Security access method, device and equipment of virtual private dial-up network and medium

By establishing L2TP tunnels in the VPDN network and utilizing authentication and permission management by the authorization server and firewall controller, the problems of unauthorized access and access control in the VPDN network are solved, achieving secure access control and fine-grained access control, and improving network security.

CN118250047BActive Publication Date: 2025-12-09INDUSTRIAL AND COMMERCIAL BANK OF CHINA +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410338259.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-22
Publication Date
2025-12-09
Estimated Expiration
2044-03-22

AI Technical Summary

Technical Problem

Existing VPDN technology lacks an effective security access control mechanism, which cannot guarantee that the access terminal is a legitimate terminal. This poses a risk of unauthorized terminals accessing the enterprise intranet and makes it impossible to finely control the network access permissions of user terminals, leading to network security issues.

Method used

An L2TP tunnel is established between the LAC router and the LNS router. The authorization server authenticates user terminal information, assigns IP addresses and determines access permissions. Combined with the firewall controller, dynamic access instructions are generated, and authentication information is periodically updated to ensure secure access and fine-grained control.

Benefits of technology

It enables secure access control for user terminals, rejects unauthorized access, finely controls network access permissions, improves network security, and dynamically adjusts access permissions to enhance security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118250047B_ABST
    Figure CN118250047B_ABST
Patent Text Reader

Abstract

The present disclosure provides a security access method of a virtual private dial-up network, which can be applied to the financial field. The method comprises the following steps: in response to a user terminal accessing an LAC router, sending authentication information of the user terminal to the LAC router; the LAC router sending the authentication information to an authorized server of an enterprise intranet through an L2TP tunnel; the authorized server authenticating the authentication information, and allowing the user terminal to access the enterprise intranet in the case that the authentication is successful; the LAC router allocating a corresponding IP address to the user terminal when the user terminal accesses the enterprise intranet; the user terminal sending the IP address and the authentication information to the authorized server, and the authorized server determining the access right of the user terminal in the enterprise intranet according to the authentication information. The present disclosure further provides a security access device of a virtual private dial-up network, equipment, a storage medium and a program product.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the field of communication technology, which can be applied to the field of finance, and more particularly to a secure access method, device, equipment, storage medium and program product of a virtual private dial-up network. BACKGROUND

[0002] The current common VPDN (Virtual Private Dial-up Networks) technology needs professional personnel to provide on-site service and modify the account to an account with a specific suffix at the user terminal. In a conventional case, when the user's existing ordinary broadband network is transformed into a VPDN network, the ordinary broadband account needs to be modified to a VPDN account at the user terminal. The manual on-site modification of the user terminal account is labor-intensive and low in efficiency.

[0003] VPDN is a scheme for expatriate office users to connect to an enterprise intranet through an operator network. The LAC (L2TP Access Concentrator) router (user side) and the LNS (L2TP Network Sever) router (company side) establish an L2TP (Layer 2 Tunneling Protocol) tunnel through the operator network. The user terminal accesses the LAC router to access the enterprise internal network.

[0004] The prior art does not have an effective secure access mechanism, and cannot guarantee that the access terminal is a legal terminal. If an illegal terminal accesses the LAC router, it can also access the enterprise intranet through the LAC router, and even initiate a scanning or attack on the enterprise intranet. The prior art does not control the access permission of the user terminal. After the user terminal accesses the enterprise intranet, there is no fine control of the servers accessible by the terminal at the network level, which may cause unauthorized access at the network level and cause network security problems. SUMMARY

[0005] In view of the above problems, the present disclosure provides a secure access method, device, equipment, storage medium and program product of a virtual private dial-up network. The method solves the secure access of the user terminal in the VPDN network environment, ensures that the terminal accessing the enterprise intranet is a secure user terminal, and rejects the access request of an illegal terminal. The network access permission of the user terminal is finely controlled to improve the network security.

[0006] According to a first aspect of the present disclosure, a secure access method of a virtual private dial-up network is provided, the virtual private dial-up network comprising a LAC router and a LNS router, the LAC router and the LNS router establishing an L2TP tunnel through an operator network, the method comprising: in response to a user terminal accessing the LAC router, sending authentication information of the user terminal to the LAC router; the LAC router sending the authentication information to an authorization server of an intranet through the L2TP tunnel; the authorization server authenticating the authentication information, and in the case that the authentication is successful, allowing the user terminal to access the intranet; when the user terminal accesses the intranet, the LAC router allocating a corresponding IP address to the user terminal; the user terminal sending the IP address and the authentication information to the authorization server, and the authorization server determining an access right of the user terminal in the intranet according to the authentication information.

[0007] According to an embodiment of the present disclosure, the intranet is configured with a plurality of enterprise servers; and the method further comprises: determining the access right of the user terminal in the intranet comprises: determining at least one enterprise server accessible by the user terminal in the plurality of enterprise servers.

[0008] According to an embodiment of the present disclosure, the method further comprises: the authorization server sending the IP address of the user terminal, the IP address of the enterprise server and port information to a firewall controller; and the firewall controller generating a firewall instruction according to the port information and sending the firewall instruction to a firewall, wherein the firewall instruction comprises: allowing the IP address of the user terminal to access the at least one enterprise server and setting an effective duration of the firewall instruction.

[0009] According to an embodiment of the present disclosure, the method further comprises: in the process of the user terminal continuously accessing, the authentication information of the user terminal is periodically sent to the authorization server, wherein the period is less than the effective duration of the firewall instruction; the authorization server sends the authentication information to the firewall controller, and the firewall controller updates the effective duration of the firewall instruction.

[0010] According to an embodiment of the present disclosure, the method further comprises: when the user terminal is offline, the authentication information stops being sent to the authorization server and the firewall controller; and when the effective duration of the firewall instruction exceeds a preset duration, the user terminal cannot access the enterprise server.

[0011] According to an embodiment of the present disclosure, the LAC router sends the authentication information to an authorized server of the intranet through an L2TP tunnel, wherein the L2TP tunnel is established by the following method, including: the LAC router sends the authentication information to the authorized server, and receives domain information of a virtual private dial-up network and address information of an LNS router sent by the authorized server; according to the domain information of the virtual private dial-up network, the LAC router initiates an L2TP tunnel establishment request to the LNS router corresponding to the address information; according to the establishment request, the LAC router and the LNS router establish the L2TP tunnel through an operator network.

[0012] According to an embodiment of the present disclosure, the authorized server determines the access permission of the user terminal in the intranet according to the authentication information, including: the authorized server queries the corresponding permission of the user terminal according to a plurality of preset accessible enterprise server information tables and the authentication information.

[0013] The second aspect of the present disclosure provides a secure access device of a virtual private dial-up network, the virtual private dial-up network including an LAC router and an LNS router, the LAC router and the LNS router establishing an L2TP tunnel through an operator network, the device including: an authentication information response module, configured to send authentication information of a user terminal to the LAC router in response to the user terminal accessing the LAC router; an authentication information sending module, configured to send the authentication information to an authorized server of an intranet by the LAC router through an L2TP tunnel; an intranet access module, configured to authenticate the authentication information by the authorized server, and allow the user terminal to access the intranet if the authentication is successful; a terminal address allocation module, configured to allocate a corresponding IP address to the user terminal by the LAC router when the user terminal accesses the intranet; and an access permission determination module, configured to send the IP address and the authentication information to the authorized server by the user terminal, and determine the access permission of the user terminal in the intranet by the authorized server according to the authentication information.

[0014] According to an embodiment of the present disclosure, the device further includes a firewall control module and a validity duration instruction module, wherein the firewall control module is configured to send the IP address of the user terminal, the IP address of the enterprise server, and port information to a firewall controller by the authorized server; and the validity duration instruction module is configured to generate a firewall instruction and send it to the firewall according to the port information, wherein the firewall instruction includes: allowing the IP address of the user terminal to access at least one enterprise server, and setting the validity duration of the firewall instruction.

[0015] According to an embodiment of the present disclosure, the device further includes an access invalidation module, wherein the access invalidation module is configured to stop the authentication information from being sent to the authorized server and the firewall controller when the user terminal is offline, and to prohibit the user terminal from accessing the enterprise server when the validity duration of the firewall instruction exceeds a preset duration.

[0016] A third aspect of the present disclosure provides an electronic device, comprising: one or more processors; a storage device for storing one or more computer programs, characterized in that the one or more processors execute the one or more computer programs to implement the steps of the above method.

[0017] A fourth aspect of the present disclosure also provides a computer-readable storage medium having stored thereon a computer program, characterized in that the computer program, when executed by a processor, implements the steps of the above method.

[0018] A fifth aspect of the present disclosure also provides a computer program product comprising a computer program, characterized in that the computer program, when executed by a processor, implements the steps of the above method. BRIEF DESCRIPTION OF DRAWINGS

[0019] The above and other objects, features and advantages of the present disclosure will become more apparent from the following description of embodiments of the present disclosure taken in conjunction with the accompanying drawings, in which:

[0020] Figure 1 An application scenario diagram of secure access of a virtual private dial-up network according to an embodiment of the present disclosure is schematically shown;

[0021] Figure 2 A flowchart of a method for establishing an L2TP tunnel according to an embodiment of the present disclosure is schematically shown;

[0022] Figure 3 A flowchart of a firewall control method according to an embodiment of the present disclosure is schematically shown;

[0023] Figure 4 A flowchart of a firewall control method according to an embodiment of the present disclosure is schematically shown;

[0024] Figure 5 A flowchart of a firewall control method according to an embodiment of the present disclosure is schematically shown;

[0025] Figure 6 A structure block diagram of a secure access device of a virtual private dial-up network according to an embodiment of the present disclosure is schematically shown; and

[0026] Figure 7 A block diagram of an electronic device suitable for implementing secure access of a virtual private dial-up network according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION

[0027] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. It should be understood, however, that the description is merely exemplary of the present disclosure, and is not intended to limit the scope of the present disclosure. In the following detailed description of the embodiments of the present disclosure, numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. However, it would be apparent to one skilled in the art that the present disclosure can be practiced without these specific details. In other instances, well known structures and functions have not been described in detail in order to avoid obscuring aspects of the present disclosure.

[0028] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the present disclosure. As used herein, the term "including" "comprising" and the like are meant to be inclusive, but not limiting to the components, steps, operations and / or functions that are described.

[0029] All terms used herein, including technical and scientific terms, have the meanings commonly understood by one of ordinary skill in the art unless otherwise defined. It should be noted that the terms used herein are defined as having meanings that are consistent with the context of the specification in which the terms are used, and should not be interpreted in an idealized or overly formal way.

[0030] In situations where similar terminology is used in a similar manner, one of ordinary skill in the art will be aware that the terminology has a meaning that is consistent with the context in which the terminology is used (e.g., "a system having at least one of A, B, and C" should be interpreted to include, but is not limited to, a system that has only A, only B, only C, a system that has A and B, a system that has A and C, a system that has B and C, and / or a system that has A, B, and C, etc.).

[0031] Some of the blocks and / or combinations of the blocks in the flowcharts can be implemented by computer program instructions. Such computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowcharts and / or flow diagrams block or blocks. The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operations to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus implement the functions / acts specified in the flowcharts and / or flow diagrams block or blocks. The techniques of the present disclosure can be implemented in hardware and / or in software (including firmware, microcode, etc.). Furthermore, the techniques of the present disclosure can be implemented in a computer program product having a computer readable medium storing instructions which, when executed by a processor, cause the processor to perform the methods of the present disclosure.

[0032] In the technical solutions of the present disclosure, the user information (including but not limited to user personal information, user image information, user equipment information such as location information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved are all information and data authorized by the user or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary security measures, do not violate public order and good customs, and provide corresponding operation portals for the user to choose authorization or refusal.

[0033] In the scenario of making automatic decisions by using personal information, the method, device and system provided by the embodiments of the present disclosure all provide corresponding operation portals for the user to choose to agree or refuse the automatic decision result; if the user chooses to refuse, the expert decision process is entered. The expression "automatic decision" herein refers to the activity of automatically analyzing, evaluating the behavior habits, interests and hobbies or economic, health and credit conditions of a person by a computer program and making decisions. The expression "expert decision" herein refers to the activity of making decisions by a person who is specialized in a certain field, has special experience, knowledge and skills and reaches a certain professional level.

[0034] First, the technical terms recorded in this paper are explained and described as follows.

[0035] VPDN (Virtual Private Dial-up Networks) service is a virtual private network service based on dial-up mode opened on the basis of the Internet. It provides users with dial-up access to broadband Internet, uses special network encryption and communication protocols, and can enable enterprises to build a virtual, undisturbed private channel on a public network, thereby safely accessing internal data resources of the enterprise network.

[0036] L2TP (Layer 2 Tunneling Protocol) is a virtual tunneling protocol, usually used in virtual private networks. L2TP protocol itself does not provide encryption and reliability verification functions, and can be used with security protocols to achieve encrypted transmission of data.

[0037] LAC (L2TP Access Concentrator) is one side of the L2TP tunnel endpoint, mainly used to provide connection services for user terminals through PSTN / Internet networks. LAC is located between the remote dial-up user and the LNS device, and is responsible for data forwarding between the remote dial-up user and the LNS device.

[0038] LNS (L2TP Network Sever, L2TP network server) is another side endpoint of the L2TP tunnel, a server device for processing the L2TP protocol, a peer device of the LAC, and a logical termination endpoint for tunnel transmission by the LAC.

[0039] Embodiments of the present disclosure provide a secure access method of a virtual private dial-up network, the virtual private dial-up network comprising an LAC router and an LNS router, the LAC router and the LNS router establishing an L2TP tunnel through an operator network, the method comprising: in response to a user terminal accessing the LAC router, sending authentication information of the user terminal to the LAC router; the LAC router sending the authentication information to an authorization server of an enterprise intranet through an L2TP (protocol) tunnel; the authorization server authenticating the authentication information, and in the case of successful authentication, allowing the user terminal to access the enterprise intranet; when the user terminal accesses the enterprise intranet, the LAC router allocating a corresponding IP address to the user terminal; the user terminal sending the IP address and the authentication information to the authorization server, and the authorization server determining access rights of the user terminal in the enterprise intranet according to the authentication information.

[0040] Through the embodiments of the present disclosure, the secure access of the user terminal in the VPDN network environment is solved, it is ensured that the terminal accessing to the enterprise intranet is a secure user terminal, the access request of an illegal terminal is rejected, and the network access rights of the user terminal are finely controlled, and the network security is improved. In addition, through periodic authentication and instruction issuing, dynamic access authorization is realized, and the security of network access is improved.

[0041] Figure 1 An application scenario diagram of secure access of a virtual private dial-up network according to an embodiment of the present disclosure is schematically shown. It should be noted that, Figure 1 The diagram shown is only an example of an application scenario to which the embodiments of the present disclosure can be applied, to help those skilled in the art understand the technical content of the present disclosure, but does not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments or scenarios.

[0042] As Figure 1 shown, the application scenario 100 according to the embodiment can include terminal devices 101, 102, 103, a network 104 and a server 105. The network 104 is a medium for providing a communication link between the terminal devices 101, 102, 103 and the server 105. The network 104 can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.

[0043] The user can use the terminal devices 101, 102, and 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications can be installed on the terminal devices 101, 102, and 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).

[0044] The terminal devices 101, 102, and 103 can be various electronic devices with display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, etc.

[0045] The server 105 can be a server providing various services, such as a background management server providing support for websites browsed by users using the terminal devices 101, 102, and 103 (only as an example). The background management server can analyze and process received user requests and other data, and feed back the processing results (such as web pages, information, or data, etc. obtained or generated according to user requests) to the terminal devices.

[0046] It should be noted that the security access of the virtual private dial-up network provided by the embodiments of the present disclosure can generally be performed by the server 105. Accordingly, the security access device of the virtual private dial-up network provided by the embodiments of the present disclosure can generally be arranged in the server 105. The security access of the virtual private dial-up network provided by the embodiments of the present disclosure can also be performed by a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, and 103 and / or the server 105. Accordingly, the security access device of the virtual private dial-up network provided by the embodiments of the present disclosure can also be arranged in a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, and 103 and / or the server 105.

[0047] It should be understood that Figure 1 The number of terminal devices, networks, and servers in

[0048] The following will be based on Figure 1 the scenario described below to describe in detail the security access of the virtual private dial-up network of the disclosed embodiments. Figures 2-5

[0049] Figure 2 A flowchart of the security access of the virtual private dial-up network according to the embodiments of the present disclosure is schematically shown. The virtual private dial-up network includes a LAC router and a LNS router, and the LAC router and the LNS router establish an L2TP tunnel through an operator network, as shown in Figure 2 ​As shown, the method can further include operation S210 to operation S250.

[0050] In operation S210, in response to the user terminal accessing the LAC router, authentication information of the user terminal is sent to the LAC router.

[0051] Specifically, the VPDN is composed of a LAC device and a LNS device, wherein the LAC device includes a LAC router and the LNS device includes a LNS router. When the user terminal accesses the LAC router, a security authentication client deployed on the user terminal sends authentication information (e.g., username, password information) to the LAC router.

[0052] In operation S220, the LAC router sends the authentication information to an authorization server of the intranet through an L2TP tunnel.

[0053] In an embodiment of the present disclosure, the LAC router sends the authentication information to the authorization server of the intranet through a preset L2TP over IPsec tunnel for authentication.

[0054] It should be noted that the authorization server is a server program capable of processing user access requests, providing authentication and authorization, and account services, and the main purpose is to manage user access to network servers and provide services to users with access rights. For example, the AAA server (Authentication, Authorization, and Accounting) usually works in cooperation with network access control, gateway servers, databases, and user information directories.

[0055] When the LAC router receives the dial request sent by the user terminal, the account information and password information in the authentication information are not authenticated, and the authentication is released directly, and the authentication information is sent to the AAA server, so that the AAA server authenticates the account information of the user terminal.

[0056] Through the embodiments of the present disclosure, the security access of the user terminal in the VPDN network environment is solved, and it is ensured that the terminal accessing the intranet is a secure user terminal, and the access request of an illegal terminal is rejected.

[0057] In an embodiment of the present disclosure, the L2TP tunnel establishment method is described as follows:

[0058] Figure 3 A flowchart of the L2TP tunnel establishment method according to an embodiment of the present disclosure is schematically shown. As shown, Figure 3 The L2TP tunnel is established by the following method, which can further include operation S310 to S330.

[0059] In operation S310, the LAC router sends the authentication information to the authorization server, and receives domain information of the virtual private dial-up network and address information of the LNS router sent by the authorization server.

[0060] Specifically, if the authorization server authenticates that the user terminal account is a VPDN account (i.e., authentication is passed), the authorization server sends the suffix information of the virtual private dial-up network domain corresponding to the user terminal account and the IP address information of the LNS device to the LAC router. The domain information of the virtual private dial-up network includes, but is not limited to, the suffix information of the virtual private dial-up network domain.

[0061] In operation S320, according to the domain information of the virtual private dial-up network, the LAC router initiates an L2TP tunnel establishment request to the LNS router corresponding to the address information.

[0062] In operation S330, according to the establishment request, the LAC router and the LNS router establish an L2TP tunnel through the operator network.

[0063] Specifically, according to the domain information of the virtual private dial-up network, the LAC device information is determined, and according to the address information of the LNS router, the corresponding LNS device information is determined, and then the LAC router initiates an L2TP tunnel establishment request to the LNS router corresponding to the address information. Based on the establishment request, the LAC router and the LNS router establish an L2TP tunnel through the operator network.

[0064] In operation S230, the authorization server authenticates the authentication information, and in the case of successful authentication, allows the user terminal to access the enterprise intranet.

[0065] In operation S240, when the user terminal accesses the enterprise intranet, the LAC router allocates a corresponding IP address to the user terminal.

[0066] Specifically, the authorization server verifies the authentication information of the user terminal, and if the authentication is successful, returns an authentication success message to the LAC router, and the LAC router allows the user to access the network, and if the authentication fails, sends an authentication failure message to the LAC, and the LAC router refuses the user to access the network. When the authentication is successful, the user terminal can access the enterprise intranet.

[0067] In an embodiment of the present disclosure, the LAC router is provided with a corresponding DHCP (Dynamic Host Configuration Protocol) address pool, and after the user terminal successfully authenticates and accesses the network in the enterprise intranet, the LAC router dynamically allocates a corresponding IP address to the user terminal.

[0068] In operation S250, the user terminal sends the IP address and the authentication information to the authorization server, and the authorization server determines the access permission of the user terminal in the enterprise intranet according to the authentication information.

[0069] In the embodiments of the present disclosure, the user terminal sends the IP address and the authentication information to the authorization server, and the authorization server queries the corresponding right of the user terminal according to the preset plurality of accessible enterprise server information table and the authentication information.

[0070] It should be noted that the intranet of the enterprise is configured with a plurality of enterprise servers, and the user terminal can access at least one of the plurality of enterprise servers.

[0071] Through the embodiments of the present disclosure, the network access right of the user terminal is finely controlled, and the network security is improved.

[0072] Figure 4 The flowchart of the firewall control method according to the embodiments of the present disclosure is schematically shown. As shown in Figure 4 The firewall control method can further include operations S410-S420.

[0073] In operation S410, the authorization server sends the IP address of the user terminal, the IP address of the enterprise server, and the port information to the firewall controller.

[0074] In operation S420, the firewall controller generates a firewall instruction according to the port information and sends it to the firewall, wherein the firewall instruction includes: allowing the IP address of the user terminal to access at least one enterprise server and setting the validity duration of the firewall instruction.

[0075] Specifically, when the authorization server sends the IP address of the user terminal and the IP address and port information of the accessible enterprise server to the firewall controller. The firewall controller generates a corresponding firewall instruction according to the relevant information and sends it to the firewall, for example, the firewall instruction includes: allowing the IP address of the user terminal to access at least one enterprise server and setting the validity duration of the firewall instruction.

[0076] Through the embodiments of the present disclosure, dynamic access authorization is realized through periodic authentication and instruction issuing, and the security of network access is improved.

[0077] Figure 5 The flowchart of the user terminal continuous access processing according to the embodiments of the present disclosure is schematically shown. As shown in Figure 5 The user terminal continuous access processing can further include operations S510-S530.

[0078] In operation S510, during the continuous access of the user terminal, the authentication information of the user terminal is periodically sent to the authorization server, and the period is less than the validity duration of the firewall instruction.

[0079] At operation S520, the authorization server sends the authentication information to the firewall controller.

[0080] At operation S530, the firewall controller updates the validity duration of the firewall instruction.

[0081] Specifically, when the user terminal continuously accesses, the user terminal periodically sends the related authentication information to the authorization server, wherein the period of sending the authentication information should be less than the validity duration of the firewall instruction; after the authorization server receives the authentication information, the authorization server synchronizes the related information to the firewall controller, and the firewall controller refreshes the validity duration of the related instruction on the firewall, thereby guaranteeing the continuous access of the user terminal.

[0082] In the embodiments of the present disclosure, when the user terminal is offline, the authentication information stops being sent to the authorization server and the firewall controller; and when the validity duration of the firewall instruction exceeds the preset duration, the user terminal cannot access the enterprise server. For example, when the user terminal is offline, the access authentication is invalid, and the user terminal no longer periodically sends the authentication information to the authorization server, and the authentication server no longer synchronizes the related information to the firewall controller. In addition, when the firewall instruction expires, the related instruction is invalid, and the instruction of the user to access the enterprise server is terminated.

[0083] Through the embodiments of the present disclosure, the security access of the user terminal in the VPDN network environment is solved, it is ensured that the terminal accessing to the enterprise intranet is a secure user terminal, and the access request of the illegal terminal is rejected. In addition, the network access permission of the user terminal is finely controlled, and the network security is improved. In addition, through the periodic authentication and the instruction issuing, the dynamic access authorization is realized, and the security of the network access is improved.

[0084] Based on the security access of the virtual private dial-up network, the present disclosure further provides a security access device of a virtual private dial-up network. The following will be described in detail in combination with Figure 6 the device.

[0085] Figure 6 The structure block diagram of the security access device of the virtual private dial-up network according to the embodiments of the present disclosure is schematically shown.

[0086] As shown in Figure 6 the security access device 600 of the virtual private dial-up network of the embodiments includes an authentication information response module 610, an authentication information sending module 620, an enterprise intranet access module 630, a terminal address allocation module 640, and an access permission determination module 650.

[0087] In the embodiments of the present disclosure, the virtual private dial-up network includes an LAC router and an LNS router, and the LAC router and the LNS router establish an L2TP tunnel through an operator network.

[0088] The authentication information response module 610 is configured to send authentication information of the user terminal to the LAC router in response to the user terminal accessing the LAC router. In an embodiment, the authentication information response module 610 can be configured to perform operation S210 described above, and details are not repeated here.

[0089] The authentication information sending module 620 is configured to send the authentication information to an authorized server of the intranet by the LAC router through an L2TP tunnel. In an embodiment, the authentication information sending module 620 can be configured to perform operation S220 described above, and details are not repeated here.

[0090] The intranet access module 630 is configured to authenticate the authentication information by the authorized server, and allow the user terminal to access the intranet if the authentication is successful. In an embodiment, the intranet access module 630 can be configured to perform operation S230 described above, and details are not repeated here.

[0091] The terminal address allocation module 640 is configured to allocate a corresponding IP address for the user terminal by the LAC router when the user terminal accesses the intranet. In an embodiment, the terminal address allocation module 640 can be configured to perform operation S240 described above, and details are not repeated here.

[0092] The access permission determination module 650 is configured to send the IP address and the authentication information to the authorized server by the user terminal, and determine access permission of the user terminal in the intranet according to the authentication information by the authorized server. In an embodiment, the access permission determination module 650 can be configured to perform operation S250 described above, and details are not repeated here.

[0093] In an embodiment of the present disclosure, the secure access device 600 of the virtual private dial-up network further comprises a firewall control module, a validity duration instruction module, and an access invalidation module.

[0094] Specifically, the firewall control module is configured to send the IP address of the user terminal, the IP address of the enterprise server, and port information to a firewall controller by the authorized server.

[0095] The validity duration instruction module is configured to generate a firewall instruction according to the port information and send the firewall instruction to a firewall by the firewall controller, wherein the firewall instruction comprises: allowing the IP address of the user terminal to access at least one enterprise server and setting a validity duration of the firewall instruction.

[0096] The access invalidation module is configured to stop the authentication information from being sent to the authorized server and the firewall controller after the user terminal is offline, and prohibit the user terminal from accessing the enterprise server when the validity duration of the firewall instruction exceeds a preset duration.

[0097] According to an embodiment of the present disclosure, any of the authentication information response module 610, the authentication information sending module 620, the intranet access module 630, the terminal address allocation module 640 and the access permission determination module 650 can be combined in one module for implementation, or any of them can be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the authentication information response module 610, the authentication information sending module 620, the intranet access module 630, the terminal address allocation module 640 and the access permission determination module 650 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or any other reasonable way of hardware or firmware that can be integrated or packaged with a circuit, or any one of software, hardware and firmware or a suitable combination of any of them. Alternatively, at least one of the authentication information response module 610, the authentication information sending module 620, the intranet access module 630, the terminal address allocation module 640 and the access permission determination module 650 can be at least partially implemented as a computer program module that can perform corresponding functions when executed.

[0098] Figure 7 A block diagram of an electronic device suitable for implementing secure access of a virtual private dial-up network according to an embodiment of the present disclosure is schematically shown.

[0099] As shown in Figure 7 The electronic device 700 according to an embodiment of the present disclosure includes a processor 701 that can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 702 or loaded from a storage portion 708 into a random access memory (RAM) 703. The processor 701 can include, for example, a general-purpose microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a special-purpose microprocessor (such as an application specific integrated circuit (ASIC)), and the like. The processor 701 can also include an on-board memory for cache use. The processor 701 can include a single processing unit or multiple processing units for performing different actions of the method processes according to embodiments of the present disclosure.

[0100] ​In the RAM 703, various programs and data required for the operation of the electronic device 700 are stored. The processor 701, the ROM 702, and the RAM 703 are connected to each other via the bus 704. The processor 701 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 702 and / or the RAM 703. It should be noted that the programs can also be stored in one or more memories other than the ROM 702 and the RAM 703. The processor 701 can also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.

[0101] According to an embodiment of the present disclosure, the electronic device 700 can further include an input / output (I / O) interface 705, which is also connected to the bus 704. The electronic device 700 can further include one or more of the following components connected to the I / O interface 705: an input part 706 including a keyboard, a mouse, etc.; an output part 707 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage part 708 including a hard disk, etc.; and a communication part 709 including a network interface card such as a LAN card, a modem, etc. The communication part 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the I / O interface 705 as necessary. A removable medium 711 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is mounted on the drive 710 as necessary, so that a computer program read out therefrom is installed in the storage part 708 as necessary.

[0102] The present disclosure also provides a computer readable storage medium, which can be included in the device / apparatus / system described in the above embodiments; or can exist separately without being assembled into the device / apparatus / system. The above computer readable storage medium carries one or more programs, when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.

[0103] According to an embodiment of the present disclosure, the computer readable storage medium can be a nonvolatile computer readable storage medium, for example, can include, but is not limited to, a portable computer diskette, a hard disk, a Random Access Memory (RAM), a Read Only Memory (ROM), an Erasable Programmable Read Only Memory (EPROM or Flash memory), a portable compact disc read only memory (CD-ROM), an optical storage device, a magnetic storage device, or any appropriate combination thereof. In the present disclosure, the computer readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer readable storage medium can include one or more memories such as the ROM 702 and / or the RAM 703 described above and / or one or more memory other than the ROM 702 and the RAM 703.

[0104] Embodiments of the present disclosure also include a computer program product that includes a computer program containing program codes for executing the methods shown in the flowcharts. When the computer program product is run in a computer system, the program codes are used to make the computer system implement the methods provided by the embodiments of the present disclosure.

[0105] The above-described functions defined in the system / device / apparatus of the embodiments of the present disclosure are performed when the computer program is executed by the processor 701. According to an embodiment of the present disclosure, the system, apparatus, module, unit, etc. described above can be implemented by computer program modules.

[0106] In one embodiment, the computer program can rely on a tangible storage medium such as an optical storage device, a magnetic storage device, etc. In another embodiment, the computer program can also be transmitted, distributed, and downloaded in the form of a signal on a network medium and installed and / or mounted through the communication part 709 and / or from the detachable medium 711. The program codes contained in the computer program can be transmitted by any appropriate network medium, including but not limited to wireless, wired, etc., or any appropriate combination thereof.

[0107] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 709 and / or from the detachable medium 711. When the computer program is executed by the processor 701, the above-described functions defined in the system of the embodiments of the present disclosure are performed. According to an embodiment of the present disclosure, the system, apparatus, device, module, unit, etc. described above can be implemented by computer program modules.

[0108] According to embodiments of the present disclosure, program code of the computer program for performing the methods provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages, and can be implemented in a computer program product. Specifically, the computer program can be implemented in a high-level procedural and / or object-oriented programming language, and / or in assembly / machine language. The programming language includes, but is not limited to, Java, C++, python, “C” language, or similar programming languages. The program code can execute entirely on the user's computing device, partly on the user's device, and partly on a remote computing device, or entirely on the remote computing device or server. In the latter scenario, the remote computing device can be connected to the user's computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computing device, such as through the Internet using an Internet Service Provider (ISP).

[0109] The computer program product of the present disclosure can be a computer program product, which is a machine-readable medium (or computer readable medium) having stored therein a sequence of instructions executable by a machine such as a personal digital assistant (PDA), a laptop, a desktop computer, or a server. Alternatively, the computer program product can be a propagated signal per se generated by using the program code, and the program code can be stored on a machine-readable medium that can be read by a machine such as a personal digital assistant (PDA), a laptop, a desktop computer, or a server. The program code of the computer program product defines a function, preferably a corresponding action, and / or implements the elements / object / means for performing this function or a part thereof as disclosed in the embodiments of the present disclosure. The program code can be executed by using one or more processors.

[0110] Those skilled in the art will understand that features of the various embodiments and / or claims of the present disclosure can be combined or / and integrated with one another, even though such a combination or integration is not expressly disclosed in the present disclosure. In particular, the features of the various embodiments and / or claims of the present disclosure can be combined or / and integrated with one another in any combination, without departing from the spirit and teachings of the present disclosure. All such combinations and / or integrations are within the scope of the present disclosure.

[0111] The above describes embodiments of the present disclosure. However, these embodiments are merely for illustrative purposes, and are not intended to limit the scope of the present disclosure. Although each embodiment is described above separately, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Those skilled in the art can make various substitutions and modifications without departing from the scope of the present disclosure, and these substitutions and modifications should all fall within the scope of the present disclosure.

Claims

1. A security access method of a virtual private dial-up network, the virtual private dial-up network comprising a LAC router and a LNS router, the LAC router and the LNS router establishing an L2TP tunnel through an operator network, characterized in that, The method comprises: In response to the user terminal accessing the LAC router, sending authentication information of the user terminal to the LAC router; The LAC router sends the authentication information to an authorization server of the intranet through an L2TP tunnel; The authorization server authenticates the authentication information, and allows the user terminal to access the intranet if the authentication is successful; When the user terminal accesses the intranet, the LAC router allocates a corresponding IP address to the user terminal; The user terminal sends the IP address and the authentication information to the authorization server, and the authorization server determines the access right of the user terminal in the intranet according to the authentication information; The authorization server sends the IP address of the user terminal, the IP address of the enterprise server and the port information to a firewall controller; According to the port information, the firewall controller generates a firewall instruction and sends it to the firewall, wherein the firewall instruction includes: allowing the IP address of the user terminal to access at least one enterprise server and setting the validity period of the firewall instruction; During the continuous access of the user terminal, the authentication information of the user terminal is periodically sent to the authorization server, wherein the period is less than the validity period of the firewall instruction; The authorization server sends the authentication information to the firewall controller; The firewall controller updates the validity period of the firewall instruction.

2. The secure access method of virtual private dial-up network according to claim 1, wherein, The intranet is configured with a plurality of enterprise servers; The determination of the access right of the user terminal in the intranet comprises: Determining at least one enterprise server accessible to the user terminal in the plurality of enterprise servers.

3. The method for security access of virtual private dial-up network according to claim 1, wherein, The method further comprises: When the user terminal is offline, the authentication information stops being sent to the authorization server and the firewall controller; and When the validity period of the firewall instruction exceeds a preset period, the user terminal cannot access the enterprise server.

4. The method for security access of virtual private dial-up network according to claim 1, wherein, The LAC router sends the authentication information to the authorization server of the intranet through an L2TP tunnel, wherein the L2TP tunnel is established by the following method, comprising: The LAC router sends the authentication information to the authorization server, and receives domain information of a virtual private dial-up network and address information of an LNS router sent by the authorization server; According to the domain information of the virtual private dial-up network, the LAC router initiates an L2TP tunnel establishment request to the LNS router corresponding to the address information; According to the establishment request, the LAC router and the LNS router establish an L2TP tunnel through an operator network.

5. The method for secure access of a virtual private dial-up network of claim 1, wherein, The authorization server determines the access right of the user terminal in the intranet according to the authentication information, comprising: The authorization server queries the corresponding right of the user terminal according to a plurality of preset accessible enterprise server information tables and the authentication information.

6. A security access device of a virtual private dial-up network, the virtual private dial-up network comprising a LAC router and a LNS router, the LAC router and the LNS router establishing a L2TP tunnel through a carrier network, characterized in that, The device comprises: An authentication information response module for sending authentication information of the user terminal to the LAC router in response to the user terminal accessing the LAC router; The authentication information sending module is configured to send the authentication information to an authorized server of the enterprise intranet through an L2TP tunnel by the LAC router. The enterprise intranet access module is configured to authenticate the authentication information by the authorized server, and allow the user terminal to access the enterprise intranet if the authentication is successful. The terminal address allocation module is configured to allocate a corresponding IP address to the user terminal by the LAC router when the user terminal accesses the enterprise intranet. The access permission determination module is configured to send the IP address and the authentication information to the authorized server by the user terminal, and determine the access permission of the user terminal in the enterprise intranet by the authorized server according to the authentication information. The device further comprises a firewall control module and a validity duration instruction module, wherein The firewall control module is configured to send the IP address of the user terminal, the IP address of the enterprise server and the port information to the firewall controller by the authorized server. The validity duration instruction module is configured to generate a firewall instruction and send it to the firewall according to the port information by the firewall controller, wherein the firewall instruction comprises: allowing the IP address of the user terminal to access at least one enterprise server and setting the validity duration of the firewall instruction.

7. The secure access device of a virtual private dial-up network of claim 6, wherein, The device further comprises an access invalidation module, wherein The access invalidation module is configured to stop the authentication information from being sent to the authorized server and the firewall controller when the user terminal is offline, and prohibit the user terminal from accessing the enterprise server when the validity duration of the firewall instruction exceeds a preset duration.

8. An electronic device, comprising: one or more processors; a storage device for storing one or more computer programs, characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1-5.

9. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method according to any one of claims 1-5.

10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method according to any one of claims 1-5. The computer program is executed by the processor to implement the steps of the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • 3G virtual private dialing network user safety authentication method and device thereof

    CN101867476A

  • KR20230095727A