Method and apparatus for identifying terminal accessing intranet
By combining multiple identification methods and security strategies, the accuracy and security issues of traditional terminal identification methods in multi-MAC address scenarios are solved, enabling accurate identification and secure management of terminals and improving the management efficiency of enterprise intranets.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SUZHOU LANGDONG NET TEC CO LTD
- Filing Date
- 2023-07-27
- Publication Date
- 2026-07-21
AI Technical Summary
Traditional terminal identification methods rely solely on MAC addresses, which cannot effectively handle situations with multiple network interfaces and multiple MAC addresses, leading to inaccurate identification and insufficient security.
By acquiring the terminal's hardware information and business login information, and comparing it with multiple identification methods (MAC address identification, mixed identification and non-MAC address identification), a security policy is constructed, valid MAC addresses are filtered and merged, and whitelists and blacklists are used to determine the terminal's security information and trust category.
It improves the accuracy and security of terminal identification, can handle multi-MAC address scenarios, achieves accurate terminal identification, improves enterprise management efficiency, and prevents unauthorized devices from accessing the intranet.
Smart Images

Figure CN116800533B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a method and apparatus for identifying terminals accessing an intranet. Background Technology
[0002] An intranet (IV) is a local area network established within an organization or institution. Based on specific network technologies and protocols, it connects different computers, servers, and devices within an internal space to enable resource sharing, data transmission, and collaboration. When a terminal needs to access the IV, security verification is required to determine whether access is permitted.
[0003] Traditional identification methods rely on the terminal's MAC (Media Access Control) address. However, traditional identification methods depend solely on the MAC address, and a single identification approach cannot handle situations with multiple network interfaces and multiple MAC addresses. Summary of the Invention
[0004] Therefore, it is necessary to provide a terminal identification method and device capable of handling multiple network interfaces and multiple MAC addresses accessing the intranet, in order to address the above-mentioned technical problems.
[0005] Firstly, this application provides a method for identifying a terminal accessing an intranet. The method for identifying a terminal accessing an intranet includes:
[0006] Obtain the hardware information and service login information of the terminal that sent the request; the hardware information includes more than one MAC address;
[0007] The identification method for a terminal is determined by comparing one or more MAC addresses, business login information, and historical terminal requests. The identification method is selected from MAC address identification, mixed identification, and non-MAC address identification.
[0008] The terminal is identified based on the identification method, and the identification result is obtained;
[0009] A security policy is constructed, and based on the security policy, the security information of the terminal is determined by judging more than one MAC address and business login information, and the identification results and security information are output to the terminal.
[0010] In one embodiment, the historical terminal request includes multiple historical MAC addresses and multiple historical login information; the method for identifying the terminal by comparing one or more MAC addresses, service login information, and historical terminal requests includes:
[0011] The first comparison result is obtained by comparing one or more MAC addresses with historical MAC addresses, and the second comparison result is obtained by comparing business login information with historical login information.
[0012] The terminal identification method is determined based on the first comparison result and the second comparison result.
[0013] In one embodiment, the method for determining the terminal identification based on the first comparison result and the second comparison result includes:
[0014] If the first comparison result determines that more than one MAC address is known, and the second comparison result determines that the business login information is known, then the terminal identification method is determined to be non-MAC address identification.
[0015] If the first comparison result determines that more than one MAC address is unknown, and the second comparison result determines that the business login information is unknown, then the terminal identification method is determined to be MAC address identification.
[0016] Otherwise, the terminal identification method is determined to be hybrid identification.
[0017] In one embodiment, a security policy is constructed, and based on the security policy, the security information of the terminal is determined by judging one or more MAC addresses and service login information, including:
[0018] A security policy is built based on historical terminal requests; the security policy includes a whitelist and a blacklist.
[0019] The terminal's hardware information and service login information are compared with the whitelist and blacklist respectively to obtain the terminal's security information.
[0020] In one embodiment, before constructing a security policy, determining the security information of the terminal by judging one or more MAC addresses and service login information based on the security policy, and outputting the identification result and security information to the terminal, the method further includes:
[0021] If there are multiple MAC addresses, then filter the valid addresses among the multiple MAC addresses;
[0022] The system cleans and merges valid addresses based on their respective categories, and updates more than one MAC address based on the cleaning and merging results.
[0023] In one embodiment, the terminal identification method for accessing the intranet further includes:
[0024] The trusted category of the terminal is determined based on the identification results and security information; the trusted category includes trusted devices and untrusted devices.
[0025] Whether a terminal is allowed to access the network is determined based on its trusted category.
[0026] Secondly, this application also provides a terminal identification device for accessing an intranet. The terminal identification device for accessing an intranet includes:
[0027] The device information acquisition module is used to acquire the hardware information and service login information of the terminal that sent the request; the hardware information includes one or more MAC addresses.
[0028] The device identification module is used to compare one or more MAC addresses, service login information, and historical terminal requests to determine the terminal identification method; the identification method is selected from MAC address identification, mixed identification, and non-MAC address identification.
[0029] The identification result determination module is used to identify the terminal based on the identification method and obtain the identification result;
[0030] The security management module is used to build security policies, judge one or more MAC addresses and business login information based on the security policies, determine the security information of the terminal, and output the identification results and security information to the terminal.
[0031] Thirdly, this application also provides a computer device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0032] Obtain the hardware information and service login information of the terminal that sent the request; the hardware information includes more than one MAC address;
[0033] The identification method for a terminal is determined by comparing one or more MAC addresses, business login information, and historical terminal requests. The identification method is selected from MAC address identification, mixed identification, and non-MAC address identification.
[0034] The terminal is identified based on the identification method, and the identification result is obtained;
[0035] A security policy is constructed, and based on the security policy, the security information of the terminal is determined by judging more than one MAC address and business login information, and the identification results and security information are output to the terminal.
[0036] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:
[0037] Obtain the hardware information and service login information of the terminal that sent the request; the hardware information includes more than one MAC address;
[0038] The identification method for a terminal is determined by comparing one or more MAC addresses, business login information, and historical terminal requests. The identification method is selected from MAC address identification, mixed identification, and non-MAC address identification.
[0039] The terminal is identified based on the identification method, and the identification result is obtained;
[0040] A security policy is constructed, and based on the security policy, the security information of the terminal is determined by judging more than one MAC address and business login information, and the identification results and security information are output to the terminal.
[0041] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, performs the following steps:
[0042] Obtain the hardware information and service login information of the terminal that sent the request; the hardware information includes more than one MAC address;
[0043] The identification method for a terminal is determined by comparing one or more MAC addresses, business login information, and historical terminal requests. The identification method is selected from MAC address identification, mixed identification, and non-MAC address identification.
[0044] The terminal is identified based on the identification method, and the identification result is obtained;
[0045] A security policy is constructed, and based on the security policy, the security information of the terminal is determined by judging more than one MAC address and business login information, and the identification results and security information are output to the terminal.
[0046] The aforementioned terminal identification method and apparatus for accessing the intranet first acquires the terminal's hardware information and service login information. By comparing the MAC address, service login information, and historical terminal requests in the terminal's hardware information, the identification method is determined, and the identification result is obtained based on the identification method. After judging the terminal's security through security policies, the terminal's security information is obtained. The intranet can then determine whether to allow the terminal to access based on the identification result and security information, and feed the information back to the terminal. Compared to traditional technologies that use a single MAC address identification method, the technical solution provided in this application employs multiple identification methods, which can be selected according to specific circumstances, greatly improving the accuracy of device identification. This allows it to be applied to scenarios where terminals have multiple MAC addresses, achieving accurate terminal identification and improving enterprise management efficiency. Attached Figure Description
[0047] Figure 1 This is an application environment diagram of a terminal identification method for accessing the intranet in one embodiment;
[0048] Figure 2 This is a flowchart illustrating a terminal identification method for accessing the intranet in one embodiment;
[0049] Figure 3 This is a flowchart illustrating the steps of a terminal identification method in one embodiment;
[0050] Figure 4 This is a schematic diagram of a process for determining terminal security information through a security policy in one embodiment.
[0051] Figure 5 This is a flowchart illustrating a terminal identification method for accessing the intranet in another embodiment;
[0052] Figure 6 This is a timing diagram of the execution of a terminal identification method for accessing the intranet in one embodiment;
[0053] Figure 7 This is a structural block diagram of a terminal identification device for accessing an intranet in one embodiment;
[0054] Figure 8 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0055] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0056] The terminal identification method for accessing the intranet provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104 or located in the cloud or on other network servers. The server can be equipped with a device identification system. When terminal 102 sends a network connection request to server 104, the device identification system identifies terminal 102, determines whether terminal 102 meets security requirements, provides feedback to terminal 102, and determines whether to allow terminal 102 to connect to the network. Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart vehicle devices, etc. Portable wearable devices can include smartwatches, smart bracelets, head-mounted devices, etc. Server 104 can be implemented using a standalone server or a server cluster composed of multiple servers.
[0057] In one embodiment, such as Figure 2 As shown, a method for terminal identification when accessing an intranet is provided, which can be applied to... Figure 1 Taking server 104 as an example, the explanation includes the following steps S202 to S208:
[0058] S202, Obtain the hardware information and service login information of the terminal that sent the request; the hardware information includes one or more MAC addresses.
[0059] Terminal 102 sends an intranet access request to server 104, and server 104 performs a security check on terminal 102. Server 104 can be a server within the enterprise intranet. This is used to send an intranet access request to server 104 after terminal 102 logs in. At this time, server 104 simultaneously receives the hardware information of terminal 102 and the user's service login information. Indicatively, terminal 102 may have a device information generation module, responsible for generating device hardware information and service login information when the device accesses the network.
[0060] An intranet can be an enterprise's internal office network: in this application scenario, the enterprise needs to manage employees' computers and mobile devices to ensure network and data security. An intranet can also be a production network: in this application scenario, production equipment and sensors need to connect to the network for data exchange and control. Intranets can also be network environments in industries such as finance and healthcare, where the management requirements for connected devices are more stringent, necessitating precise device identification and secure management.
[0061] Hardware information refers to the device information of the terminal device, which includes at least the MAC address, and may also include the device model, device IP address, device type, etc. Multiple MAC addresses are allowed.
[0062] Business login information refers to the information a user uses to log in on a terminal device, including the user's login name, login time, and login location.
[0063] S204, compare one or more MAC addresses, service login information and historical terminal requests to determine the terminal identification method; the identification method is selected from MAC address identification, mixed identification and non-MAC address identification.
[0064] Historical terminal requests are the collection of requests sent by other terminal devices before terminal 102 sends its current request to access the intranet.
[0065] If the current terminal request exists in the historical terminal requests and was previously determined to be secure, then the current terminal can also be considered secure. This allows for a preliminary assessment of the terminal's security level, and a determination of which identification method to use based on that security level.
[0066] MAC address authentication verifies or authorizes access by recognizing the MAC address of a terminal device. Network administrators can allow or deny access to a device based on its MAC address. The advantage of this method is its simplicity and directness, but the disadvantage is that MAC addresses can be forged, making it vulnerable to spoofing attacks.
[0067] Hybrid identification combines multiple identification technologies to improve accuracy and security. In addition to MAC addresses, it can also combine IP addresses, user credentials, device type, location, and other information for identification. For example, authentication can be performed using a combination of MAC address and username / password, or device type and location information can be combined for device identification. The advantage of hybrid identification is that it provides more information to identify devices and is difficult to forge easily, but its implementation is more complex.
[0068] Non-MAC address identification refers to technologies that rely on more than just MAC addresses for identification. It can use other identifiers, features, or algorithms to identify devices, such as digital certificates, device fingerprints, and behavioral analysis. The advantage of non-MAC address identification is that it does not depend on the uniqueness of MAC addresses, providing higher security and accuracy. The disadvantages are higher implementation complexity and potential user privacy issues.
[0069] Therefore, by comparing all MAC addresses, business login information, and historical terminal requests of the terminal, the security level of the terminal can be preliminarily determined, and a suitable identification method can be selected based on this.
[0070] S206, Identify the terminal based on the identification method and obtain the identification result.
[0071] Once the identification method is determined, the terminal can be identified based on the identification method to obtain the identification result.
[0072] The identification results can determine whether a device has specific access permissions or authentication.
[0073] S208: Construct a security policy, determine the security information of the terminal by judging one or more MAC addresses and business login information based on the security policy, and output the identification results and security information to the terminal.
[0074] After determining the identification result of the terminal, it is necessary to further determine whether the terminal is secure.
[0075] Security policies can be based on MAC addresses and business login information to determine the security information of a terminal. The intranet or server can determine whether to allow the terminal to access the network based on the identification results and security information, and then feed back the identification results and security information to the terminal so that the terminal is aware of them.
[0076] In the aforementioned terminal identification method for accessing the intranet, the terminal's hardware information and service login information are first obtained. The terminal identification method is determined by comparing the MAC address, service login information, and historical terminal requests in the terminal's hardware information, and the identification result is obtained based on this method. After the terminal's security is assessed through security policies, the terminal's security information is obtained. The intranet can then determine whether to allow the terminal to access based on the identification result and security information, and feed this information back to the terminal. Compared to traditional technologies that use a single MAC address identification method, the technical solution provided in this application employs multiple identification methods, which can be selected according to specific circumstances, greatly improving the accuracy of device identification. This allows it to be applied to scenarios where terminals have multiple MAC addresses, achieving accurate terminal identification and improving enterprise management efficiency.
[0077] In one embodiment, such as Figure 3 As shown, in step S204, the historical terminal request includes multiple historical MAC addresses and multiple historical login information; comparing one or more MAC addresses, service login information, and historical terminal requests to determine the terminal identification method includes:
[0078] S302: Compare one or more MAC addresses with historical MAC addresses to obtain the first comparison result; compare the business login information with historical login information to obtain the second comparison result.
[0079] Historical terminal requests are a collection of prior intranet requests from multiple terminals, resulting in multiple historical MAC addresses and multiple historical login records. Indicatively, these can be stored in a data storage system.
[0080] The MAC address of the terminal making this request is compared with the historical MAC addresses to obtain the first comparison result. The first comparison result can be whether the MAC address of this request exists in the historical MAC addresses. If it exists, it can be further determined whether the MAC address was allowed to access the internal network in a previous request.
[0081] Similarly, the second comparison result can be whether the business login information requested in this request exists in the historical login information. If it exists, it can be further determined whether the business login information was allowed to access the intranet in the previous request.
[0082] S304, determine the terminal identification method based on the first comparison result and the second comparison result.
[0083] Terminal identification methods include MAC address identification, mixed identification, and non-MAC address identification, which can be determined based on the first comparison result and the second comparison result.
[0084] In one feasible implementation, if the first comparison result determines that one or more MAC addresses are known, and the second comparison result determines that the service login information is known, then the terminal identification method is determined to be non-MAC address identification; if the first comparison result determines that one or more MAC addresses are unknown, and the second comparison result determines that the service login information is unknown, then the terminal identification method is determined to be MAC address identification; otherwise, the terminal identification method is determined to be hybrid identification.
[0085] If all MAC addresses are known and the business login information is known, non-MAC address identification is used to prevent other devices from forging known information. The advantage of non-MAC address identification is that it does not rely on the uniqueness of MAC addresses, and can provide higher security and accuracy.
[0086] If both the MAC address and the business login information are unknown, it is assumed that the device is making its first intranet access request. Using the MAC address for identification is simple and efficient.
[0087] In other cases, hybrid identification is used, including situations where the MAC address is partially known and partially unknown, the MAC address is known but the service login information is unknown, or the MAC address is unknown but the service login information is known. Hybrid identification can use a combination of MAC address and service login information for authentication, or combine device type and location information to identify the device, thereby improving identification accuracy.
[0088] In this embodiment, the terminal device identification method based on whether the MAC address is known and whether the service login information is known is different from the single identification method in traditional technology. The solution provided in this application can classify the terminal and select different identification methods according to different classification results. On the one hand, it can improve the accuracy of identification, and on the other hand, it can improve the efficiency of judgment, thus achieving a balance between accuracy and efficiency.
[0089] In one embodiment, such as Figure 4 As shown, in step S208, a security policy is constructed. Based on the security policy, the security information of the terminal is determined by judging one or more MAC addresses and service login information, including:
[0090] S402, builds a security policy based on historical terminal requests; the security policy includes a whitelist and a blacklist.
[0091] Historical terminal requests include data from multiple terminals, and whitelists and blacklists can be built based on these historical terminal requests. For example, they can be built based on historical MAC addresses or historical login information from the historical terminal requests.
[0092] A whitelist is an authorized list that identifies trusted endpoints that are permitted to access a system or resource. Only endpoints listed on the whitelist are granted access; other entities not listed on the whitelist will be prohibited or have their access restricted.
[0093] A blacklist is a prohibited list that identifies endpoints that are not trusted or permitted to access a system or resources. Entities listed on the blacklist will be prohibited from accessing or restricted.
[0094] S404 compares the terminal's hardware information and service login information with the whitelist and blacklist respectively to obtain the terminal's security information.
[0095] By comparing the hardware information of the terminal requesting this request with the whitelist and blacklist respectively, and comparing the service login information with the whitelist and blacklist respectively, it is possible to determine whether the terminal exists in the whitelist or blacklist, thereby obtaining the terminal's security information.
[0096] If a device exists in the whitelist, it is considered to have high security; if it exists in the blacklist, it is considered to have poor security.
[0097] In this embodiment, a whitelist and blacklist for security policies are constructed. The security information of a terminal is determined by comparing the device's hardware information and business login information with these lists. In traditional solutions, security management may be ineffective due to inaccurate device identification. This embodiment, through accurate device identification, enables the implementation of more precise security policies for terminal devices, preventing unauthorized terminal devices from accessing the enterprise intranet.
[0098] In one embodiment, before constructing a security policy in step S208, judging one or more MAC addresses and service login information based on the security policy, determining the security information of the terminal, and outputting the identification result and security information to the terminal, the method further includes: if there are multiple MAC addresses, filtering the valid addresses among the multiple MAC addresses; cleaning and merging the valid addresses based on the category of each MAC address, and updating one or more MAC addresses according to the cleaning and merging result.
[0099] When dealing with devices with multiple network interface cards (NICs) or multiple MAC addresses, it is necessary to clean and merge the business login information with the multiple MAC addresses in order to achieve unified identification and management of the devices.
[0100] During MAC address cleaning and merging, for each received MAC address, the module first checks its validity (e.g., whether it conforms to MAC address format rules, whether it belongs to the known MAC address range of the device manufacturer, etc.). Then, the module merges all valid MAC addresses into a single unified MAC address identifier to update all MAC addresses on the device. After cleaning and merging the MAC addresses, the MAC address cleaning and merging module sends the device identification results and the unified MAC address identifier to the security management module for further processing.
[0101] The technical solution provided in this embodiment solves the problem of identifying multi-NIC devices. In traditional solutions, the identification of multi-NIC devices may lead to confusion and inaccuracy. However, this embodiment successfully overcomes this problem by simultaneously identifying multiple network interfaces and cleaning and merging multiple MAC addresses.
[0102] In one embodiment, the terminal identification method for accessing the intranet further includes: determining the trusted category of the terminal based on the identification result and security information; the trusted category includes trusted devices and untrusted devices; and determining whether to allow the terminal to access the network based on the trusted category.
[0103] If the identification result indicates that the device has specific access permissions or authentication, the terminal is considered a trusted device. If the security information indicates that the terminal is a secure device, it is also considered a trusted device. Only when the identification result indicates that the device lacks permissions and authentication, and the security information indicates that the device is insecure, is the device considered an untrusted device.
[0104] Trusted devices will be allowed to access the network. Untrusted devices will be blocked from accessing the network, and a security warning may be generated and sent to the terminal.
[0105] In this embodiment, the trusted category of the terminal is determined based on the identification results and security information, and it is further determined whether the terminal can access the intranet. In this way, the security of the terminal is assessed, preventing malicious intrusion and ensuring the security of the intranet.
[0106] like Figure 5 As shown, in one embodiment, a terminal identification method for accessing an intranet includes the following steps:
[0107] S502, obtain the hardware information and service login information of the terminal that sent the request; the hardware information includes one or more MAC addresses.
[0108] S504 compares one or more MAC addresses with historical MAC addresses to obtain the first comparison result, and compares the business login information with historical login information to obtain the second comparison result.
[0109] S506, determine the terminal identification method based on the first comparison result and the second comparison result; the identification method is selected from MAC address identification, mixed identification and non-MAC address identification.
[0110] S508 identifies the terminal based on the identification method and obtains the identification result.
[0111] S510: If there are multiple MAC addresses, then filter the valid addresses among the multiple MAC addresses.
[0112] S512 cleans and merges valid addresses based on the category of each MAC address, and updates more than one MAC address according to the cleaning and merging results.
[0113] S514 builds security policies based on historical terminal requests; the security policies include whitelists and blacklists.
[0114] S516 compares the terminal's hardware information and service login information with the whitelist and blacklist respectively to obtain the terminal's security information, and outputs the identification results and security information to the terminal.
[0115] S518 determines the trusted category of the terminal based on the identification results and security information; the trusted category includes trusted devices and untrusted devices.
[0116] S520 determines whether to allow a terminal to access the network based on its trusted category.
[0117] Also refer to Figure 6 , Figure 6 The execution timing diagram for terminal identification in this embodiment is shown, where the device identification system can be an intranet server used to perform terminal device identification. Figure 6 In this context, the terminal device is the device that accesses the intranet; selecting the identification method refers to selecting the identification method based on the first comparison result and the second comparison result, and obtaining the identification result; cleaning and merging MAC addresses refers to the need to clean and merge multiple MAC addresses, so this step is only performed when necessary; applying security policies refers to applying the MAC address input value to the security policy to obtain security information, i.e., security management information.
[0118] Specifically, in this embodiment, the hardware information and service login information of the terminal device are first obtained. The MAC address in the hardware information is compared with the historical MAC address to obtain a first comparison result, and the service login information is compared with the historical login information to obtain a second comparison result. Based on the first and second comparison results, a terminal identification method is determined. The identification method is selected from MAC address identification, mixed identification, and non-MAC address identification, and an identification result is obtained according to the identification method. If the terminal has multiple MAC addresses, the multiple MAC addresses need to be cleaned and merged, and the merged unified address is input into the security policy for judgment. The security policy includes a whitelist and a blacklist, which can determine the security information of the terminal device based on the whitelist and blacklist. Finally, the trusted category of the terminal device is determined based on the identification result and security information, and fed back to the terminal. The terminal identification method for accessing the intranet provided in this embodiment achieves accurate terminal identification and improves enterprise management efficiency.
[0119] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0120] Based on the same inventive concept, this application also provides a terminal identification device for accessing an intranet, which implements the terminal identification method for accessing an intranet as described above. The solution provided by this device is similar to the solution described in the above method. Therefore, the specific limitations of one or more terminal identification device embodiments for accessing an intranet provided below can be found in the limitations of the terminal identification method for accessing an intranet described above, and will not be repeated here.
[0121] In one embodiment, such as Figure 7 As shown, a terminal identification device 700 for accessing an intranet is provided, comprising: a device information acquisition module 702, a device identification module 704, an identification result determination module 706, and a security management module 708, wherein:
[0122] The device information acquisition module 702 is used to acquire the hardware information and service login information of the terminal that sent the request; the hardware information includes one or more MAC addresses.
[0123] The device identification module 704 is used to compare one or more MAC addresses, service login information and historical terminal requests to determine the terminal identification method; the identification method is selected from MAC address identification, mixed identification and non-MAC address identification.
[0124] The identification result determination module 706 is used to identify the terminal based on the identification method and obtain the identification result.
[0125] The security management module 708 is used to build security policies, determine the security information of a terminal by judging one or more MAC addresses and business login information based on the security policies, and output the identification results and security information to the terminal.
[0126] In one embodiment, the historical terminal request includes multiple historical MAC addresses and multiple historical login information; the device identification module 704 is specifically used to: compare one or more MAC addresses with historical MAC addresses to obtain a first comparison result, compare the service login information with historical login information to obtain a second comparison result; and determine the terminal identification method based on the first comparison result and the second comparison result.
[0127] In one embodiment, the device identification module 704 is specifically used to: if the first comparison result determines that one or more MAC addresses are known, and the second comparison result determines that the service login information is known, then determine that the terminal identification method is non-MAC address identification; if the first comparison result determines that one or more MAC addresses are unknown, and the second comparison result determines that the service login information is unknown, then determine that the terminal identification method is MAC address identification; otherwise, determine that the terminal identification method is hybrid identification.
[0128] In one embodiment, the security management module 708 is specifically used to: construct a security policy based on historical terminal requests; the security policy includes a whitelist and a blacklist; and compare the terminal's hardware information and service login information with the whitelist and blacklist respectively to obtain the terminal's security information.
[0129] In one embodiment, the terminal identification device 700 accessing the intranet further includes a MAC address cleaning and merging module, which is used to: if there are multiple MAC addresses, filter the valid addresses among the multiple MAC addresses; clean and merge the valid addresses based on the category of each MAC address, and update one or more MAC addresses according to the cleaning and merging results.
[0130] In one embodiment, the terminal identification device 700 accessing the intranet further includes a device trust determination module, which is used to determine the trust category of the terminal based on the identification result and security information; the trust category includes trusted devices and untrusted devices; and determine whether to allow the terminal to access the network based on the trust category.
[0131] Each module in the aforementioned terminal identification device accessing the intranet can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0132] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 8 As shown, this computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operating system and computer programs stored in the non-volatile storage media. The database stores historical terminal request data. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When executed by the processor, the computer program implements a terminal identification method for accessing an intranet.
[0133] Those skilled in the art will understand that Figure 8 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0134] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.
[0135] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps in the above method embodiments.
[0136] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0137] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0138] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0139] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for identifying a terminal accessing an intranet, characterized in that, The method includes: Obtain the hardware information and service login information of the terminal that sent the request; the hardware information includes one or more MAC addresses; The identification method for the terminal is determined by comparing the one or more MAC addresses, the service login information, and the historical terminal requests. The identification method is selected from MAC address identification, mixed identification, and non-MAC address identification. The historical terminal requests include multiple historical MAC addresses and multiple historical login information. The terminal is identified based on the identification method to obtain the identification result; A security policy is constructed, and based on the security policy, the security information of the terminal is determined by judging the one or more MAC addresses and the service login information, and the identification result and the security information are output to the terminal. The method for determining the terminal identification by comparing the one or more MAC addresses, the service login information, and historical terminal requests includes: comparing the one or more MAC addresses with the historical MAC addresses to obtain a first comparison result; comparing the service login information with the historical login information to obtain a second comparison result; if the first comparison result determines that all of the one or more MAC addresses are known, and the second comparison result determines that the service login information is known, then the terminal identification method is determined to be non-MAC address identification; if the first comparison result determines that all of the one or more MAC addresses are unknown, and the second comparison result determines that the service login information is unknown, then the terminal identification method is determined to be MAC address identification; otherwise, the terminal identification method is determined to be hybrid identification.
2. The method according to claim 1, characterized in that, The security policy is constructed by determining the security information of the terminal based on the one or more MAC addresses and the service login information, including: A security policy is constructed based on the historical terminal requests; the security policy includes a whitelist and a blacklist. The terminal's hardware information and service login information are compared with the whitelist and blacklist respectively to obtain the terminal's security information.
3. The method according to claim 1, characterized in that, Before constructing the security policy, determining the security information of the terminal by judging the one or more MAC addresses and the service login information based on the security policy, and outputting the identification result and the security information to the terminal, the method further includes: If there are multiple MAC addresses, then filter out the valid addresses from among the multiple MAC addresses; The valid addresses are cleaned and merged based on the category of each MAC address, and the one or more MAC addresses are updated according to the cleaning and merging results.
4. The method according to any one of claims 1-3, characterized in that, The method further includes: The trusted category of the terminal is determined based on the identification result and the security information; the trusted category includes trusted devices and untrusted devices. Whether the terminal is allowed to access the network is determined based on the trusted category.
5. A terminal identification device for accessing an intranet, characterized in that, The device includes: The device information acquisition module is used to acquire the hardware information and service login information of the terminal that sent the request; the hardware information includes one or more MAC addresses. The device identification module is used to compare the one or more MAC addresses, the service login information, and historical terminal requests to determine the identification method of the terminal. The identification method is selected from MAC address identification, hybrid identification, and non-MAC address identification. The historical terminal requests include multiple historical MAC addresses and multiple historical login information. The step of comparing the one or more MAC addresses, the service login information, and historical terminal requests to determine the identification method of the terminal includes: comparing the one or more MAC addresses with the historical MAC addresses to obtain a first comparison result; comparing the service login information with the historical login information to obtain a second comparison result. If the first comparison result determines that all of the one or more MAC addresses are known, and the second comparison result determines that the service login information is known, then the identification method of the terminal is determined to be non-MAC address identification. If the first comparison result determines that all of the one or more MAC addresses are unknown, and the second comparison result determines that the service login information is unknown, then the identification method of the terminal is determined to be MAC address identification. Otherwise, the identification method of the terminal is determined to be hybrid identification. The identification result determination module is used to identify the terminal based on the identification method and obtain the identification result; The security management module is used to construct security policies, determine the security information of the terminal based on the security policies and the business login information, and output the identification results and the security information to the terminal.
6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.
8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.