Method and apparatus for processing onboarding information of a device, and electronic device

By automating the processing of network access application information for devices awaiting network access, and reviewing and configuring them according to preset rules, the problem of low processing efficiency caused by manual intervention in existing technologies is solved, and efficient processing of network access application information is achieved.

CN118353686BActive Publication Date: 2025-12-09INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410515729.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-26
Publication Date
2025-12-09
Estimated Expiration
2044-04-26

AI Technical Summary

Technical Problem

In existing technologies, manual intervention is required during the processing of equipment network access application information, resulting in low processing efficiency.

Method used

The system employs automated methods to obtain network access application information for devices seeking to join the network, reviews the device information and software installation information according to preset network access review rules, configures the device information in the network access protection system, and achieves fully automated processing.

Benefits of technology

It improves the efficiency of processing network access application information, avoids manual intervention, and realizes automated review and configuration of network access application information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118353686B_ABST
    Figure CN118353686B_ABST
Patent Text Reader

Abstract

The application discloses a kind of processing method, device and electronic equipment of the network application information of equipment.It relates to the field of financial technology or other fields, which comprises: obtaining the network application information of target equipment to be networked, wherein the network application information includes device information of target equipment, software installation information of target equipment;According to the preset network audit rule, the device information and the software installation information are audited, and the target audit result is obtained;In the case where the target audit result represents that the audit is passed, the device information is configured on the network protection system.The application solves the technical problem of low processing efficiency in related art when processing the network application information of the equipment to be networked, as part of the process needs manual participation.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of financial technology or other fields, in particular, to a method and device for processing network access application information of a device and an electronic device. BACKGROUND

[0002] Device network access refers to connecting a new device to an existing network so that it can communicate with other devices in the network and share resources. With the rapid development of the Internet of Things and smart devices, there are numerous attack methods on the network. In order to protect the security of the network, the network access application information of the device needs to be audited before the device is networked, and the related information of the device is recorded in the device for protecting the network after the audit is passed, so that the device can be successfully networked.

[0003] At present, in the related art, when processing the network access application information of the device to be networked, part or all of the process needs to be manually involved, thereby having the problem of low processing efficiency.

[0004] In view of the above problems, no effective solution has been proposed so far. SUMMARY

[0005] Embodiments of the present application provide a method and device for processing network access application information of a device and an electronic device to at least solve the technical problem of low processing efficiency in the related art when processing the network access application information of the device to be networked, because part of the process needs to be manually involved.

[0006] According to an aspect of an embodiment of the present application, a method for processing network access application information of a device is provided, comprising: obtaining network access application information of a target device to be networked, wherein the network access application information comprises device information of the target device and software installation information of the target device; auditing the device information and the software installation information according to a preset network access auditing rule to obtain a target auditing result; and in the case that the target auditing result represents that the auditing is passed, configuring the device information on a network access protection system, wherein the network access protection system is used to protect a target network, and the network access protection system determines first permission information based on a target access request of the target device to the target network and the configured device information in the case that the target access request is received, and the first permission information is used to represent whether the target device is allowed to access the target network.

[0007] Further, the method for processing the device access application information further comprises: extracting target information from the software installation information, wherein the target information comprises at least one of the following: a version number of the installed software, a device serial number, a running state of the installed software; performing a first-level audit on the target information according to the access audit rule to obtain an initial audit result; in a case where the initial audit result indicates that the first-level audit is passed, determining a device serial number of the target device according to the device information to obtain a target device serial number; performing a second-level audit on the target device serial number according to the access audit rule to obtain a target audit result.

[0008] Further, the method for processing the device access application information further comprises: obtaining a first information table, wherein the first information table comprises device serial numbers of devices owned by the target department; in a case where the target device serial number exists in the first information table, determining that the target audit result indicates that the audit is passed; in a case where the target device serial number does not exist in the first information table, obtaining a second information table, wherein the second information table comprises device serial numbers of devices borrowed by the target department; in a case where the target device serial number exists in the second information table, determining that the target audit result indicates that the audit is passed; in a case where the target device serial number does not exist in the second information table, determining that the target audit result indicates that the audit is not passed.

[0009] Further, the access protection system comprises a plurality of network control devices and a plurality of firewall devices, the network control devices are configured to forward access requests of devices to the firewall devices, the firewall devices are configured to determine third permission information according to the received access requests and the configured device information, the third permission information indicates whether the devices are allowed to access the network, wherein the method for processing the device access application information further comprises: obtaining a third information table, wherein the third information table comprises a plurality of network links and matching relationships among the network control devices, the firewall devices and the network links, each network link comprises a source IP address and a destination IP address of a device allowed to access the network, different network control devices and different firewall devices are configured to process access requests on different network links; extracting the source IP address and the destination IP address of the target device from the device information; determining a network link containing the source IP address and the destination IP address of the target device from the third information table to obtain a target network link; determining the network control device and the firewall device matched with the target network link as the network control device and the firewall device matched with the target device; and configuring the device information on the network control device and the firewall device matched with the target device.

[0010] Further, the processing method of the device's network application information further comprises: extracting the MAC address of the target device from the device information to obtain first device sub-information; configuring the first device sub-information on the network control device matched with the target device according to the first configuration script, wherein the network control device matched with the target device determines second permission information according to the target access request and the configured first device sub-information in the case of receiving the target access request, and the second permission information is used to represent whether the target access request is allowed to be forwarded to the firewall device; extracting the source IP address, the destination IP address and the allowed network access time range of the target device from the device information to obtain second device sub-information; configuring the second device sub-information on the firewall device matched with the target device according to the second configuration script, wherein the firewall device matched with the target device determines first permission information according to the target access request and the configured second device sub-information in the case of receiving the target access request.

[0011] Further, the third information table comprises the IP addresses of the network control devices and the IP addresses of the firewall devices, wherein the processing method of the device's network application information further comprises: determining the device model of the network control device matched with the target device according to the IP address of the network control device matched with the target device to obtain a first device model; determining the device model of the firewall device matched with the target device according to the IP address of the firewall device matched with the target device to obtain a second device model; determining the configuration script matched with the first device model as the first configuration script, and determining the configuration script matched with the second device model as the second configuration script.

[0012] Further, the processing method of the device's network application information further comprises: extracting the network access time range allowed for the target device to access the network from the device information after configuring the device information on the network protection system; deleting the device information from the network control device and / or the firewall device matched with the target device in the case that the target time point is after the time terminal point of the network access time range.

[0013] According to another aspect of the embodiments of the present application, a device network application information processing apparatus is also provided, comprising: an obtaining module, configured to obtain network application information of a target device to be networked, wherein the network application information comprises device information of the target device and software installation information of the target device; a processing module, configured to perform an audit on the device information and the software installation information according to a preset network application audit rule, and obtain a target audit result; and a configuring module, configured to configure the device information on a network protection system in a case where the target audit result indicates that the audit is passed, wherein the network protection system is configured to protect a target network, and the network protection system is configured to determine first permission information based on a target access request of the target device to the target network and the configured device information in a case where the target access request is received, and the first permission information is configured to indicate whether the target device is allowed to access the target network.

[0014] According to another aspect of the embodiments of the present application, a computer readable storage medium is also provided, wherein the computer readable storage medium stores a computer program, and the computer program is configured to execute the device network application information processing method when running.

[0015] According to another aspect of the embodiments of the present application, an electronic device is also provided, comprising one or more processors, and a memory configured to store one or more programs, and the one or more programs are configured to enable the one or more processors to implement a program for running when executed, wherein the program is configured to execute the device network application information processing method when running.

[0016] In the embodiments of the present application, the network application information is audited automatically, and the network application information that passes the audit is configured in the network protection system, which comprises the following steps: obtaining network application information of a target device to be networked, wherein the network application information comprises device information of the target device and software installation information of the target device; performing an audit on the device information and the software installation information according to a preset network application audit rule, and obtaining a target audit result; and configuring the device information on a network protection system in a case where the target audit result indicates that the audit is passed, wherein the network protection system is configured to protect a target network, and the network protection system is configured to determine first permission information based on a target access request of the target device to the target network and the configured device information in a case where the target access request is received, and the first permission information is configured to indicate whether the target device is allowed to access the target network.

[0017] In the above process, by auditing the device information and the software installation information according to the preset network access auditing rule, the target auditing result is obtained, the automatic auditing of the network access application information of the target device is realized, by configuring the device information in the network access application information on the network access protection system in the case that the target auditing result represents that the auditing is passed, the automatic configuration of the network access application information is realized, thereby realizing the full-automatic processing mode in the process of processing the network access application information, avoiding the manual participation, and thus effectively improving the processing efficiency of the network access application information.

[0018] Therefore, the scheme provided in the present application achieves the purpose of automatically auditing the network access application information and automatically configuring the network access application information that passes the auditing in the network access protection system, thereby realizing the technical effect of improving the processing efficiency of the network access application information, and further solving the technical problem of low processing efficiency in the related art when processing the network access application information of the device to be accessed. BRIEF DESCRIPTION OF DRAWINGS

[0019] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and serve to explain the principles of the application. In the drawings:

[0020] Figure 1 is a flow of an optional network access application information processing method of a device according to an embodiment of the present application Figure 1 ;

[0021] Figure 2 is a flow of an optional network access application information processing method of a device according to an embodiment of the present application Figure 2 ;

[0022] Figure 3 is a schematic diagram of an optional network access application information processing device of a device according to an embodiment of the present application;

[0023] Figure 4 is a schematic diagram of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0024] In order to enable persons skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by persons skilled in the art without creative labor should fall within the protection scope of the present application.

[0025] It should be noted that the terms "first", "second", and the like in the description and claims of the application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not necessarily limit to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0026] It should be noted that the device's onboarding application information processing method, device and electronic device of the present disclosure can be used in the field of financial technology, and can also be used in any field other than the field of financial technology. The application field of the device's onboarding application information processing method, device and electronic device of the present disclosure is not limited.

[0027] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards in the relevant region, and provide corresponding operation portal for user to choose authorization or refusal.

[0028] Embodiment 1

[0029] According to the embodiments of the present application, an embodiment of a device's onboarding application information processing method is provided. It should be noted that the steps shown in the flowchart of the drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown herein.

[0030] Figure 1 is a flowchart of an optional device's onboarding application information processing method according to an embodiment of the present application Figure 1 As shown in Figure 1 , the method comprises the following steps:

[0031] Step S101, obtaining the onboarding application information of the target device to be on-boarded, wherein the onboarding application information includes device information of the target device and software installation information of the target device.

[0032] Optionally, an electronic device, an application system, a server or the like can be taken as an execution subject of the present application, and in the embodiment, a target processing system is taken as the execution subject to obtain the network access application information. The target device can be a device to be accessed to the internal network of the financial institution.

[0033] Optionally, the network access application information can be sent by the owner (e.g., a user or the like) of the target device to the target processing system through the target device, the device information includes but is not limited to a device serial number of the target device, a MAC (Media Access Control) address of the target device, a source IP (Internet Protocol) address, a destination IP address, a network access time range allowed to access the network, and the like, and the software installation information includes but is not limited to a version number of the installed software, a device serial number of the device to which the software belongs, a running state of the installed software, and the like.

[0034] In step S102, the device information and the software installation information are audited according to a preset network access auditing rule to obtain a target auditing result.

[0035] Optionally, the target processing system can determine whether the target device is owned or borrowed by the target department according to the device information and determine whether the target software is installed in the target device according to the software installation information according to the preset network access auditing rule, so as to determine the target auditing result according to the two obtained determination results.

[0036] In step S103, the device information is configured on a network access protection system in a case where the target auditing result represents that the auditing is passed, the network access protection system is used to protect a target network, and the network access protection system determines first permission information based on a target access request of the target device to the target network and the configured device information in a case where the target access request of the target device to the target network is received, and the first permission information is used to represent whether the target device is allowed to access the target network.

[0037] Optionally, if the target auditing result represents that the auditing is passed, the target device is determined to be a device allowed to access the network, and in this case, the target processing system can configure the device information of the target device on the network access protection system, otherwise, if the target auditing result represents that the auditing is not passed, the device information of the target device is not configured on the network access protection system.

[0038] Optionally, when the target processing system sends a target access request to the target network, the onboarding protection system can determine accurate first permission information based on the target access request and the configured device information. For example, if the device information in the target access request is consistent with the configured device information, it is determined that the first permission information represents that the target device is allowed to access the target network, and if the device information in the target access request is inconsistent with the configured device information, it is determined that the first permission information represents that the target device is not allowed to access the target network.

[0039] Based on the scheme defined in steps S101-S103, it can be known that in the embodiment of the application, the device information of the onboarding application information is automatically audited and automatically configured in the onboarding protection system. The onboarding application information of the target device is obtained, and then the device information and the software installation information are audited according to the preset onboarding auditing rule to obtain a target auditing result, so that the device information is configured on the onboarding protection system when the target auditing result represents that the audit is passed. The onboarding application information includes device information of the target device and software installation information of the target device, the onboarding protection system is used to protect the target network, and the onboarding protection system determines first permission information based on the target access request and the configured device information when receiving a target access request of the target device to the target network. The first permission information is used to represent whether the target device is allowed to access the target network.

[0040] It is easy to note that in the above process, the device information and the software installation information are audited according to the preset onboarding auditing rule to obtain a target auditing result, which realizes automatic auditing of the onboarding application information of the target device. The device information in the onboarding application information is configured on the onboarding protection system when the target auditing result represents that the audit is passed, which realizes automatic configuration of the onboarding application information. Thus, a fully automated processing method is realized in the process of processing the onboarding application information, manual participation is avoided, and the processing efficiency of the onboarding application information is effectively improved.

[0041] Therefore, the scheme provided in the present application achieves the purpose of automatically auditing the onboarding application information and automatically configuring the onboarding application information that passes the audit in the onboarding protection system, thereby realizing the technical effect of improving the processing efficiency of the onboarding application information, and further solving the technical problem of low processing efficiency in the related art when processing the onboarding application information of the device to be on-boarded.

[0042] In an optional embodiment, in the process of auditing the device information and the software installation information according to the preset network access auditing rule to obtain the target auditing result, the target processing system can extract the target information from the software installation information, then perform first-level auditing on the target information according to the network access auditing rule to obtain an initial auditing result, and then in the case that the initial auditing result indicates that the first-level auditing is passed, determine the device serial number of the target device according to the device information to obtain a target device serial number, and then perform second-level auditing on the target device serial number according to the network access auditing rule to obtain the target auditing result. The target information includes at least one of the following: the version number of the installed software, the device serial number, and the running state of the installed software.

[0043] The software installation information can be in the form of a screenshot, text, video, etc. In the case that the software installation information is in the form of a screenshot or video, the target processing system can extract the target information from the software installation information through OCR (Optical Character Recognition).

[0044] After obtaining the target information, the target processing system can perform first-level auditing on the target information according to the network access auditing rule to obtain an initial auditing result. For example, it is determined whether the target software exists in the installed software according to the version number of the installed software, whether the target software is the latest version if the target software exists, whether the device serial number is the device serial number of the target device in the case that the target software exists and is the latest version, and whether the target software is in a normal running state according to the running state of the installed software in the case that the device serial number is the device serial number of the target device. The network access auditing rule can include a first sub-rule, which can indicate that the initial auditing result indicates that the first-level auditing is passed in the case that the target software exists and is the latest version, the device serial number is the device serial number of the target device, and the target software is in a normal running state, and otherwise, the initial auditing result indicates that the first-level auditing is not passed in the case that the target software does not exist, or the target software is not the latest version, or the device serial number is not the device serial number of the target device, or the target software is not in a normal running state. The target software can be an access control software.

[0045] Optionally, in the case that the initial auditing result indicates that the first-level auditing is not passed, the target processing system can directly determine that the target auditing result indicates that the auditing is not passed. In the case that the initial auditing result indicates that the first-level auditing is passed, the target processing system can determine the device serial number of the target device according to the device information to obtain a target device serial number, and then perform second-level auditing on the target device serial number according to the network access auditing rule to obtain the target auditing result.

[0046] The device information can be in the form of a screenshot, text, video, etc. In the case where the device information is in the form of a screenshot or a video, the target processing system can extract the target device serial number from the device information through OCR (Optical Character Recognition).

[0047] It should be noted that, by first auditing the software installation information, and in the case where the software installation information passes the audit, auditing the device information, the efficiency of the audit can be effectively improved, and invalid audits caused by auditing the device information in the case where the software installation information fails the audit can be avoided.

[0048] In an optional embodiment, in the process of performing a second-level audit on the target device serial number according to the network access audit rule to obtain a target audit result, the target processing system can obtain a first information table, and then in the case where the target device serial number exists in the first information table, determine that the target audit result represents an audit pass, and in the case where the target device serial number does not exist in the first information table, obtain a second information table, and in the case where the target device serial number exists in the second information table, determine that the target audit result represents an audit pass, so as to determine that the target audit result represents an audit fail in the case where the target device serial number does not exist in the second information table. The first information table includes device serial numbers of devices owned by the target department, and the second information table includes device serial numbers of devices borrowed by the target department.

[0049] The first information table and the second information table can be preset in the target processing system by the staff, and the target department is a preset department. The network access audit rule can include a second sub-rule, which can represent that in the case where the target device is owned or borrowed by the target department, the target audit result is determined to represent an audit pass, and otherwise, in the case where the target device is not owned or borrowed by the target department, the target audit result is determined to represent an audit fail.

[0050] It should be noted that, through the above process, effective auditing of the device information is achieved, thereby improving the accuracy of the audit.

[0051] In an optional embodiment, the network access protection system comprises a plurality of network control devices and a plurality of firewall devices, the network control devices are configured to forward the access request of the device to the firewall devices, the firewall devices are configured to determine third permission information according to the received access request and the configured device information, the third permission information represents whether the device is allowed to access the network, wherein, in the process of configuring the device information on the network access protection system, the target processing system can obtain a third information table, then extract the source IP address and the destination IP address of the target device from the device information, then determine the network link containing the source IP address and the destination IP address of the target device from the third information table, obtain the target network link, and determine the network control devices and the firewall devices matched with the target network link as the network control devices and the firewall devices matched with the target device, so as to configure the device information on the network control devices and the firewall devices matched with the target device. Wherein, the third information table comprises a plurality of network links and the matching relationship among the network control devices, the firewall devices and the network links, each network link comprises the source IP address and the destination IP address of the device allowed to access the network, and different network control devices and different firewall devices are used to process the access request on different network links.

[0052] Optionally, the network control devices are configured to receive the access request sent by the device, and determine whether to forward the access request to the firewall devices according to the access request and the configured device information, and the firewall devices are configured to forward the access request to the network in the case that the third permission information represents that the device is allowed to access the network, and prohibit forwarding the access request to the network in the case that the third permission information represents that the device is not allowed to access the network.

[0053] Wherein, the third information table can be preset in the target processing system by the staff, if the target device passes the audit, the source IP address and the destination IP address of the target device are default correct addresses, that is, the third information table contains the source IP address and the destination IP address of the target device. Therefore, the target processing system can determine the network link containing the source IP address and the destination IP address of the target device from the third information table, obtain the target network link, and configure the device information on the network control devices and the firewall devices matched with the target network link.

[0054] It should be noted that, since different network control devices and different firewall devices are used to process the access request on different network links, by determining the target network link and configuring the device information on the network control devices and the firewall devices matched with the target network link, it is ensured that when the target device sends a target access request to the target network, the network access protection system can accurately determine whether to forward the target access request to the target network according to the configured information.

[0055] In an alternative embodiment, in the process of configuring device information on the network control device and the firewall device matched with the target device, the target processing system can extract the MAC address of the target device from the device information, obtain first device sub-information, and then configure the first device sub-information on the network control device matched with the target device according to the first configuration script, and then extract the source IP address, the destination IP address, and the allowed network access time range of the target device from the device information, obtain second device sub-information, and then configure the second device sub-information on the firewall device matched with the target device according to the second configuration script, wherein the network control device matched with the target device determines second permission information according to the target access request and the configured first device sub-information in the case of receiving the target access request, and the second permission information is used to represent whether the target access request is allowed to be forwarded to the firewall device, and the firewall device matched with the target device determines first permission information according to the target access request and the configured second device sub-information in the case of receiving the target access request.

[0056] Optionally, the network control device matched with the target device is configured to receive the target access request sent by the target device, and the network control device matched with the target device can determine that the second permission information represents that the target access request is allowed to be forwarded to the firewall device in the case that the MAC address in the target access request is the same as the first device sub-information, and determine that the second permission information represents that the target access request is not allowed to be forwarded to the firewall device in the case that the MAC address in the target access request is different from the first device sub-information.

[0057] Optionally, the firewall device matched with the target device can determine that the first permission information represents that the target device is allowed to access the target network in the case that the source IP address and the destination IP address in the target access request are the same as the source IP address and the destination IP address in the second device sub-information, and the request access time of the target access request is within the network access time range, and otherwise, determine that the first permission information represents that the target device is not allowed to access the target network in the case that the source IP address and the destination IP address in the target access request are different from the source IP address and the destination IP address in the second device sub-information, or the request access time of the target access request is outside the network access time range.

[0058] Wherein, after the first device sub-information is configured on the network control device matched with the target device according to the first configuration script, the target processing system can detect whether the first device sub-information is configured successfully, if not, send the system administrator the information of configuration failure, if yes, configure the second device sub-information, after the second device sub-information is configured on the firewall device matched with the target device according to the second configuration script, the target processing system can detect whether the second device sub-information is configured successfully, if not, delete the first device sub-information on the network control device matched with the target device, and send the system administrator the information of configuration failure, if yes, send the system administrator the information of configuration success.

[0059] It should be noted that through the above process, the effective automatic configuration of device information is realized, thereby improving the efficiency of processing the network access application information, and facilitating the network control device and the firewall device to protect the target network in time.

[0060] In an alternative embodiment, the third information table includes the IP addresses of each network control device and the IP addresses of each firewall device, wherein the target processing system can determine the first configuration script and the second configuration script by the following way: determining the device model of the network control device matched with the target device according to the IP address of the network control device matched with the target device, obtaining the first device model; determining the device model of the firewall device matched with the target device according to the IP address of the firewall device matched with the target device, obtaining the second device model; determining the configuration script matched with the first device model as the first configuration script, and determining the configuration script matched with the second device model as the second configuration script.

[0061] Wherein, the target processing system can be pre-set with multiple configuration scripts matched with the device models of different network control devices, and pre-set with multiple configuration scripts matched with the device models of different firewall devices, and the target processing system can also be pre-set with the matching relationship between the IP addresses of the network control devices and the device models of the network control devices, and the matching relationship between the IP addresses of the firewall devices and the device models of the firewall devices.

[0062] The target processing system can determine the IP address of the network control device matched with the target device from the third information table, and determine the first device model according to the above matching relationship and the IP address of the network control device matched with the target device, and the target processing system can also determine the IP address of the firewall device matched with the target device from the third information table, and determine the second device model according to the above matching relationship and the IP address of the firewall device matched with the target device.

[0063] Afterwards, the target processing system can determine a first configuration script from the plurality of configuration scripts matched with the device model of the different network control devices according to the first device model, and determine a second configuration script from the plurality of configuration scripts matched with the device model of the different firewall devices according to the second device model. The first configuration script is used to configure the first device sub-information on the network control device matched with the target device, and the second configuration script is used to configure the second device sub-information on the firewall device matched with the target device.

[0064] After the first configuration script and the second configuration script are determined, the target processing system can load the first configuration script to the network control device matched with the target device, and run the first configuration script on the network control device to configure the first device sub-information. The target processing system can also load the second configuration script to the firewall device matched with the target device, and run the second configuration script on the firewall device to configure the second device sub-information.

[0065] It should be noted that through the above process, the configuration scripts required by the network control device matched with the target device and the firewall device matched with the target device are accurately determined, thereby facilitating the effective configuration of the device information, and further improving the stability of the processing of the network access application information.

[0066] In an optional embodiment, after the device information is configured on the network access protection system, the target processing system can extract the network access time range in which the target device is allowed to access the network from the device information, and delete the device information from the network control device and / or the firewall device matched with the target device in a case where the target time point is after the time terminal point of the network access time range.

[0067] The target time point can be the current time point. Optionally, a timing task can be run in the target processing system, and the target processing system can read the obtained network access application information through the timing task to determine whether the target time point is after the time terminal point in the network access application information, so as to delete the device information corresponding to the network access application information from the network control device and / or the firewall device matched with the target device in a case where the determination result is yes, and otherwise, retain the device information corresponding to the network access application information in the network control device and the firewall device matched with the target device in a case where the determination result is no.

[0068] It should be noted that through the above process, the device information configured in the network access application information is automatically deleted, thereby further improving the processing efficiency of the network access application information and avoiding manual operation.

[0069] Figure 2This is a flowchart of an optional method for processing network access application information of a device according to an embodiment of the present invention. Figure 2 ,like Figure 2 As shown, an optional application process of this application is described. Figure 2 As shown, after receiving the network access application information of the target device, the target processing system can review the network access application information according to the network access review rules. If the review fails, a return message is sent to the user who owns the target device and the processing ends. If the review is successful, the network access application information can be sent to the department leader for a second review and the department leader's review result can be obtained.

[0070] like Figure 3 As shown, if the department leader's review fails, a return message is sent to the user who owns the target device and the processing ends. If the department leader's review approves, the device information in the network access application information is automatically configured on the network access protection system, thereby completing the processing of the network access application information.

[0071] Therefore, the solution provided in this application achieves the goal of automatically reviewing network access application information and automatically configuring the approved network access application information in the network access protection system, thereby improving the technical efficiency of processing network access application information. This solves the technical problem of low processing efficiency in related technologies when processing network access application information of devices waiting to be connected to the network, due to the need for manual intervention in some processes.

[0072] Example 2

[0073] According to an embodiment of the present invention, an embodiment of a device for processing network access application information is provided, wherein... Figure 3 This is a schematic diagram of an optional device for processing network access application information according to an embodiment of the present invention, such as... Figure 4 As shown, the device includes:

[0074] The acquisition module 301 is used to acquire the network access application information of the target device to be connected to the network, wherein the network access application information includes the device information of the target device and the software installation information of the target device;

[0075] The processing module 302 is used to review the device information and software installation information according to the preset network access review rules, and obtain the target review result;

[0076] The configuration module 303 is used to configure device information on the network access protection system when the target review result indicates that the review has passed. The network access protection system is used to protect the target network. When the network access protection system receives a target access request from the target device to the target network, it determines the first permission information based on the target access request and the configured device information. The first permission information is used to indicate whether the target device is allowed to access the target network.

[0077] It should be noted that the above acquisition module 301, processing module 302 and configuration module 303 correspond to steps S101-S103 in the above embodiment, and the three modules have the same examples and application scenarios as the corresponding steps, but are not limited to the content disclosed in the above embodiment 1.

[0078] Optionally, the processing module 302 further includes: a first extraction sub-module configured to extract target information from the software installation information, wherein the target information includes at least one of the following: a version number of the installed software, a device serial number, a running state of the installed software; a first processing sub-module configured to perform a first-level audit on the target information according to the network access audit rule to obtain an initial audit result; a first determination sub-module configured to determine a device serial number of the target device according to the device information in a case where the initial audit result represents that the first-level audit is passed, to obtain a target device serial number; and a second processing sub-module configured to perform a second-level audit on the target device serial number according to the network access audit rule to obtain a target audit result.

[0079] Optionally, the second processing sub-module further includes: a first acquisition unit configured to acquire a first information table, wherein the first information table includes device serial numbers of devices owned by the target department; a first determination unit configured to determine that the target audit result represents that the audit is passed in a case where the target device serial number exists in the first information table; a second acquisition unit configured to acquire a second information table in a case where the target device serial number does not exist in the first information table, wherein the second information table includes device serial numbers of devices borrowed by the target department; a second determination unit configured to determine that the target audit result represents that the audit is passed in a case where the target device serial number exists in the second information table; and a third determination unit configured to determine that the target audit result represents that the audit is not passed in a case where the target device serial number does not exist in the second information table.

[0080] Optionally, the configuration module 303 further comprises: an acquisition sub-module, configured to acquire a third information table, wherein the third information table comprises a plurality of network links and matching relationships among network control devices, firewall devices and the network links, each network link comprises source IP addresses and destination IP addresses of devices allowed to access a network, and different network control devices and different firewall devices are used to process access requests on different network links; a second extraction sub-module, configured to extract source IP addresses and destination IP addresses of the target device from the device information; a second determination sub-module, configured to determine, from the third information table, a network link containing the source IP addresses and the destination IP addresses of the target device, to obtain a target network link; a third determination sub-module, configured to determine, as network control devices and firewall devices matched with the target device, network control devices and firewall devices matched with the target network link; and a configuration sub-module, configured to configure the device information on the network control devices and the firewall devices matched with the target device.

[0081] Optionally, the configuration sub-module further comprises: a first extraction unit, configured to extract a MAC address of the target device from the device information, to obtain first device sub-information; a first configuration unit, configured to configure the first device sub-information on the network control devices matched with the target device according to the first configuration script, wherein the network control devices matched with the target device are configured to determine second permission information according to the target access request and the configured first device sub-information in a case where the target access request is received, and the second permission information is used to represent whether the target access request is allowed to be forwarded to the firewall devices; a second extraction unit, configured to extract source IP addresses, destination IP addresses and a network access time range of devices allowed to access a network from the device information, to obtain second device sub-information; and a second configuration unit, configured to configure the second device sub-information on the firewall devices matched with the target device according to the second configuration script, wherein the firewall devices matched with the target device are configured to determine first permission information according to the target access request and the configured second device sub-information in a case where the target access request is received.

[0082] Optionally, the device network access application information processing apparatus further comprises: a first determination module, configured to determine a device model of the network control devices matched with the target device according to IP addresses of the network control devices matched with the target device, to obtain a first device model; a second determination module, configured to determine a device model of the firewall devices matched with the target device according to IP addresses of the firewall devices matched with the target device, to obtain a second device model; and a third determination module, configured to determine, as the first configuration script, a configuration script matched with the first device model, and determine, as the second configuration script, a configuration script matched with the second device model.

[0083] Optionally, the device network access application information processing apparatus further comprises an extraction module configured to extract, from the device information, a network access time range during which the target device is allowed to access the network; and a deletion module configured to delete the device information from the network control device and / or the firewall device matched with the target device if the target time point is after a time terminal point of the network access time range.

[0084] Embodiment 3

[0085] According to another aspect of the embodiments of the present application, there is also provided a computer readable storage medium having a computer program stored therein, wherein the computer program is configured to execute the device network access application information processing method when running.

[0086] Embodiment 4

[0087] According to another aspect of the embodiments of the present application, there is also provided an electronic device, wherein Figure 4 is a schematic diagram of an optional electronic device according to an embodiment of the present application, as ​ shown, the electronic device comprises one or more processors; a memory configured to store one or more programs, which, when executed by the one or more processors, cause the one or more processors to implement a program for running, wherein the program is configured to execute the device network access application information processing method when running.

[0088] The above-mentioned embodiment numbers of the present application are only for description, and do not represent the advantages or disadvantages of the embodiments.

[0089] In the above-mentioned embodiments of the present application, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0090] In the several embodiments provided in the present application, it should be understood that the disclosed technology can be implemented in other ways. Of course, the device embodiment described above is only schematic. For example, the division of the units can be a logical function division, and there can be another division manner in actual implementation, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, and can be electrical or other forms.

[0091] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e. they can be located in one place, or can be distributed on a plurality of units. Part or all of the units can be selected according to actual needs to achieve the purpose of the present embodiment scheme.

[0092] In addition, each function unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit.

[0093] If the integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application, essentially or the part that contributes to the prior art, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the embodiments of the method of the present application. The foregoing storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.

[0094] The above is only the preferred embodiment of the present application, and it should be pointed out that for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, and these improvements and refinements should be considered as the protection scope of the present application.

Claims

1. A method for processing network access application information of a device, characterized in that, The method comprises: obtaining network access application information of a target device to be networked, wherein the network access application information comprises device information of the target device and software installation information of the target device; auditing the device information and the software installation information according to a preset network access auditing rule to obtain a target auditing result; in a case where the target auditing result represents that the auditing is passed, configuring the device information on a network access protection system, wherein the network access protection system is used to protect a target network, and the network access protection system, in a case where a target access request of the target device to the target network is received, determines first permission information based on the target access request and the configured device information, the first permission information being used to represent whether the target device is allowed to access the target network; the network access protection system comprises a plurality of network control devices and a plurality of firewall devices, and the network control devices are used to forward access requests of devices to the firewall devices, wherein configuring the device information on the network access protection system comprises: obtaining a third information table, wherein the third information table comprises a plurality of network links and matching relationships among the network control devices, the firewall devices and the network links, each network link comprises a source IP address and a destination IP address of a device allowed to access a network, and different network control devices and different firewall devices are used to process access requests on different network links; extracting the source IP address and the destination IP address of the target device from the device information; determining a network link containing the source IP address and the destination IP address of the target device from the third information table to obtain a target network link; determining the network control device and the firewall device matched with the target network link as the network control device and the firewall device matched with the target device; configuring the device information on the network control device and the firewall device matched with the target device, wherein the firewall device matched with the target device, in a case where the target access request is received, determines the first permission information according to the target access request and the device information.

2. The method of claim 1, wherein, auditing the device information and the software installation information according to a preset network access auditing rule to obtain a target auditing result, comprising: extracting target information from the software installation information, wherein the target information comprises at least one of the following: a version number of an installed software, a device serial number, and a running state of the installed software; performing first-level auditing on the target information according to the network access auditing rule to obtain an initial auditing result; in a case where the initial auditing result represents that the first-level auditing is passed, determining a device serial number of the target device according to the device information to obtain a target device serial number; performing second-level auditing on the target device serial number according to the network access auditing rule to obtain the target auditing result.

3. The method of claim 2, wherein, performing second-level auditing on the target device serial number according to the network access auditing rule to obtain the target auditing result, comprising: obtaining a first information table, wherein the first information table comprises device serial numbers of devices owned by a target department; In a case where the target device serial number exists in the first information table, it is determined that the target audit result represents an audit pass; In a case where the target device serial number does not exist in the first information table, a second information table is obtained, wherein the second information table comprises device serial numbers of devices borrowed by the target department; In a case where the target device serial number exists in the second information table, it is determined that the target audit result represents an audit pass; In a case where the target device serial number does not exist in the second information table, it is determined that the target audit result represents an audit fail.

4. The method of claim 1, wherein, The device information is configured on the network control device and the firewall device matched with the target device, comprising: A MAC address of the target device is extracted from the device information to obtain first device sub-information; The first device sub-information is configured on the network control device matched with the target device according to a first configuration script, wherein the network control device matched with the target device determines second permission information according to the target access request and the configured first device sub-information in a case where the target access request is received, and the second permission information is used to represent whether the target access request is allowed to be forwarded to the firewall device; A source IP address, a destination IP address, and a network access allowed network access time range of the target device are extracted from the device information to obtain second device sub-information; The second device sub-information is configured on the firewall device matched with the target device according to a second configuration script, wherein the firewall device matched with the target device determines the first permission information according to the target access request and the configured second device sub-information in a case where the target access request is received.

5. The method of claim 4, wherein, The third information table comprises IP addresses of each network control device and IP addresses of each firewall device, wherein the first configuration script and the second configuration script are determined by the following manner: A device model of the network control device matched with the target device is determined according to an IP address of the network control device matched with the target device to obtain a first device model; A device model of the firewall device matched with the target device is determined according to an IP address of the firewall device matched with the target device to obtain a second device model; The configuration script matched with the first device model is determined as the first configuration script, and the configuration script matched with the second device model is determined as the second configuration script.

6. The method of claim 1, wherein, After the device information is configured on the network access protection system, the method further comprises: A network access allowed network access time range of the target device is extracted from the device information; In a case where a target time point is after a time terminal point of the network access time range, the device information is deleted from the network control device and / or the firewall device matched with the target device.

7. A device for processing network access application information of a device, characterized in that, A processing method for performing network access application information of a device in any one of claims 1 to 6, comprising: An obtaining module is configured to obtain network access application information of a target device to be accessed to a network, wherein the network access application information comprises device information of the target device and software installation information of the target device; A processing module is configured to perform an audit on the device information and the software installation information according to a preset network access audit rule, and obtain a target audit result; A configuration module is configured to, in a case where the target audit result represents that the audit is passed, configure the device information on a network access protection system, wherein the network access protection system is configured to protect a target network, and the network access protection system is configured to, in a case where a target access request of the target device to the target network is received, determine first permission information based on the target access request and the configured device information, and the first permission information is configured to represent whether the target device is allowed to access the target network.

8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program is configured to execute the processing method of the network access application information of the device in any one of claims 1 to 6 when running.

9. An electronic device, comprising: The electronic device comprises one or more processors; A memory is configured to store one or more programs, and the one or more programs are configured to enable the one or more processors to implement a program running method when executed by the one or more processors, and the program is configured to execute the processing method of the network access application information of the device in any one of claims 1 to 6 when running.

Citation Information

Patent Citations

  • Secure network access method and device, electronic equipment and storage medium

    CN114039779A

  • Internet of Things equipment network access method and device, electronic equipment and storage medium

    CN117424805A