[0063] Figure 4 This is a schematic diagram of one embodiment of the unidirectional shuttle gateway in this application.

[0064] Figure 5 This is a schematic diagram of one embodiment of the zero-trust server in this application.

[0065] Figure 6 This is a schematic diagram of one embodiment of the single-package authentication system in this application. Detailed Implementation

[0066] This invention provides a method and related apparatus for single-packet authentication, which provides users with zero-trust client download information and SPA knock-on keys through a one-way ferry gateway. This improves the convenience of obtaining zero-trust clients and SPA knock-on keys. Furthermore, because the one-way ferry gateway directly forwards the knock-on key acquisition request to the zero-trust server after the knock-on key acquisition request is verified, without performing local storage on the knock-on key acquisition request, it avoids the security risks caused by attacks on the one-way ferry gateway, thus improving the security of the single-packet authentication process.

[0067] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0068] The terms "first," "second," "third," "fourth," etc., used in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0069] For ease of understanding, the technical terms used in the embodiments of this application will be described below:

[0070] 1. Zero Trust: A security concept of "never trust, always verify" and has developed into a security framework of "identity-centric, continuous trust assessment, and dynamic access control". The mainstream technologies for implementation include three types: Software-Defined Boundary (SDP), Unified Identity Management (IAM), and Micro-Segmentation (MSG). The "zero trust" concept in this invention specifically refers to SDP products.

[0071] 2. Software-Defined Perimeter (SDP): Before accessing hidden assets, a trusted connection needs to be established through SPA single-package authorization, and the least privilege policy is used to implement access control for users. It consists of three main components: the SDP control center and proxy gateway (hereinafter referred to as the "server"), and the SDP connection initiating host (hereinafter referred to as the "client").

[0072] 3. SPA Single Packet Authorization: The client sends an authentication request to the server by carrying authentication information in a single data packet. Before the authentication is successful, the client cannot or can only establish a TCP connection, thus it cannot access the services provided by the server. Only after the authentication is successful is it allowed to establish a connection with the relevant services of the server.

[0073] 4. SPA Door Key: Authentication and identification information used in the SPA single-package authorization process.

[0074] 5. Identity Authentication: This typically refers to confirming a user's identity through one or more methods. In this invention, the concept of "identity authentication" specifically refers to the server-side authentication service that allows access only after SPA single-package authorization authentication; that is, SPA single-package authorization is not considered an identity authentication service in this invention.

[0075] 6. One-way ferry gateway: An intermediate server that exchanges and transmits data between the client and the server.

[0076] 7. Message Gateway: A message server that transmits the SPA knock key from the server to the user, used to implement out-of-band key management.

[0077] The single-packet authentication method in this application embodiment is described below from an interactive perspective. Please refer to [link / reference]. Figure 1 The single-packet authentication system in this embodiment includes at least a browser, a one-way gateway, a zero-trust client, and a zero-trust server. The one-way gateway in this embodiment is a one-way non-controlling gateway, and the administrator pre-registers the IP address of the zero-trust server access address, the method for obtaining the knock key, and the download information of the zero-trust client on the one-way gateway. The method for obtaining the knock key can be that the browser sends a knock key acquisition request to the one-way gateway carrying a knock key identifier, or the browser sends a knock key acquisition request to the one-way gateway carrying a terminal identification code and an email identification code, or the browser sends a knock key acquisition request to the one-way gateway by scanning a QR code with the terminal, etc. There are no specific restrictions on the method for obtaining the knock key here. The download information of the zero-trust client at least includes the download method of the zero-trust client to facilitate users in downloading and installing the zero-trust client.

[0078] One embodiment of single-package authorization authentication in this application includes:

[0079] 101. Receive the access address of the zero-trust server input by the user through the browser;

[0080] If a user wants to access network resources, they generally do so through a network domain name. For example, to access a search server, they can enter "www.baidu.com" in their browser, while to access Taobao, they can enter "www.tmall.com". In this embodiment of the application, to access a zero-trust server, the user can enter the access address of the zero-trust server in their browser, where the access address includes the domain name of the zero-trust server.

[0081] 102. The one-way transfer gateway displays the download and installation page of the zero-trust client to the user through the browser based on the address pointed to by the access address of the zero-trust server and the download information of the zero-trust client;

[0082] Before accessing the Zero Trust server, users typically need to send an authentication request to the Zero Trust server via a single data packet containing authentication information through the Zero Trust client. Before successful authentication, a TCP connection cannot be established, or can only be established, thus preventing access to the services provided by the Zero Trust server. Only after successful authentication is a connection to the Zero Trust server's services allowed.

[0083] Unlike existing technologies that require obtaining the zero-trust client and knock key through a third-party system, this application embodiment sets up a one-way ferry gateway and points the access address of the zero-trust server to the domain name of the one-way ferry gateway through CNAME. Therefore, in this application embodiment, after the user enters the access address of the zero-trust server through a browser, the access address of the zero-trust server is analyzed by a DNS server to obtain the address pointed to by the access address of the zero-trust server, that is, the domain name of the one-way ferry gateway.

[0084] When the one-way transfer gateway receives a user's access request, it displays the download and installation page of the zero-trust client to the user through a browser based on the download information of the pre-registered zero-trust client.

[0085] 103. Download and install the client;

[0086] Once the browser displays the Zero Trust client download and installation page to the user, the user downloads and installs the Zero Trust client according to the download information on the page. This download information includes download addresses for different versions of the Zero Trust client and identifiers for each version. As long as the user can complete the download and installation of the Zero Trust client based on this information, there are no specific restrictions on the content of the Zero Trust client download and installation page.

[0087] 104. The zero-trust client sends a knock key acquisition request to the one-way ferry gateway according to the knock key acquisition method based on the knock key identifier input by the user. The knock key acquisition request carries a knock key identifier encrypted with an irreversible algorithm.

[0088] Specifically, after downloading and installing the Zero Trust client, the user can enter the access address of the Zero Trust server on the client's page and obtain the knock key according to the preset method for obtaining the knock key on the one-way ferry gateway. Furthermore, to improve user convenience, the Zero Trust client in this embodiment can automatically fill in the knock key identifier on the Zero Trust client page after the user downloads and installs the Zero Trust client.

[0089] If the one-way transfer gateway is configured to obtain the knock key via a knock key identifier, the user needs to enter the knock key identifier in the client and then click the "Get Knock Key" button to obtain the knock key. For ease of understanding... Figure 2 A schematic diagram of a client obtaining a knock key using a knock key identifier is provided.

[0090] Furthermore, in order to minimize and anonymize the information transmitted by the one-way ferry gateway, in this embodiment of the application, when the zero-trust client sends a request to obtain the knock key, the knock key identifier in the request is encrypted using an irreversible algorithm, such as a hash algorithm. This minimized and anonymized transmission information can prevent the one-way ferry gateway from being controlled by an attacker and then accessing the server without authorization or sending illegal data to attack the server.

[0091] 105. The one-way transfer gateway verifies the request to obtain the door knocking key;

[0092] After receiving a request to obtain the key from a zero-trust client, the one-way ferry gateway verifies the request.

[0093] Specifically, when the one-way ferry gateway verifies the request to obtain the door knock key, it may perform rate limiting and frequency limiting calculations and format verification. The format verification includes, but is not limited to, the message format, message content, and message length of the request.

[0094] Once the one-way ferry gateway receives the request, it first checks whether the header and footer of the message are consistent with the pre-set requirements, that is, it verifies the message format. The message content verification can be done by checking whether the preset position in the message contains the time number, and the message length verification is based on the preset settings. For example, if the message length is 24 characters, the message length is verified based on the preset 24 characters.

[0095] Furthermore, rate limiting calculation means that the one-way ferry gateway only accepts a preset number (e.g., 30) of key retrieval requests at a time, and does not respond to any requests exceeding 30. Frequency limiting calculation means that the one-way ferry gateway receives a limited number of key retrieval requests per unit time (e.g., 15). When the number of key retrieval requests sent to the one-way ferry gateway per unit time exceeds 15, the one-way ferry gateway will not respond to any requests beyond the 15th, thus further reducing the possibility of the one-way ferry gateway being attacked, and thus further improving the security of the one-way ferry gateway.

[0096] 106. If the verification of the door knocking key acquisition request passes, the one-way ferry gateway forwards the door knocking key acquisition request to the zero-trust server according to the IP address of the zero-trust server access address.

[0097] If the one-way transfer gateway verifies the knock key acquisition request sent by the zero-trust client, the one-way transfer gateway forwards the knock key acquisition request to the zero-trust server according to the IP address of the zero-trust server access address, so that the zero-trust server and the zero-trust client can interact.

[0098] Because the one-way ferry gateway directly forwards the door key retrieval request to the zero-trust server instead of storing the door key retrieval request locally, it further prevents information leakage caused by the one-way ferry gateway being controlled by an attacker.

[0099] 107. The zero-trust server performs message verification on the request to obtain the door knock key;

[0100] After receiving the knock key retrieval request sent by the one-way ferry gateway, the zero-trust server verifies the knock key message, which includes verifying the message format, message content, and message length.

[0101] The verification process for message format, message content, and message length is similar to that described in step 105, and will not be repeated here.

[0102] 108. If the message verification passes, the zero-trust server verifies whether the user account has been involved in a network security incident based on the correspondence between the encrypted knock key identifier and the user account stored in the database in advance.

[0103] If the Zero Trust server verifies the message of the request to obtain the door key, it further verifies whether the user account has been involved in a network security incident based on the correspondence between the encrypted door key identifier and the user account stored in the database in advance. That is, it verifies whether the owner of the user account has launched a network attack on the Zero Trust server or caused a security incident to the Zero Trust server.

[0104] It is easy to understand that the database pre-stores the correspondence between user accounts, encrypted knock key identifiers, knock keys and user accounts, and the correspondence between user accounts, encrypted knock key identifiers, knock keys and user accounts is generally one-to-one.

[0105] 109. If the user account does not have a network security incident, then the message gateway is invoked to send a knock key to the zero-trust client;

[0106] If the Zero Trust server verifies that there is no network security incident in the user account, it will further call the message gateway to send the knock key to the Zero Trust client. The message gateway here is the message server that sends the knock key from the Zero Trust server to the Zero Trust client, and is used to implement out-of-band management of the knock key.

[0107] 110. The zero-trust client sends a single-packet authorization and authentication request to the zero-trust server. The single-packet authorization and authentication request includes at least the zero-trust client identifier and the user identifier encrypted using the knock key and prediction algorithm.

[0108] After receiving the knock key sent by the message gateway, the zero-trust client encrypts the zero-trust client identifier and user identifier using the message key and a prediction algorithm (such as the national cryptographic algorithm). Then, it sends the encrypted zero-trust client identifier and user identifier to the zero-trust server for single-packet authorization authentication. This single-packet authorization authentication is used to request the establishment of a communication connection between the client and the zero-trust server at the application layer.

[0109] 111. The zero-trust server performs a validity check on single-package authorization authentication requests;

[0110] After receiving a single-packet authorization authentication request sent by the Zero Trust client, the Zero Trust server verifies the legality of the authorization authentication request. The legality verification includes at least one of the following: replay verification, forgery verification, user identification code verification, and client identification code verification.

[0111] Specifically, replay verification checks whether the single-packet authorization authentication request is a single-packet authorization authentication request that has been received by the zero-trust server and sent by other zero-trust clients. Forgery verification checks whether the single-packet authorization authentication request has been tampered with. User ID code verification and client ID code verification check whether the user ID code and client ID code exist in the database, respectively.

[0112] 112. If the verification of the single-package authorization authentication request passes, the zero-trust server port and / or business service are sent to the zero-trust client.

[0113] If the zero-trust server verifies the single-packet authorization authentication request, it sends the zero-trust server port and / or business service to the zero-trust client, enabling the user to access the zero-trust server port and / or business service through the zero-trust client. This establishes a communication connection between the zero-trust client and the zero-trust server at the application layer.

[0114] In this embodiment, a one-way ferry gateway is introduced. This one-way ferry gateway can only send requests in a preset format to the zero-trust server, and the server will not send a response packet. That is, the server responds to the one-way ferry gateway with zero response, thereby preventing attackers from attacking the server through the one-way ferry gateway. In other words, the one-way ferry gateway does not change the security of the server's single-packet authorization authentication. In addition, the knock key acquisition request sent by the zero-trust client to the one-way ferry gateway is encrypted using an irreversible algorithm. Therefore, the one-way ferry gateway is a minimal, zero-leakage gateway with no data residue, further ensuring the security of the one-way ferry gateway.

[0115] based on Figure 1 In the aforementioned embodiments, to further optimize the user experience, the authentication method of the zero-trust server can be configured on the one-way transfer gateway (e.g., the zero-trust server uses single-packet authorization authentication). This allows the one-way transfer gateway to display an access prompt to the user before showing the download and installation page of the zero-trust client through the browser. This access prompt is used to remind the user that the zero-trust server has enabled single-packet authentication, thereby guiding the user to download and install the zero-trust client through the download and installation page, thus improving the user's experience with the zero-trust server service.

[0116] Furthermore, in order to accelerate the communication process between the one-way ferry gateway and the zero-trust server, the one-way ferry gateway can also be set as a whitelist of the zero-trust server. The one-way ferry gateway in this application embodiment can be set in the cloud or on the local network. There are no specific restrictions on the setting environment of the one-way ferry gateway.

[0117] based on Figure 1 The embodiments described above will be followed by a description of the single-package authorization and authentication method in the embodiments of this application. Please refer to [link to relevant documentation]. Figure 3 Another embodiment of the single-packet authentication method in this application includes:

[0118] 301. Receive the access address of the zero-trust server input by the user through the browser;

[0119] 302. The one-way transfer gateway displays the download and installation page of the zero-trust client to the user through the browser based on the address pointed to by the access address of the zero-trust server and the download information of the zero-trust client;

[0120] 303. Download and install the client;

[0121] Once the browser displays the Zero Trust client download and installation page to the user, the user downloads and installs the Zero Trust client according to the download information on the page. This download information includes download addresses for different versions of the Zero Trust client and identifiers for each version. As long as the user can complete the download and installation of the Zero Trust client based on this information, there are no specific restrictions on the content of the Zero Trust client download and installation page.

[0122] 304. The zero-trust client sends a knock key acquisition request to the one-way ferry gateway according to the knock key acquisition method based on the knock key identifier input by the user. The knock key acquisition request carries a knock key identifier encrypted with an irreversible algorithm.

[0123] 305. The one-way transfer gateway verifies the request to obtain the door knocking key;

[0124] 306. If the verification of the door knocking key acquisition request passes, the one-way ferry gateway forwards the door knocking key acquisition request to the zero-trust server according to the IP address of the zero-trust server access address.

[0125] 307. The zero-trust server performs message verification on the request to obtain the door knock key;

[0126] 308. If the message verification passes, the zero-trust server verifies whether the user account has been involved in a network security incident based on the correspondence between the encrypted knock key identifier and the user account stored in the database in advance.

[0127] 309. If the user account does not have a network security incident, then the message gateway is invoked to send a knock key to the zero-trust client;

[0128] 310. The zero-trust client sends a single-packet authorization and authentication request to the zero-trust server. The single-packet authorization and authentication request includes at least the zero-trust client identifier and the user identifier encrypted using a knock key and a prediction algorithm.

[0129] 311. The zero-trust server performs a validity check on single-package authorization authentication requests;

[0130] 312. If the verification of the single-package authorization authentication request passes, the zero-trust server sends the zero-trust server port and / or business service to the zero-trust client.

[0131] It should be noted that steps 301 to 312 above are the same as... Figure 1The steps 101 to 112 in the embodiments are described similarly and will not be repeated here.

[0132] 313. The zero-trust client sends an authentication request to the zero-trust server;

[0133] Different from Figure 1 In the described embodiment, after the zero-trust server completes single-packet authorization authentication for the zero-trust client, it directly establishes an application-layer communication connection with the zero-trust client.

[0134] In this embodiment of the application, after the Zero Trust server completes the single-packet authorization authentication of the Zero Trust client, it continues to perform identity authentication on the Zero Trust client, that is, the Zero Trust server receives the identity authentication request sent by the Zero Trust client.

[0135] The authentication request can be a verification of username and password, or an authentication of a dynamic password on the terminal (such as sending a dynamic verification code via mobile phone). There are no specific restrictions on the authentication request process here.

[0136] 314. The Zero Trust server verifies the identity authentication request. If the verification passes, it sends a fixed knock key to the Zero Trust client.

[0137] The zero-trust server verifies the client's authentication request. If the verification passes, it sends a fixed knock key to the zero-trust client.

[0138] 315. Zero-trust clients use a fixed knock key to perform single-packet authorization authentication with the zero-trust server.

[0139] After receiving the fixed knock key, the zero-trust client persists the knock key locally and binds it with the zero-trust client's feature code (such as an identification code), thereby improving the convenience of the user's subsequent single-packet authorization and authentication process between the zero-trust client and the zero-trust server.

[0140] In this embodiment of the application, in order to further improve the security of communication between the zero-trust client and the zero-trust server, after the zero-trust server completes the single-packet authorization authentication of the zero-trust client, it further performs identity authentication on the zero-trust client, and after the identity authentication of the zero-trust client is successful, it sends a fixed knock key to the zero-trust client, thereby improving the convenience of the subsequent single-packet authorization authentication process between the zero-trust client and the zero-trust server.

[0141] The single-packet authentication method in the embodiments of this application has been described in detail above. The following describes the unidirectional ferry gateway in the embodiments of this application. This unidirectional ferry gateway is a unidirectional non-controlling gateway, and it is configured with the IP address of the zero-trust server access address, the method for obtaining the knock key, and the download information for the zero-trust client. Please refer to [link / reference]. Figure 4 One embodiment of the unidirectional shuttle gateway in this application includes:

[0142] The first receiving unit 401 is used to receive the access address of the zero-trust server input by the user through a browser;

[0143] Display unit 402 is used to display the download and installation page of the zero-trust client to the user through the browser based on the access address of the zero-trust server and the download information of the zero-trust client;

[0144] The first receiving unit 401 is further configured to receive a knock key acquisition request sent by the zero trust client according to the knock key identifier input by the user and in accordance with the knock key acquisition method if the user installs the zero trust client according to the download and installation page of the zero trust client. The knock key acquisition request carries a knock key identifier encrypted with an irreversible algorithm.

[0145] The first verification unit 403 is used to verify the door knocking key acquisition request;

[0146] The forwarding unit 404 is used to forward the door key acquisition request to the zero-trust server according to the IP address of the zero-trust server access address if the verification of the door key acquisition request passes, so that the zero-trust server calls the message gateway to send the door key to the zero-trust client.

[0147] Preferably, the access address of the zero-trust server points to the domain name of the one-way ferry gateway via a CNAME, and the display unit 402 is specifically used for:

[0148] Based on the access address and CNAME pointing relationship of the zero-trust server, obtain the pointing address of the access address of the zero-trust server, wherein the pointing address includes the domain name of the one-way ferry gateway;

[0149] Based on the domain name of the one-way ferry gateway and the download information of the zero-trust client, the browser displays the download and installation page of the zero-trust client to the user.

[0150] Preferably, the unidirectional shuttle gateway further includes an embedded unit 405, used for:

[0151] The IP address of the Zero Trust server access address is embedded into the Zero Trust client installation package, so that after the user installs the Zero Trust client, the Zero Trust client automatically fills in the access address of the Zero Trust server and the IP address of the Zero Trust server access address.

[0152] Preferably, the one-way ferry gateway is also configured with a zero-trust server authentication method, and the display unit 402 is also used for:

[0153] The access prompt is displayed to the user according to the authentication method of the zero-trust server, wherein the access prompt is used to inform the user that the access address of the zero-trust server has enabled single packet authentication.

[0154] Preferably, the first verification unit 403 is specifically used for:

[0155] The message requesting the door key is subjected to rate limiting and frequency limiting calculation and format verification. The format verification includes at least one of message format verification, message length verification and message content verification.

[0156] Preferably, the one-way transfer gateway is set up in the cloud or on the local network, and the one-way transfer gateway is a whitelist of the zero-trust server.

[0157] Preferably, the knock key identifier includes a terminal identification code, an email identification code, or a QR code identification code.

[0158] It should be noted that the functions of the above-mentioned units are the same as... Figures 1 to 2 The examples described are similar and will not be repeated here.

[0159] In this embodiment, a one-way ferry gateway is introduced. The forwarding unit 404 of the one-way ferry gateway can only send requests in a preset format to the zero-trust server, and the server will not send a response packet. That is, the server responds to the one-way ferry gateway with zero response, thereby preventing attackers from attacking the server through the one-way ferry gateway. In other words, the one-way ferry gateway does not change the security of the server's single-packet authorization authentication. In addition, the knock key acquisition request sent by the zero-trust client to the one-way ferry gateway is encrypted using an irreversible algorithm. Therefore, the one-way ferry gateway is a minimal, zero-leakage gateway with no data residue, further ensuring the security of the one-way ferry gateway.

[0160] The zero-trust server in this application embodiment is described below. Please refer to... Figure 5 One embodiment of the zero-trust server in this application includes:

[0161] The second receiving unit 501 is used to receive a knock key acquisition request sent by the one-way ferry gateway, wherein the knock key acquisition request carries a knock key identifier encrypted with an irreversible algorithm.

[0162] The second verification unit 502 is used to verify the message format of the door knocking key acquisition request;

[0163] The second verification unit 502 is further configured to, if the format verification of the knock key acquisition request passes, verify whether the user account has a network security incident based on the correspondence between the encrypted knock key identifier and the user account stored in the database in advance;

[0164] Calling unit 503 is used to call the message gateway to send a knock key to the zero-trust client if the user account does not have a network security event.

[0165] The second receiving unit 501 is further configured to receive a single-packet authorization authentication request sent by the zero-trust client, wherein the single-packet authorization authentication request includes at least a zero-trust client identifier and a user identifier encrypted using the knock key and a preset algorithm;

[0166] The second verification unit 502 is also used to perform a legality verification on the single-packet authorization authentication request;

[0167] The sending unit 504 is configured to send the zero-trust server port and / or business service to the zero-trust client if the verification of the single-packet authorization authentication request passes, so that the user can access the zero-trust server port and / or business service through the zero-trust client.

[0168] Preferably, the second verification unit 502 is specifically used for:

[0169] Perform at least one of the following on the single-packet authorization authentication request: replay verification, forgery verification, user identification code verification, and client identification code verification.

[0170] The single-packet authentication system in the embodiments of this application will be described below. Please refer to [link / reference]. Figure 6 The single-packet authentication system in this application embodiment includes:

[0171] The system comprises a browser, a zero-trust client, a message gateway, a one-way transfer gateway, and a zero-trust server. The interaction flow between these components and the role of each are described. Figures 1 to 3 Similar to the descriptions in the text, it will not be repeated here.

[0172] The unidirectional ferry gateway and zero-trust server in the embodiments of the present invention have been described above from the perspective of modular functional entities. The computer device in the embodiments of the present invention is described below from the perspective of hardware processing:

[0173] This computer device is used to implement the functions of one side of a one-way shuttle gateway. One embodiment of the computer device in this invention includes:

[0174] Processor and memory;

[0175] When a memory is used to store computer programs, and a processor executes the computer programs stored in the memory, the following steps can be achieved:

[0176] Receive the access address of the zero-trust server entered by the user through the browser;

[0177] Based on the access address of the zero-trust server and the download information of the zero-trust client, the browser displays the download and installation page of the zero-trust client to the user.

[0178] If the user installs the Zero Trust Client through the download and installation page of the Zero Trust Client, then the Zero Trust Client receives a knock key acquisition request sent by the Zero Trust Client according to the knock key identifier entered by the user and in accordance with the knock key acquisition method, wherein the knock key acquisition request carries a knock key identifier encrypted using an irreversible algorithm.

[0179] The request to obtain the door knocking key is verified;

[0180] If the verification of the door-knocking key acquisition request passes, the door-knocking key acquisition request is forwarded to the zero-trust server according to the IP address of the zero-trust server access address, so that the zero-trust server calls the message gateway to send the door-knocking key to the zero-trust client.

[0181] In some embodiments of the present invention, the access address of the zero-trust server points to the domain name of the one-way ferry gateway via a CNAME. The processor can also be used to implement the following steps:

[0182] Based on the access address and CNAME pointing relationship of the zero-trust server, obtain the pointing address of the access address of the zero-trust server, wherein the pointing address includes the domain name of the one-way ferry gateway;

[0183] Based on the domain name of the one-way ferry gateway and the download information of the zero-trust client, the browser displays the download and installation page of the zero-trust client to the user.

[0184] In some embodiments of the present invention, the processor may also be used to implement the following steps:

[0185] The IP address of the Zero Trust server access address is embedded into the Zero Trust client installation package, so that after the user installs the Zero Trust client, the Zero Trust client automatically fills in the access address of the Zero Trust server and the IP address of the Zero Trust server access address.

[0186] In some embodiments of the present invention, the one-way ferry gateway is further configured with a zero-trust server authentication method. Before displaying the download and installation page of the zero-trust client to the user through the browser, the processor can also be used to implement the following steps:

[0187] The access prompt is displayed to the user according to the authentication method of the zero-trust server, wherein the access prompt is used to inform the user that the access address of the zero-trust server has enabled single packet authentication.

[0188] In some embodiments of the present invention, the processor may also be used to implement the following steps:

[0189] The message requesting the door key is subjected to rate limiting and frequency limiting calculation and format verification. The format verification includes at least one of message format verification, message length verification and message content verification.

[0190] In some embodiments of the present invention, the one-way ferry gateway is set in the cloud or in the local network, and the one-way ferry gateway is a whitelist of the zero-trust server.

[0191] In some embodiments of the present invention, the door knock key identifier includes a terminal identification code, an email identification code, or a QR code identification code.

[0192] The computer device is also used to implement the functions of a zero-trust server side. One embodiment of the computer device in this invention includes:

[0193] Processor and memory;

[0194] When a memory is used to store computer programs, and a processor executes the computer programs stored in the memory, the following steps can be achieved:

[0195] Receive a knock key acquisition request sent by a one-way ferry gateway, wherein the knock key acquisition request carries a knock key identifier encrypted using an irreversible algorithm;

[0196] The request to obtain the door knocking key is message verified;

[0197] If the message for requesting the door knock key passes verification, then the user account is checked for a network security incident based on the correspondence between the encrypted door knock key identifier and the user account stored in the database in advance.

[0198] If the user account does not have a network security incident, the message gateway is invoked to send a knock key to the zero-trust client;

[0199] Receive a single-packet authorization and authentication request sent by the zero-trust client, wherein the single-packet authorization and authentication request includes at least a zero-trust client identifier and a user identifier encrypted using the knock key and a preset algorithm;

[0200] Perform a validity check on the single-package authorization authentication request;

[0201] If the single-packet authorization authentication request passes the verification, the zero-trust server port and / or business service are sent to the zero-trust client, enabling the user to access the zero-trust server port and / or business service through the zero-trust client.

[0202] In some embodiments of the present invention, the processor may also be used to implement the following steps:

[0203] Perform at least one of the following on the single-packet authorization authentication request: replay verification, forgery verification, user identification code verification, and client identification code verification.

[0204] It is understood that when the processor in the computer device described above executes the computer program, it can also implement the functions of each unit in the corresponding device embodiments described above, which will not be repeated here. For example, the computer program can be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the one-way ferry gateway / zero-trust server. For example, the computer program can be divided into units in the one-way ferry gateway described above, and each unit can implement the specific functions described in the corresponding one-way ferry gateway above.

[0205] The computer device may be a desktop computer, laptop, handheld computer, or cloud server, etc. The computer device may include, but is not limited to, a processor and memory. Those skilled in the art will understand that the processor and memory are merely examples of a computer device and do not constitute a limitation on the computer device. It may include more or fewer components, or a combination of certain components, or different components. For example, the computer device may also include input / output devices, network access devices, buses, etc.

[0206] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the computer device, connecting various parts of the computer device via various interfaces and lines.

[0207] The memory can be used to store the computer programs and / or modules. The processor implements various functions of the computer device by running or executing the computer programs and / or modules stored in the memory and by calling data stored in the memory. The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function, etc.; the data storage area may store data created according to the use of the terminal, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, RAM, plug-in hard disk, SmartMediaCard (SMC), Secure Digital (SD) card, FlashCard, at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0208] The present invention also provides a computer-readable storage medium for implementing the functions of one side of a one-way ferry gateway, wherein a computer program is stored thereon, and when the computer program is executed by a processor, the processor can perform the following steps:

[0209] Receive the access address of the zero-trust server entered by the user through the browser;

[0210] Based on the access address of the zero-trust server and the download information of the zero-trust client, the browser displays the download and installation page of the zero-trust client to the user.

[0211] If the user installs the Zero Trust Client through the download and installation page of the Zero Trust Client, then the Zero Trust Client receives a knock key acquisition request sent by the Zero Trust Client according to the knock key identifier entered by the user and in accordance with the knock key acquisition method, wherein the knock key acquisition request carries a knock key identifier encrypted using an irreversible algorithm.

[0212] The request to obtain the door knocking key is verified;

[0213] If the verification of the door-knocking key acquisition request passes, the door-knocking key acquisition request is forwarded to the zero-trust server according to the IP address of the zero-trust server access address, so that the zero-trust server calls the message gateway to send the door-knocking key to the zero-trust client.

[0214] In some embodiments of the present invention, the access address of the zero-trust server points to the domain name of the one-way ferry gateway via a CNAME. When the computer program is executed by the processor, the processor can also be used to implement the following steps:

[0215] Based on the access address and CNAME pointing relationship of the zero-trust server, obtain the pointing address of the access address of the zero-trust server, wherein the pointing address includes the domain name of the one-way ferry gateway;

[0216] Based on the domain name of the one-way ferry gateway and the download information of the zero-trust client, the browser displays the download and installation page of the zero-trust client to the user.

[0217] In some embodiments of the present invention, when a computer program is executed by a processor, the processor may also be used to perform the following steps:

[0218] The IP address of the Zero Trust server access address is embedded into the Zero Trust client installation package, so that after the user installs the Zero Trust client, the Zero Trust client automatically fills in the access address of the Zero Trust server and the IP address of the Zero Trust server access address.

[0219] In some embodiments of the present invention, the one-way ferry gateway is further configured with a zero-trust server authentication method. Before the download and installation page of the zero-trust client is displayed to the user through the browser, when the computer program is executed by the processor, the processor can also be used to implement the following steps:

[0220] The access prompt is displayed to the user according to the authentication method of the zero-trust server, wherein the access prompt is used to inform the user that the access address of the zero-trust server has enabled single packet authentication.

[0221] In some embodiments of the present invention, when a computer program is executed by a processor, the processor may also be used to perform the following steps:

[0222] The message requesting the door key is subjected to rate limiting and frequency limiting calculation and format verification. The format verification includes at least one of message format verification, message length verification and message content verification.

[0223] In some embodiments of the present invention, the one-way ferry gateway is set in the cloud or in the local network, and the one-way ferry gateway is a whitelist of the zero-trust server.

[0224] In some embodiments of the present invention, the door knock key identifier includes a terminal identification code, an email identification code, or a QR code identification code.

[0225] The present invention also provides another computer-readable storage medium for implementing the functions of a zero-trust server side, wherein a computer program is stored thereon, and when the computer program is executed by a processor, the processor can perform the following steps:

[0226] Receive a knock key acquisition request sent by a one-way ferry gateway, wherein the knock key acquisition request carries a knock key identifier encrypted using an irreversible algorithm;

[0227] The request to obtain the door knocking key is message verified;

[0228] If the message for requesting the door knock key passes verification, then the user account is checked for a network security incident based on the correspondence between the encrypted door knock key identifier and the user account stored in the database in advance.

[0229] If the user account does not have a network security incident, the message gateway is invoked to send a knock key to the zero-trust client;

[0230] Receive a single-packet authorization and authentication request sent by the zero-trust client, wherein the single-packet authorization and authentication request includes at least a zero-trust client identifier and a user identifier encrypted using the knock key and a preset algorithm;

[0231] Perform a validity check on the single-package authorization authentication request;

[0232] If the single-packet authorization authentication request passes the verification, the zero-trust server port and / or business service are sent to the zero-trust client, enabling the user to access the zero-trust server port and / or business service through the zero-trust client.

[0233] In some embodiments of the present invention, when a computer program is executed by a processor, the processor may also be used to perform the following steps:

[0234] Perform at least one of the following on the single-packet authorization authentication request: replay verification, forgery verification, user identification code verification, and client identification code verification.

[0235] It is understood that if the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a corresponding computer-readable storage medium. Based on this understanding, all or part of the processes in the above-described embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the above-described method embodiments. The computer program includes computer program code, which can be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electrical carrier signals and telecommunication signals.

[0236] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between apparatuses or units through some interfaces, and may be electrical, mechanical, or other forms.

[0237] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0238] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0239] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for single-package authentication, characterized in that, This method is applied to a one-way bypass gateway, which is a one-way non-controlling gateway. The one-way bypass gateway is configured with the IP address of the zero-trust server access address, the method for obtaining the knock key, and the download information of the zero-trust client. The one-way non-controlling gateway instructs the one-way bypass gateway to only send requests of a preset format to the zero-trust server, and the zero-trust server does not respond with a packet. That is, the one-way bypass gateway does not change the security of the zero-trust server's single-packet authorization authentication, thus achieving the purpose of non-control. The method includes: Receive the access address of the zero-trust server entered by the user through the browser; Based on the access address of the zero-trust server and the download information of the zero-trust client, the browser displays the download and installation page of the zero-trust client to the user. If the user installs the Zero Trust Client through the download and installation page of the Zero Trust Client, then the Zero Trust Client receives a knock key acquisition request sent by the Zero Trust Client according to the knock key identifier entered by the user and in accordance with the knock key acquisition method, wherein the knock key acquisition request carries a knock key identifier encrypted using an irreversible algorithm. The request to obtain the door knocking key is verified; If the verification of the door-knocking key acquisition request passes, the door-knocking key acquisition request is forwarded to the zero-trust server according to the IP address of the zero-trust server access address, so that the zero-trust server calls the message gateway to send the door-knocking key to the zero-trust client.

2. The method according to claim 1, characterized in that, The access address of the zero-trust server points to the domain name of the one-way ferry gateway via a CNAME; Based on the address pointed to by the access address of the zero-trust server and the download information of the zero-trust client, the browser displays the download and installation page of the zero-trust client to the user, including: Based on the access address and CNAME pointing relationship of the zero-trust server, obtain the pointing address of the access address of the zero-trust server, wherein the pointing address includes the domain name of the one-way ferry gateway; Based on the domain name of the one-way ferry gateway and the download information of the zero-trust client, the browser displays the download and installation page of the zero-trust client to the user.

3. The method according to claim 1, characterized in that, When displaying the download and installation page of the zero-trust client to the user through the browser, the method further includes: The IP address of the Zero Trust server access address is embedded into the Zero Trust client installation package, so that after the user installs the Zero Trust client, the Zero Trust client automatically fills in the access address of the Zero Trust server and the IP address of the Zero Trust server access address.

4. The method according to claim 1, characterized in that, The one-way ferry gateway is also configured with a zero-trust server authentication method. Before displaying the zero-trust client download and installation page to the user through the browser, the method further includes: The access prompt is displayed to the user according to the authentication method of the zero-trust server, wherein the access prompt is used to inform the user that the access address of the zero-trust server has enabled single packet authentication.

5. The method according to claim 1, characterized in that, Verification of the door-knocking key retrieval request includes: The message requesting the door key is subjected to rate limiting and frequency limiting calculation and format verification. The format verification includes at least one of message format verification, message length verification and message content verification.

6. The method according to claim 1, characterized in that, The one-way transfer gateway is set up in the cloud or on the local network, and the one-way transfer gateway is a whitelist of the zero-trust server.

7. The method according to claim 1, characterized in that, The knock key identifier includes a terminal identification code, email identification code, or QR code identification code.

8. A method for single-package authentication, characterized in that, Applied to zero-trust servers, the method includes: Receive a knock key acquisition request sent by a one-way ferry gateway, wherein the knock key acquisition request carries a knock key identifier encrypted using an irreversible algorithm; The request to obtain the door knocking key is message verified; If the message for requesting the door knock key passes verification, then the user account is checked for a network security incident based on the correspondence between the encrypted door knock key identifier and the user account stored in the database in advance. If the user account does not have a network security incident, the message gateway is invoked to send a knock key to the zero-trust client; Receive a single-packet authorization and authentication request sent by the zero-trust client, wherein the single-packet authorization and authentication request includes at least a zero-trust client identifier and a user identifier encrypted using the knock key and a preset algorithm; Perform a validity check on the single-package authorization authentication request; If the single-packet authorization authentication request passes the verification, the zero-trust server port and / or business service are sent to the zero-trust client, enabling the user to access the zero-trust server port and / or business service through the zero-trust client.

9. The method according to claim 8, characterized in that, The legality verification of the single-package authorization authentication request includes: Perform at least one of the following on the single-packet authorization authentication request: replay verification, forgery verification, user identification code verification, and client identification code verification.

10. A one-way shuttle gateway, characterized in that, The one-way ferry gateway is a one-way non-controlling gateway, and the one-way ferry gateway is configured with the IP address of the zero-trust server access address, the method for obtaining the knock key, and the download information of the zero-trust client. The one-way non-controlling gateway is used to instruct the one-way ferry gateway to only send requests of a preset format to the zero-trust server, and the zero-trust server does not reply with a packet. That is, the one-way ferry gateway does not change the security of the single packet authorization authentication of the zero-trust server, so as to achieve the purpose of non-controlling. The one-way shuttle gateway includes: The first receiving unit is used to receive the access address of the zero-trust server input by the user through a browser; The display unit is used to display the download and installation page of the zero-trust client to the user through the browser based on the access address of the zero-trust server and the download information of the zero-trust client; The first receiving unit is further configured to receive a knock key acquisition request sent by the zero trust client according to the knock key identifier input by the user and in accordance with the knock key acquisition method if the user installs the zero trust client according to the download and installation page of the zero trust client. The knock key acquisition request carries a knock key identifier encrypted with an irreversible algorithm. The first verification unit is used to verify the request to obtain the door knocking key; The forwarding unit is used to forward the request to the zero-trust server according to the IP address of the zero-trust server access address if the verification of the request to obtain the knock key passes, so that the zero-trust server can call the message gateway to send the knock key to the zero-trust client.

11. A zero-trust server, characterized in that, The zero-trust server includes: The second receiving unit is used to receive a knock key acquisition request sent by the one-way ferry gateway, wherein the knock key acquisition request carries a knock key identifier encrypted with an irreversible algorithm. The second verification unit is used to verify the message format of the door knocking key acquisition request; The second verification unit is further configured to, if the format verification of the request to obtain the door key passes, verify whether the user account has a network security incident based on the correspondence between the encrypted door key identifier and the user account stored in the database in advance; The calling unit is used to call the message gateway to send a knock key to the zero-trust client if the user account does not have a network security incident. The second receiving unit is further configured to receive a single-packet authorization and authentication request sent by the zero-trust client, wherein the single-packet authorization and authentication request includes at least a zero-trust client identifier and a user identifier encrypted using the knock key and a preset algorithm; The second verification unit is also used to perform a legality verification on the single-packet authorization authentication request; The sending unit is configured to send the zero-trust server port and / or business service to the zero-trust client if the verification of the single-packet authorization authentication request passes, so that the user can access the zero-trust server port and / or business service through the zero-trust client.

12. A single-package authentication system, characterized in that, include: A browser, a zero-trust client, a messaging gateway, a one-way ferry gateway as described in claim 10, and a zero-trust server as described in claim 11.

13. A computer device comprising a processor, characterized in that, When the processor executes a computer program stored in the memory, it is used to implement the single-package authentication method as described in any one of claims 1 to 7, or any one of claims 8 to 9.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it is used to implement the method of single-package authentication as claimed in any one of claims 1 to 7, or any one of claims 8 to 9.