An Internet access method and system

By receiving requested domain names, collecting user information, analyzing access rights and generating pass tokens in the enterprise business system, the problem that the enterprise business system is difficult to control access rights and security threats during external access is solved, and a higher security and convenient management experience is achieved.

CN118018274BActive Publication Date: 2025-06-27BEIJING DAOHE ZHUOXIN TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410143544.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-01
Publication Date
2025-06-27
Estimated Expiration
2044-02-01

AI Technical Summary

Technical Problem

When facing a large number of external accesses, it is difficult for enterprise business systems to effectively control access rights, and the external access environment is complex, which may lead to a threat to security.

Method used

By receiving the requested domain name, collecting user login information and identity information, analyzing and judging the authenticity of the requested address or domain name, generating access identifiers, detecting access permissions, and generating a pass token based on the detection results for data access.

Benefits of technology

It improves the security of the system and prevents phishing websites from placing corporate data and user identity information, facilitates administrators to manage the system, and has a more convenient and fast user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118018274B_ABST
    Figure CN118018274B_ABST
Patent Text Reader

Abstract

The present invention discloses an Internet access method and system. The method comprises the following steps: Step 1: Receive a requested domain name, and collect the user's login information and identity information; Step 2: Obtain the obtained requested domain name, analyze and judge the authenticity of the requested address or domain name, obtain the user's login information and identity information, and analyze and judge whether the logged-in user has the right to access the domain name; Step 3: Obtain the user's access request, analyze the user's access request to generate an access identifier, and detect the access permission according to the access identifier and identity characteristics; Step 4: Generate a passing token according to the detection result to access the data, submit a temporary access permission application, and generate a temporary passing token; Step 5: Receive the access result feedback by the service system, and feedback the reason for the failure of the access request. The present invention has the characteristics of high security and easy management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of Internet access, and specifically provides an Internet access method and system. Background Art

[0002] With the continuous improvement of the technological level, the operation mode of enterprises is increasingly tending towards digital transformation. The business systems of enterprises are more dependent on the Internet. Not only do internal employees of enterprises want to access various business data of the enterprises, but also customers and partners have the need to access enterprise data. The large number of access groups makes it impossible to effectively control access permissions. Moreover, customers, partners, etc. basically access from the outside, including the network environments in public places such as shopping malls and restaurants. The environments where these external accesses are located are complex, which may pose a threat to the security of enterprise business systems. Therefore, it is necessary to design an Internet access method and system with high security and easy management. Summary of the Invention

[0003] The purpose of the present invention is to provide an Internet access method and system to solve the problems raised in the above background art.

[0004] To solve the above technical problems, the present invention provides the following technical solutions: An Internet access method includes the following steps:

[0005] Step 1: Receive the requested domain name, and collect the user's login information and identity information;

[0006] Step 2: Obtain the obtained requested domain name, analyze and judge the authenticity of the request address or domain name, obtain the user's login information and identity information, and analyze and judge whether the logged-in user has the right to access the domain name;

[0007] Step 3: Obtain the user's access request, analyze the user's access request to generate an access identifier, and detect the access permission according to the access identifier and identity characteristics;

[0008] Step 4: Generate a pass token according to the detection result to access the data, submit a temporary access permission application, and generate a temporary pass token;

[0009] Step 5: Receive the access result feedback from the business system, and feedback the reason for the failure of the access request.

[0010] According to the above technical solution, the steps of analyzing and judging the authenticity of the request address or domain name and analyzing and judging whether the logged-in user has the right to access the domain name include:

[0011] Obtain the domain name information input by the user, analyze and verify the domain name information, compare the obtained domain name address with the domain name address preset in the system database, and when the comparison similarity reaches the preset maximum threshold, start the judgment unit to compare the domain name input by the user with the preset domain name in the database. When the comparison result is exactly the same, the user logs in to the website and enters the identity information. When the comparison result is different, the system feedback pop-up window prompts that the domain name is wrong and please re-enter;

[0012] Get the identity data entered by the user when logging in, analyze the user's identity data, determine the user's identity, and check whether the user's login information exists in the enterprise business system database. If it is detected in the system database, the information entered by the logged-in user is true and the user is allowed to access the website. If it does not exist in the system database, the system pops up a window to prompt the user that the information is wrong and asks him to re-enter the information. After the user logs in successfully, the data displayed on the page are all public data of the enterprise, and other data only displays the data type module.

[0013] According to the above technical solution, the step of analyzing the user access request to generate an access identifier includes:

[0014] Get the access request submitted by the user, extract keywords for the access request, confirm the type of data the user wants to access based on the extracted keywords, divide the permission security level according to the data type, and analyze the permission security level of the data to be accessed by the access request. When the permission security level is higher than the maximum threshold set by the system, the system will start two-factor authentication and submit a request to the system administrator to help complete auxiliary verification.

[0015] According to the above technical solution, the step of detecting access rights according to the access identifier and identity characteristics includes:

[0016] After the system receives the access application, it will verify the access rights. When the content accessed by the user needs to be verified, the system pops up a window to collect and identify the user's fingerprint or face using the access device, authenticate the identity and check the permissions. The system receives the fingerprint and face data for processing. The system will not immediately feedback the verification results. Through the preset program in the system, the preset permission detection result feedback interval in the system is T. After T time, the system will feedback the detection results. If access requests are sent to a group of data types within a certain period of time, the system will adjust the access permission detection result feedback time. Through the formula y=a*x 2 +T calculates the time it takes to get the test result back, with a coefficient of 0 <a<1,T为常数,根据公式不难得出短时间内访问次数越多等待时长就越长。

[0017] According to the above technical solution, the steps of generating a pass token to access data based on the detection result, submitting a temporary access permission application, and generating a temporary pass token include:

[0018] Obtain the access permission check result, and judge whether the user has the permission to access the data according to the analysis result. When the detection result shows that the access request has access permission, the user decides whether to generate a pass token, and uses the pass token to carry the user access request to access the enterprise business system to obtain the data that the user wants to access. When the access request made by an ordinary user is not within the user's permission scope, the user submits an application for temporary access rights to the data to the system administrator through the temporary permission application unit. The system will collect all user behaviors before the user applies for temporary access rights, analyze the user behavior data, analyze the user behavior to obtain the user's access preference, and further analyze whether there is a risk of enterprise data being stolen according to the user access data type and permission security level. When the user behavior stays on the content related to the enterprise's key technologies all the time, it is judged that there is a security risk in the user behavior, and the temporary permission application submitted by the user will not be approved. If it is judged by the system that the user behavior has no risk behavior and the security level of the access content of the access permission application is below the set threshold, all of them will be approved. When an internal employee submits a temporary permission application, the employee shall upload relevant work requirement certificates in a timely manner, otherwise the application will not be approved either; for the approved temporary permission applications, the system will generate respective temporary pass tokens according to the application content. The temporary pass token has a valid period, and the system administrator can change and set the valid period. The maximum valid period cannot exceed the threshold preset in the system. When the maximum valid period exceeds the preset threshold, the system will pop up a reminder and clear the set valid period. Click OK to continue setting the valid period of the temporary pass token in compliance.

[0019] According to the above technical solution, the steps of receiving the access result feedback from the business system and feedbacking the reason for the access request failure include:

[0020] The pass token and the temporary pass token carry the access data and are feedback to the web page. After the edge server obtains the access data, it sends an instruction to the data feedback unit, and the data feedback unit uses the verification unit to perform identity verification. The verification unit collects user fingerprint and face recognition information data, obtains the user permission data collected by the access permission detection unit, and compares the data collected by the verification unit with the data of the access permission detection unit. When the comparison result is exactly the same, the data feedback unit obtains the data from the edge server and feedbacks it to the page. When there is a difference in the comparison result, the verification unit sends a signal to the edge server, and the edge server crushes the temporarily stored data after receiving the signal.

[0021] According to the above technical solution, the system includes:

[0022] A domain name detection module, which is used to detect the authenticity of the domain name and verify the user identity;

[0023] An access permission management module, which is used to manage the access permissions;

[0024] A feedback module, which is used to feedback the accessed data to the web page.

[0025] According to the above technical solution, the domain name detection module includes:

[0026] A receiving unit, which is used to receive the domain name and user identity information input by the user;

[0027] A judging unit, which is used to judge the authenticity of the domain name and verify the user identity;

[0028] A sending unit, which is used to send the user permissions to the edge server, and the edge server obtains data according to the permissions.

[0029] According to the above technical solution, the access permission management module includes:

[0030] A user access request obtaining unit, which is used to obtain the user's access request data;

[0031] An access permission detection unit, which is used to detect whether the user has access permissions;

[0032] A passing token generating unit, which is used to generate a passing token to carry the user access request obtained data;

[0033] A temporary permission application unit, which is used to apply for temporary access permissions.

[0034] According to the above technical solution, the feedback module includes:

[0035] A data feedback unit, which is used to receive the access request data obtained by the edge server;

[0036] A verification unit, which is used to verify the user identity again;

[0037] A request failure feedback unit, which is used to feedback the reason for the request failure.

[0038] Compared with the prior art, the beneficial effects achieved by the present invention are as follows: In the present invention, a domain name detection module is provided to analyze the accuracy of the domain name, judge the authenticity of the domain name, prevent phishing websites from stealing enterprise data and user identity information, improve the security of the system, and an access permission detection unit and a temporary permission application unit are also provided. The access permission detection unit detects whether the access request made by the user is within its access permission. If the user does not have permission to view the access request made by the user, an application for access is made through the temporary permission application unit, and the system analyzes the result to judge whether the user's temporary permission application can pass, which facilitates the administrator's management of the system and makes the system usage experience more convenient and fast. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The accompanying drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention, and do not constitute a limitation to the present invention. In the accompanying drawings:

[0040] Figure 1 is a flowchart of the steps of an Internet access method provided in Embodiment 1 of the present invention;

[0041] Figure 2 is a schematic diagram of the module composition of an Internet access system provided in Embodiment 2 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0043] Embodiment 1: Figure 1 is a flowchart of an Internet access method and system provided in Embodiment 1 of the present invention. This embodiment can be applied to the scenario of enterprise system control access. This method can be executed by an Internet access method and system provided in this embodiment, as Figure 1 shown. The method specifically includes the following steps:

[0044] Step 1: Receive the requested domain name, and collect the user's login information and identity information;

[0045] Step 2: Obtain the obtained requested domain name, analyze and judge the authenticity of the request address or domain name, obtain the user's login information and identity information, and analyze and judge whether the logged-in user has the right to access the domain name;

[0046] In an embodiment of the present invention, during the process of accessing enterprise data through a unique domain name, the data acquisition receiving unit collects data including domain name addresses and identity information, and transmits the acquired data to the judgment unit. The judgment unit verifies the authenticity of the domain name address. The domain names corresponding to the enterprise's business systems are specific, and only the correct domain name can be used to access the enterprise's business systems. After accessing the website based on the correct domain name, the user is guided to log in to collect user identity information. The judgment unit obtains the user identity information for analysis to determine whether the user login information is correct, and uses the sending unit to send a signal to the edge server, and the edge server obtains the enterprise data.

[0047] Exemplarily, the main methods for the judgment unit to analyze the collected data include: analyzing the acquired domain name information and analyzing the identity information. The specific method for analyzing the domain name information is: obtaining the domain name information input by the user, analyzing and verifying the domain name information, comparing the acquired domain name address with the domain name address preset in the system database. When the comparison similarity reaches the preset maximum threshold, the judgment unit is activated to compare the user-entered domain name with the preset domain name in the database. When the comparison result is exactly the same, the user logs in to the website and enters the identity information. When there is a difference in the comparison result, the system pops up a window to prompt that the domain name is incorrect and please re-enter, so as to prevent criminals from using websites with similar domain names to disguise as enterprise websites for information theft or other acts harmful to the interests of the enterprise, and avoid damage to the interests of the enterprise caused by phishing websites; the specific method for analyzing the identity data is: obtaining the identity data entered by the user when logging in, analyzing the user identity data, judging the identity of the user, and detecting whether the user login information exists in the enterprise business system database. If it is detected that it exists in the system database, the information entered by the logged-in user is true and access to the website is allowed. If it does not exist in the system database, the system pops up a window to prompt that the user information is incorrect and please re-enter. After the user logs in successfully, the data displayed on the page are all enterprise-public data, and other data only display the data type module, and there will be no consequences such as data being stolen due to the account being stolen. Therefore, the security performance of this access method and system is guaranteed.

[0048] Step 3: Obtain the user's access request, analyze the user access request to generate an access identifier, and detect the access permission according to the access identifier and identity characteristics;

[0049] In an embodiment of the present invention, during the process of a user accessing a website, access request data of the user is obtained, the access request is analyzed, an access content identifier in the user access request is analyzed and obtained, identity data is obtained, and the identity data is analyzed to obtain an identity identifier. The obtained identity identifier and access content identifier are bound to the user request, and the access request carrying the access content identifier and identity identifier is subjected to access permission detection. Whether to generate a pass token is judged according to the detection result, and the pass token carrying the user access request is sent to the edge server, and the edge server retrieves data from the system and temporarily stores it in the edge server.

[0050] Exemplarily, the specific method for querying access permissions includes the analysis of the user access request and the analysis of the user access permissions. Among them, the specific method for analyzing the user access request is as follows: obtain the access request submitted by the user, extract keywords for the access request, confirm the data type that the user wants to access according to the extracted keywords, divide the permission security level according to the data type, and analyze the permission security level of the data to be accessed by the access request. When the permission security level is higher than the maximum threshold set by the system, the system will initiate dual authentication and send an application to the system administrator, asking for their help to complete the auxiliary verification and help itself complete the access permission verification, so as to achieve the purpose of protecting enterprise data with a high permission security level and further ensure the security of the business system; the specific method for analyzing the user access permissions is as follows: after the system receives the access application, it will verify the access permissions. When the content accessed by the user needs to be verified, the system pops up a window to collect and identify the user's fingerprint or face using the access device, perform identity verification and permission inspection. The system processes the fingerprint and face data received, and the system will not immediately feedback the verification result. Through a program preset in the system, the preset feedback time interval of the permission detection result in the system is T. After a duration of T, the system will feedback the detection result. If access requests are continuously sent to a set of data types within a certain period of time, the system will adjust the feedback duration of the access permission detection result. The feedback duration of the detection result is calculated by the formula y = a * x 2 + T, where the coefficient 0 < a < 1 and T is a constant. It can be easily obtained from the formula that the more access times within a short period, the longer the waiting duration. Therefore, it can effectively prevent scripts from using a fixed life cycle to test the permission defense line of the system, significantly enhancing the security of the system.

[0051] Step 4: Generate a pass token according to the detection result to access the data, submit a temporary access permission application, and generate a temporary pass token;

[0052] In an embodiment of the present invention, an access permission check result is obtained, and based on the analysis result, it is determined whether the user has the permission to access the data. When the detection result shows that the access request has access permission, the user decides whether to generate a pass token, and uses the pass token to carry the user access request to access the enterprise business system to obtain the data the user wants to access. When the access request made by an ordinary user is outside the user's permission scope, the user submits an application for temporary access rights to the data to the system administrator through the temporary permission application unit. The system will collect all the user behaviors of the user before applying for temporary access rights, analyze the user behaviors, obtain the user's access preference, and further analyze whether there is a risk of enterprise data being stolen according to the user access data type and the permission security level. When the user behavior stays on the content related to the enterprise's key technologies all the time, it is determined that there is a security risk in the user behavior, and the temporary permission application submitted by the user will not be approved. If it is determined by the system that the user behavior does not have a risk behavior, and the security level of the access content of the access permission application is below the set threshold, all of them will be approved. When an internal employee submits a temporary permission application, the employee timely uploads relevant work requirement certificates, otherwise the application will not be approved either; for the approved temporary permission applications, the system will generate respective temporary pass tokens according to the application content. The temporary pass token has a valid period, and the system administrator can change and set the valid period. The maximum valid period cannot exceed the threshold preset in the system. When the maximum valid period exceeds the preset threshold, the system will pop up a reminder and clear the set valid period. Click OK to continue to set the valid period of the temporary pass token in compliance. The temporary pass token is different from the pass token. The pass token carries the user access request by itself to achieve the purpose of obtaining access to data. The temporary pass token is generated by the system administrator's review of the target access data according to the access application, that is, the temporary pass token is attached to the access request, so that the confusion and abuse of the pass token will not occur. Therefore, the administrator's management of the system is no longer busy differentiating and managing the pass tokens, making the system operation more convenient and fast.

[0053] Step Five: Receive the access result feedback from the business system and feedback the reason for the access request failure.

[0054] In an embodiment of the present invention, during the data access process, the pass token and the temporary pass token are used as carriers to carry the access data and feedback to the web page. After the edge server obtains the access data, it sends an instruction to the data feedback unit, and uses the data feedback unit to call the verification unit for identity authentication. The verification unit collects user fingerprint and face recognition information data, obtains user authority data collected by the access authority detection unit, and compares the data collected by the verification unit with the data of the access authority detection unit. When the comparison result is completely consistent, the data feedback unit obtains the data from the edge server and feeds it back to the page. When there is a difference in the comparison result, the verification unit sends a signal to the edge server. After receiving the signal, the edge server shreds the temporarily stored data. The secondary verification of the identity information ensures the security of the data and increases the security of the system. The shredding of the data also prevents the leakage of enterprise data. When the access request fails, the request failure feedback unit analyzes the failure step to obtain the failure reason, such as identity authentication failure, unauthorized party, temporary authority application not approved or other reasons. On this basis, system problems can basically be solved in a targeted manner through the reasons fed back by the request failure feedback unit, making the system management more convenient and efficient.

[0055] Embodiment 2: Embodiment 2 of the present invention provides an Internet access method and system. Figure 2 A schematic diagram of the module composition of an Internet access system provided in Embodiment 2 of the present invention is shown in FIG. Figure 2 As shown, the system includes:

[0056] Domain name detection module, used to detect the authenticity of domain names and verify user identities;

[0057] An access rights management module, used for managing access rights;

[0058] The feedback module is used to feed back the accessed data to the web page.

[0059] In some embodiments of the present invention, the domain name detection module includes:

[0060] A receiving unit, used for receiving a domain name and user identity information input by a user;

[0061] A judgment unit, used to judge the authenticity of the domain name and verify the identity of the user;

[0062] The sending unit is used to send the user authority to the edge server, and the edge server obtains data according to the authority.

[0063] In some embodiments of the present invention, the access rights management module includes:

[0064] A user access request acquisition unit, used to acquire user access request data;

[0065] An access permission detection unit for detecting whether a user has access permission;

[0066] A pass token generation unit for generating a pass token to carry a user access request to obtain data;

[0067] A temporary permission application unit for applying for temporary access permission.

[0068] In some embodiments of the present invention, the feedback module includes:

[0069] A data feedback unit for receiving access request data obtained by the edge server;

[0070] A verification unit for verifying the user identity again;

[0071] A request failure feedback unit for feedbacking the reason for the request failure.

[0072] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device.

[0073] Finally, it should be noted that the above are only preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for accessing the Internet, characterized in that: The method comprises the following steps: Step 1: Receive the requested domain name and collect the user's login information and identity information; Step 2: Obtain the requested domain name, analyze and determine the authenticity of the request address or domain name, obtain the user login information and identity information, and analyze and determine whether the logged-in user has the right to access the domain name; Step 3: Obtain the user's access request, analyze the user's access request to generate an access identifier, and detect access rights based on the access identifier and identity features; Step 4: Generate a pass token to access the data based on the test results, submit an application for temporary access rights, and generate a temporary pass token; Step 5: Receive the access result from the business system and provide feedback on the reason for the access request failure; The steps of analyzing and determining the authenticity of the request address or domain name and analyzing and determining whether the logged-in user has the right to access the domain name include: Obtain the domain name information input by the user, analyze and verify the domain name information, compare the obtained domain name address with the domain name address preset in the system database, and when the comparison similarity reaches the preset maximum threshold, start the judgment unit to compare the domain name input by the user with the preset domain name in the database. When the comparison result is exactly the same, the user logs in to the website and enters the identity information. When the comparison result is different, the system feedback pop-up window prompts that the domain name is wrong and please re-enter; Get the identity data entered by the user when logging in, analyze the user's identity data, determine the user's identity, and check whether the user's login information exists in the enterprise business system database. If it is detected in the system database, the information entered by the logged-in user is true and the user is allowed to access the website. If it does not exist in the system database, the system pops up a window to prompt the user that the information is wrong and asks the user to re-enter the information. After the user successfully logs in, the data displayed on the page are all public data of the enterprise, and other data only display the data type module; The steps of analyzing the user access request and generating an access token include: Obtain access requests submitted by users, extract keywords from access requests, confirm the type of data that users want to access based on the extracted keywords, divide the permission security level based on the data type, and analyze the permission security level of the data to be accessed by the access request. When the permission security level is higher than the maximum threshold set by the system, the system will start dual authentication and initiate an application to the system administrator to request their help in completing auxiliary verification; The steps of detecting access rights based on access identifiers and identity features include: After the system receives an access request, it will verify the access permission. When the content accessed by the user needs to be verified, the system pops up a window to collect and identify the user's fingerprint or face using the access device, perform identity verification and check the permission. The system receives the fingerprint and face data for processing. The system will not immediately feedback the verification result. Through a program preset in the system, the preset feedback duration interval of the permission detection result in the system is T. After a duration of T, the system will feedback the detection result. If access requests are continuously sent for a set of data types within a certain period of time, the system will adjust the feedback duration of the access permission detection result. Through the formula Calculate the feedback duration of the detection result, where the coefficient 0 < a < 1 and T is a constant. It is not difficult to conclude from the formula that the more accesses are made within a short period of time, the longer the waiting duration will be; The steps of generating a pass token to access data based on the detection result, submitting an application for temporary access permission, and generating a temporary pass token include: Get the access permission check result, and determine whether the user has the permission to access the data based on the analysis result. When the detection result shows that the access request has the access permission, the user decides whether to generate a pass token, and uses the pass token to carry the user access request to access the enterprise business system to obtain the data the user wants to access. When the access request made by an ordinary user is not within the user's permission range, the user submits an application for temporary access to the data to the system administrator through the temporary permission application unit. The system will collect all user behaviors before the user applies for temporary access, analyze the user behavior data, analyze the user behavior to obtain the user's access preference, and further analyze whether the user behavior is at risk of enterprise data being stolen based on the user's access data type and permission security level. When the user behavior has been staying in the content related to the enterprise's key technologies, If the system determines that the user's behavior does not involve risk, and the security level of the access content of the access permission application is below the set threshold, all applications will be approved. When internal employees submit temporary permission applications, they should upload relevant work requirement certificates in time, otherwise the application will not be approved. For approved temporary permission applications, the system will generate their own temporary pass tokens according to the application content. The temporary pass token has a valid period, which can be changed and set by the system administrator. The maximum valid period cannot exceed the threshold preset in the system. When the maximum valid period exceeds the preset threshold, the system will pop up a window to remind you and clear the set valid period. Click OK to continue to set the valid period of the temporary pass token in compliance. The steps of receiving the access result fed back by the business system and feeding back the reason for the access request failure include: The access token and temporary access token are used as carriers to carry the access data and feedback to the web page. After the edge server obtains the access data, it sends an instruction to the data feedback unit, and uses the data feedback unit to call the verification unit for identity authentication. The verification unit collects user fingerprint and face recognition information data, obtains the user permission data collected by the access permission detection unit, and compares the data collected by the verification unit with the data of the access permission detection unit. When the comparison results are completely consistent, the data feedback unit obtains the data from the edge server and feeds it back to the page. When there is a difference in the comparison results, the verification unit sends a signal to the edge server, and the edge server shreds the temporarily stored data after receiving the signal.

2. An Internet access system, implementing an Internet access method according to claim 1, comprising: Domain name detection module, used to detect the authenticity of domain names and verify user identities; An access rights management module, used for managing access rights; Feedback module, used to feed back the accessed data to the web page; The domain name detection module includes: A receiving unit, used for receiving a domain name and user identity information input by a user; A judgment unit, used to judge the authenticity of the domain name and verify the identity of the user; A sending unit, used to send the user authority to the edge server, and the edge server obtains data according to the authority; The access rights management module includes: A user access request acquisition unit, used to acquire user access request data; An access permission detection unit, used to detect whether a user has access permission; A pass token generation unit, used to generate a pass token to carry user access request acquisition data; A temporary permission application unit is used to apply for temporary access permission; The feedback module includes: A data feedback unit, used to receive access request data obtained by the edge server; A verification unit, used to verify the user's identity again; The request failure feedback unit is used to feedback the reason for the request failure.

Citation Information

Patent Citations

  • Safety system and method for network application

    CN102231745A

  • Internal network access method and device, equipment and storage medium

    CN115277119A