Access control method, device, equipment, medium and program product of application gateway
By receiving and parsing URL requests through an application gateway, and utilizing configuration files and authentication mechanisms, the data security problem of having multiple terminal devices in an enterprise network is solved, achieving more efficient access control and data protection.
Patent Information
- Application Number
- CN202410741996.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-07
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2044-06-07
AI Technical Summary
In the private networks of enterprises or other organizations, how can we ensure the data security of applications when there are a large number of terminal devices, especially the low data access security when access control is performed through application gateways?
The application gateway receives URL requests from terminal devices, parses access requirements and current access records, uses pre-configured configuration files to determine access permissions, performs authentication, and ensures that the target access result is returned after legitimate access, thereby achieving targeted interception and redirection and ensuring data security.
It improves the legitimacy and security of access to target business applications, reduces the risk of data leakage, and enhances the efficiency and security of access control.
Smart Images

Figure CN118473814B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of network, in particular to an access control method and device of application gateway, equipment, medium and program product. BACKGROUND
[0002] Application gateway is a kind of network (Web) traffic (Open System Interconnect (OSI) layer 7) load balancer, which can be used to control the traffic of Web application. The traditional load balancer operates at the transport layer (OSI layer 4-TCP and UDP), and routes the traffic to the target IP address and port based on the source IP address and port.
[0003] In the private network / dedicated network of enterprises or other organizations, it is usually necessary to install security management software in the terminal device to control the access of the terminal device to the application deployed in the private network / dedicated network through the security management software. However, when the number of terminal devices requesting connection is large, how to guarantee the data security of the application becomes a problem to be solved. SUMMARY
[0004] Therefore, the present disclosure provides an access control method and device of application gateway, equipment, medium and program product to solve the problem of low data access security.
[0005] In a first aspect, the present disclosure provides an access control method of application gateway, the method comprising:
[0006] receiving a uniform resource locator (URL) request sent by a first terminal device, the URL request being used to request access to a target business application deployed in a first network;
[0007] parsing the URL request to determine an access requirement for the target business application and a current access record of the first terminal device;
[0008] determining an access permission of the first terminal device to the target business application through a preset first configuration file, the first configuration file comprising an access permission between a plurality of business applications and the first network;
[0009] if the access permission represents that the first terminal device is allowed to access, performing identity verification on the first terminal device based on the current access record, and determining a target access result of accessing the target business application based on the access requirement when the identity verification result is passed;
[0010] feeding back the target access result to the first terminal device to respond to the URL request.
[0011] In a second aspect, the present disclosure provides an access control device of an application gateway, the device comprising:
[0012] a first receiving module configured to receive a network resource locator (URL) request sent by a first terminal device, the URL request being used to request access to a target service application deployed in a first network;
[0013] a parsing module configured to parse the URL request, and determine an access requirement for the target service application and a current access record of the first terminal device;
[0014] a first processing module configured to determine, by using a preset first configuration file, an access right of the first terminal device to the target service application, the first configuration file comprising a plurality of access rights between service applications and the first network;
[0015] a second processing module configured to, if the access right represents that the first terminal device is allowed to access, perform identity verification on the first terminal device based on the current access record, and determine a target access result of accessing the target service application based on the access requirement if the identity verification result is passed;
[0016] a feedback module configured to feed back the target access result to the first terminal device in response to the URL request.
[0017] In a third aspect, the present disclosure provides a computer device, comprising a memory and a processor, the memory and the processor being communicatively connected with each other, the memory storing computer instructions, and the processor executing the computer instructions to perform the access control method of the application gateway according to the first aspect or any one of the corresponding embodiments thereof.
[0018] In a fourth aspect, the present disclosure provides a computer readable storage medium, the computer readable storage medium storing computer instructions, and the computer instructions being used to make a computer perform the access control method of the application gateway according to the first aspect or any one of the corresponding embodiments thereof.
[0019] In a fifth aspect, the present disclosure provides a computer program product, the computer program product comprising computer instructions, and the computer instructions being used to make a computer perform the access control method of the application gateway according to the first aspect or any one of the corresponding embodiments thereof.
[0020] The application gateway access control method provided by the embodiment can guarantee the access security of the target service application by determining the access permission of the first terminal device to the target service application through the URL request, and then in the case that the first terminal device can access the target service application, the target access result finally fed back to the first terminal device is determined based on the access demand of the first terminal device to the target service application and the current access record, so that the data access security of the target service application can be effectively guaranteed, and the legality and security of the target service application being accessed can be improved. BRIEF DESCRIPTION OF DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the specific embodiments of the present disclosure or the prior art, the drawings needed to be used in the specific embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present disclosure, and other drawings can also be obtained by those skilled in the art without creative labor.
[0022] Figure 1 is a system architecture schematic diagram of an access control system according to an embodiment of the present disclosure;
[0023] Figure 2 is a flow schematic diagram of an application gateway access control method according to an embodiment of the present disclosure;
[0024] Figure 3 is a flow schematic diagram of another application gateway access control method according to an embodiment of the present disclosure;
[0025] Figure 4 is a structural block diagram of an application gateway access control device according to an embodiment of the present disclosure;
[0026] Figure 5 is a flow schematic diagram of still another application gateway access control method according to an embodiment of the present disclosure;
[0027] Figure 6 is a structural block diagram of another application gateway access control device according to an embodiment of the present disclosure;
[0028] Figure 7 is a hardware structure schematic diagram of a computer device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0029] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be implemented in various forms and should not be interpreted as being limited to the embodiments set forth herein, but rather, these embodiments are provided so as to more completely and thoroughly understand the present disclosure. It is understood that the drawings and embodiments of the present disclosure are for exemplary purposes only and are not intended to limit the scope of protection of the present disclosure.
[0030] In the description of embodiments of the present disclosure, the term "comprising" and its conjugations should be understood as open-ended, i.e., "including but not limited to". The term "based on" should be understood as "based at least in part on". The term "one embodiment" or "an embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". Other explicit and implicit definitions can also be included below.
[0031] In this document, unless explicitly stated, performing a step "in response to A" does not mean performing the step immediately after A, but can include one or more intermediate steps.
[0032] It can be understood that the data involved in the technical solutions of the present disclosure (including but not limited to the data itself, the obtaining, use, storage or deletion of the data) should comply with the requirements of relevant laws and regulations and relevant provisions.
[0033] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the type of information involved in the present disclosure, the scope of use, the use scenario, etc. should be informed to the relevant user and the authorization of the relevant user should be obtained by appropriate means, wherein the relevant user can include any type of right subject, such as an individual, an enterprise, or a group.
[0034] For example, in response to receiving a user's active request, a prompt message is sent to the relevant user to explicitly prompt the relevant user that the operation requested to be performed will require obtaining and using the information of the relevant user, so that the relevant user can voluntarily choose whether to provide information to the software or hardware such as electronic devices, application programs, servers or storage media that perform the operation of the technical solutions of the present disclosure according to the prompt message.
[0035] As an optional but non-limiting implementation manner, in response to receiving an active request of a relevant user, the manner of sending a prompt message to the relevant user can be, for example, a pop-up window manner, in which the prompt message can be presented in the form of text. In addition, the pop-up window can also carry selection controls for the user to select "agree" or "disagree" to provide information to the electronic device.
[0036] It can be understood that the above notification and user authorization obtaining process is only illustrative and does not limit the implementation of the present disclosure, and other ways that meet relevant laws and regulations can also be applied to the implementation of the present disclosure.
[0037] Office security generally involves network, identity, and terminal security management. Through the implementation of proprietary network networking, access control, management of terminals in the proprietary network, and information security protection, digital office can be more secure, efficient, and easy to use. Network-level security management can ensure that the proprietary network such as the office network can operate safely and efficiently, and further ensure that business data can be transmitted and stored safely. Identity-level security management can improve the efficiency and security of user access to the proprietary network. Terminal-level security management can achieve unified management of terminal devices in the proprietary network, data leak prevention, and terminal threat protection, thereby ensuring the security of enterprise data.
[0038] In actual application, network, identity, and terminal security management can achieve technical association in multiple technical branches such as networking strategy, network access and control, remote access, unified terminal management, terminal detection and response, enterprise data leak prevention, and identity authentication management, so as to make digital office simpler, more efficient, and easier to implement.
[0039] In the related art, the terminal device of the external network can access the enterprise-level application deployed in the enterprise intranet through the pre-set proxy server. However, when the number of terminal devices requesting access is large, how to ensure the data security of the enterprise-level application in the enterprise intranet becomes a problem to be solved.
[0040] Therefore, the present disclosure provides an application gateway access control method. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0041] As Figure 1As shown, the system architecture of the access control system adopted by the embodiments of the present disclosure mainly includes a plurality of terminal devices, an application gateway and a server where a service application server is located. Wherein, the internal members of an enterprise can access application resources such as application programs hosted in a data center in a first network, a public cloud, a private cloud, and SaaS applications, etc. through a service application client on the terminal device. The application gateway is deployed in the headquarters, branch network, Internet Data Center (IDC machine room) or cloud service (such as public cloud, private cloud) of the enterprise. The application gateway is connected with each service application server hosted in the first network, and is used to control the terminal device to access the application resources of each service application. The server where the service application server is located is used to provide services for the corresponding service application client.
[0042] In the present embodiment, an access control method of an application gateway is provided, which can be used in a computer device such as a proxy server, a gateway, Figure 2 is a flowchart of the access control method of the application gateway according to the embodiments of the present disclosure, as Figure 2 shown, the flow includes the following steps:
[0043] Step S201, receiving a uniform resource locator (URL) request sent by a first terminal device.
[0044] Wherein, the URL request is used to request to access a target service application deployed in a first network. The target service application can be understood as a service application that needs to be managed in a targeted manner and is pre-deployed in the first network. The first terminal device can be accessed through the Internet. Wherein, the first terminal device can be a terminal device deployed in the first network with the target service application, or a terminal device deployed in other network offline, which is not limited here.
[0045] When detecting the URL request sent by the first terminal device, the access security of the target service application is guaranteed, and the URL request is intercepted to identify whether the first terminal device can access the target service application based on the URL request.
[0046] Step S202, parsing the URL request to determine the access demand for the target service application and the current access record of the first terminal device.
[0047] To determine the access purpose of the first terminal device accessing the target service application, the URL request is parsed, the data operation required by the first terminal device on the data in the target service application is determined, and whether the first terminal device has accessed the target service application is determined, and then the access demand for the target service application and the current access record of the first terminal device are determined, so that the purpose of the first terminal device accessing the target service application can be better understood. For example, by parsing the parameters and parameter values in the URL request, the specific data operation required by the first terminal device can be determined, such as reading, writing, deleting, downloading, etc. Parsing other related information in the request, such as user identity, access time, etc., can also help determine the context and limitation of the access demand.
[0048] In some optional implementation scenarios, the URL request can be parsed by a preset parsing tool. For example, the parsing tool can be a Hypertext Transfer Protocol (HTTP) request parsing library or a Uniform Resource Locator (URL) parsing library used in World Wide Web (web) development, which can be selected according to actual needs.
[0049] In step S203, the access permission of the first terminal device to the target service application is determined through a preset first configuration file.
[0050] The first configuration file includes access permissions between a plurality of service applications and the first network. To ensure the access security of the target service application, the access permission between the target service application and the first network is determined from the access permissions between the plurality of service applications and the first network, so as to determine whether the first terminal device can access the target service application.
[0051] In step S204, if the access permission represents that the first terminal device is allowed to access, the identity of the first terminal device is verified based on the current access record, and when the identity verification result is verified, the target access result of accessing the target service application is determined based on the access demand.
[0052] If the access permission represents that the first terminal device is allowed to access, in order to ensure the data security of the target service application, the identity of the first terminal device is verified based on the current access record, to ensure whether the current access of the first terminal device to the target service application is a legal access. If the identity verification result is verified, it represents that the current access of the first terminal device to the target service application is a legal access, and therefore, in order to ensure the data security of the target application, the access redirection processing is performed based on the access demand, to ensure the legality and security of the access, so as to obtain a suitable target access result.
[0053] Step S205, feeding back the target access result to the first terminal device in response to the URL request.
[0054] The target access result is fed back to the first terminal device, so that the first terminal device can determine whether the sent URL request is valid according to the obtained target access result, so that subsequent targeted processing can be performed, unnecessary polling or waiting time is reduced, and the performance of the system is thus improved.
[0055] The application gateway access control method provided in the embodiment can guarantee the access security of the target service application by determining the access permission of the first terminal device to the target service application through the URL request, and then in the case where it is determined that the first terminal device can access the target service application, the target access result fed back to the first terminal device is determined based on the access demand of the first terminal device to the target service application and the current access record, so that the data access security of the target service application can be effectively guaranteed, and the legality and security of the target service application being accessed can be improved.
[0056] In some optional embodiments, in the process of authenticating the first terminal device based on the current access record, the following steps are included:
[0057] Step a1, obtaining the historical access record of the first terminal device;
[0058] Step a2, authenticating the first terminal device based on the matching result between the current access record and the historical access record;
[0059] Step a3, if the matching result represents that there is the same access record as the current access record in the historical access record, it is determined that the authentication result is passed;
[0060] Step a4, if the matching result represents that there is no access record same as the current access record in the historical access record, it is determined that the authentication result is not passed.
[0061] Specifically, the access record includes any one or more of the following record data: the device identifier of the first terminal device, the currently used access account, the request initiation location corresponding to the URL request, the operating system corresponding to the first terminal device, the Internet protocol address or local area network address corresponding to the first terminal device.
[0062] To determine whether the access of the first terminal device is legitimate, the historical access information of the first terminal device is acquired to determine the historical access of the first terminal device to the target service application. The current access record is matched with the historical access record to verify whether the current access is normal access through the historical access record. If the matching result indicates that there is the same access record as the current access record in the historical access record, it indicates that the current access of the first terminal device is reasonable, and therefore, it is determined that the identity verification result is verification passed. If the matching result indicates that there is no access record same as the current access record in the historical access record, it indicates that the current access of the first terminal device is unreasonable, and therefore, it is determined that the identity verification result is verification failed.
[0063] The identity verification based on the historical access record of the user can not only ensure the access security of the target application, but also effectively improve the user experience.
[0064] In some optional embodiments, in the process of determining the access demand to the target service application, if the URL request includes a download field, it is determined that the access demand to the target service application is data download. That is, in the process of parsing the URL request, the URL request is field-parsed. If there is a " / download" field in the URL, it is determined that the access demand to the target service application is data download.
[0065] If the URL request includes a target field representing data protection, it is determined that the access demand to the target service application is to access the protected data in the target service application. That is, the target field can be a field defined by the business demand itself. In the process of parsing the URL request, whether there is a field matching the target field in the URL request is identified through field matching. If it is identified that there is a field matching the target field in the URL request, it is determined that the access demand to the target service application is data protection.
[0066] An access control method of an application gateway is provided in the embodiment, Figure 3 is a flowchart of the access control method of the application gateway according to the embodiment of the disclosure, as Figure 3 shown, the flow includes the following steps:
[0067] Step S301, receiving a uniform resource locator (URL) request sent by a first terminal device.
[0068] Step S302, parsing the URL request to determine the access demand to the target service application and the current access record of the first terminal device.
[0069] Step S303, determining the access right of the first terminal device to the target service application through a preset first configuration file.
[0070] Step S304, if the access permission represents that the first terminal device is allowed to access, then based on the current access record, the first terminal device is authenticated.
[0071] Step S305, when the authentication result is passed, based on the access requirement, a target access result of accessing the target service application is determined.
[0072] Specifically, the step S305 includes:
[0073] Step S3051, when the authentication result is passed, if the access requirement is data download, then through the preset second configuration file, a first operation permission of allowing the first terminal device to access the target service application is determined.
[0074] The second configuration file includes at least one data operation permission of allowing the first terminal device to access the target service application, and the second configuration file is obtained through the permission configuration platform. The data operation permission corresponding to the data download is a download permission.
[0075] When the authentication result is passed, it represents that the first terminal device can access the target service application. In order to ensure the data security of the target application, the first operation permission of the first terminal device that can be executed on the target service application is determined through the second configuration file.
[0076] Step S3052, if the operation corresponding to the first operation permission does not include the download permission, then the URL request is blocked, and a preset access error page is taken as the target access result of the target service application.
[0077] If the operation corresponding to the first operation permission does not include the download permission, it represents that the first terminal device can access the target service application, but cannot perform the download operation on the target service application. Therefore, the URL request is blocked, and the preset access error page is taken as the target access result of the target service application, so as to prompt the first terminal device through the access error page that the URL request is an invalid request, and further to protect the data security of the target service application and reduce the occurrence of data leakage.
[0078] In some optional embodiments, the step S305 further includes:
[0079] Step S3053, if the access requirement is to access the protected data in the target service application, then the first terminal device is authenticated again.
[0080] If the access demand is to access the protected data in the target service application, the characterization of the access demand requested by the first terminal device affects the data security of the target service application. Therefore, in order to protect the data security of the target service application, the access identity of the first terminal device is verified again to protect the access security of the target service application in a continuous verification manner, so as to ensure the access reliability of the target service application.
[0081] In some optional embodiments, the process of secondary identity verification of the first terminal device can be as follows: redirecting the URL request to the identity authentication page of the identity authentication system, and sending the identity authentication page to the first terminal device to perform secondary identity verification of the first terminal device by the identity authentication system; if the URL request sent again by the first terminal device is received within a specified time period, it is determined that the secondary identity verification of the first terminal device is passed; if the URL request sent again by the first terminal device is not received within the specified time period, it is determined that the secondary identity verification of the first terminal device is failed.
[0082] That is, in order to protect the access legality of the first terminal device, the URL request is redirected to the identity authentication page of the identity authentication system, so as to perform secondary identity verification of the access identity of the first terminal device by the identity authentication system, and the identity authentication page is sent to the first terminal device to prompt the first terminal device to perform identity verification processing. The identity verification through the identity authentication page includes but is not limited to any one or a combination of multiple verification methods, such as inputting a dynamic password, sending a specified short message, or sending an email. The identity authentication content includes but is not limited to any one or multiple dimensions of identity, such as a login account for accessing the target service application, a model of the first terminal device, a login geographic location for accessing the target service application, an operating system corresponding to the first terminal device, an Internet address where the first terminal device is located, and a MAC (Media Access Control address, a network device address, etc.
[0083] Since the purpose of secondary identity verification of the first terminal device is to further determine the access legality of the first terminal device. Because, in order to protect the effectiveness of identity verification, a specified time period is preset to limit the effective time period of identity verification. For example, the specified time period can be 6 hours or 5 minutes, and the specific time period can be set according to the demand, which is not limited here.
[0084] If the URL request sent by the first terminal device again is received within the specified time length, it is determined that the access identity verification of the first terminal device is passed, and it is considered that the access identity of the first terminal device is a legal identity, and then the URL request sent by the first terminal device can be satisfied. If the URL request sent by the first terminal device again is not received within the specified time length, it is determined that the access identity verification of the first terminal device is not passed, and it is considered that the access identity of the first terminal device is an illegal identity, and the URL request sent by the first terminal device is intercepted.
[0085] In step S3054, if the secondary identity verification of the first terminal device is passed, the application access result page corresponding to the access demand in the target service application is subjected to data protection processing, and the processed application access result page is taken as the target access result.
[0086] If the secondary identity verification of the first terminal device is passed, it is considered that the access identity of the first terminal device is a legal identity. Therefore, in order to satisfy the access demand of the first terminal device and protect the protected data in the target service application, the application access result page corresponding to the access demand in the target service application is subjected to data protection processing, so as to protect the data in the application access result page by means of data protection processing, and then the processed application access result page is taken as the target access result, so as to satisfy the access demand of the first terminal device when the target access result is fed back to the first terminal device.
[0087] In some optional embodiments, the data protection processing process of the application access result page can include: determining the application access result page corresponding to the access demand in the target service application, and then adding a preset target identifier to the application access result page to obtain the processed application access result page. By adding a preset target identifier to the application access result page, the specific data access operation performed by the first terminal device on the application access result page can be determined, and the data of the target service application can be effectively prevented from being tampered with, thereby helping to enhance the data security and traceability of the target service application. The target identifier can be a specified unique identifier or a specified tracking code, and the specific identifier content can be determined according to the demand.
[0088] In step S306, the target access result is fed back to the first terminal device to respond to the URL request.
[0089] The application gateway access control method provided by the embodiment can determine the access permission of the first terminal device to the target service application through the preset first configuration file, can realize centralized access control management, can improve access security efficiency, can reduce the occurrence of missed identification, and can further control the access of the first terminal device to the target service application by verifying the access identity of the first terminal device in the case where it is determined that the first terminal device can access the target service application, can effectively improve the data access security of the target service application, and can guide the first terminal device to the application access result page required by the first terminal device according to the access requirement, so as to provide more accurate and personalized access results.
[0090] In some optional embodiments, in the case where the first terminal device is allowed to access the target service application, the process of accessing the target service application by the first terminal device further includes: obtaining a data access record of the first terminal device accessing protected data in the target service application, so that the running condition of the target service application can be determined according to the data access record. In order to optimize the utilization of resources and response speed, the protected data in the data access record is processed to reduce the amount of redundant and invalid data storage, and then a target access record that can be used to manage the target service application in a targeted manner is obtained.
[0091] In other optional embodiments, in order to ensure the reliability of the first configuration file, the first configuration file is obtained from the permission configuration platform and saved at a preset period, so that when the first configuration file is updated, the updated first configuration file can be obtained in time, and the effectiveness of the subsequent control of the first terminal device accessing the target service application can be ensured, thereby effectively improving the access security and data security of the target service application. The first configuration file includes the access permission between a plurality of service applications and corresponding terminal devices. The preset period can be determined according to actual requirements, for example, the first configuration file is obtained from the permission configuration platform and saved every 5 minutes. For another example, the first configuration file is obtained from the permission configuration platform and saved every 30 seconds.
[0092] In still other optional embodiments, the manner of obtaining the first configuration file further includes: receiving an incremental first configuration file pushed by the permission configuration platform, updating the first configuration file through the incremental first configuration file, and saving the updated first configuration file, so that the first configuration file in the application gateway can be updated in time, the data synchronization between the application gateway and the permission configuration platform is realized, and the effectiveness and reliability of the targeted control of the access to the target service application are improved.
[0093] In some optional examples, to ensure network security, the first configuration file obtained may also include access control rules, routing rules, security policies, etc., for access by different target business applications.
[0094] This disclosure also provides an application gateway, the structural block diagram of which can be as follows: Figure 4 As shown, it includes: control plane and data plane.
[0095] The control plane connects to the permission configuration platform and retrieves the first configuration file from the platform at preset intervals, saving it to local memory and disk. The first configuration file includes, but is not limited to, access control rules, routing rules, security policies, and access permissions between multiple business applications and their corresponding terminal devices for access by different target business applications. The permission configuration platform can perform real-time rule increments and change pushes based on event-driven mechanisms, enabling the control plane to promptly obtain the updated first configuration file. To conserve network resources, the first configuration file stored in local memory is sent to the execution module connected to the control plane for caching updates via local offline storage to synchronize the first configuration file.
[0096] The control plane also provides configuration management functions for the access control devices managing the application gateway, including operations such as uploading, modifying, backing up, and restoring the primary configuration file, enabling administrators to flexibly manage and adjust the application gateway's access control devices. The control plane also provides services to the data module, including traffic forwarding, routing, acceleration, and load balancing, to ensure high network performance and stability.
[0097] There must be at least one data plane, connected to servers corresponding to multiple target business applications, supporting various deployment architectures such as public cloud, private cloud, and hybrid cloud. The data plane is used to redirect access to error pages, authentication pages from an authentication system, or application access result pages after data protection processing. During data plane operation, the first configuration file, the first terminal device, and the corresponding access information can be cached in memory and parsed specifically in memory, thereby quickly determining the final target access result.
[0098] Since the first configuration file is cached in the memory of the application gateway's access control device, even without a public network, the first terminal device can still be controlled to access the target business application on the intranet through the locally cached first configuration file.
[0099] As one or more specific application examples of the embodiments of the present disclosure, the access control device taking the application gateway as an example. When a user needs to access a target service application through a first terminal device, the application gateway controls the interactive process of the first terminal device accessing the target service application, which can be as shown in Figure 5
[0100] The configuration phase: the control plane of the application gateway first acquires a first configuration file from the permission configuration platform, and the permission configuration platform responds by sending the first configuration file to the control plane of the application gateway. The control plane of the application gateway saves the acquired first configuration file to the memory and the disk, and then synchronizes the first configuration file to the data plane of the application gateway to ensure the security of the first configuration file.
[0101] The control phase: the user sends a URL request for the target service application through the first terminal device. The data plane of the application gateway receives the URL request. The URL request is parsed to determine the access demand for the target service application and the current access record of the first terminal device. The access permission of the first terminal device to the target service application is determined through the preset first configuration file. If the access permission represents that the access of the first terminal device is allowed, the identity of the first terminal device is verified based on the current access record, and when the identity verification result is passed and the access demand is data download, the URL request is blocked, and a preset access error page is taken as a target access result of the target service application. The target access result is fed back to the first terminal device to respond to the URL request.
[0102] If the access permission represents that the access of the first terminal device is allowed, the identity of the first terminal device is verified based on the current access record, and when the identity verification result is passed and the access demand is to access the protected data in the target service application, the URL request is redirected to an identity authentication page of an identity authentication system, and the identity authentication page is sent to the first terminal device. The first terminal device accesses the identity authentication page to send a verification result to the identity authentication system. The identity authentication system responds according to the received verification result. If the access identity authentication of the first terminal device is passed, the first terminal device sends the URL request again. If the data plane of the application gateway receives the URL request sent by the first terminal device again within a specified time length, it is determined that the access identity authentication of the first terminal device is passed. When the secondary identity authentication of the first terminal device is passed, the server of the target service application is connected to determine an application access result page corresponding to the access demand in the target service application, a preset target identifier is added to the application access result page, and the processed application access result page is taken as a target access result and fed back to the first terminal device.
[0103] In the process that the first terminal device accesses the target service application through the application gateway, an access record of the first terminal device accessing the target service application is acquired, and data processing is performed on protected data corresponding to a target field in the access record, to obtain a target access record.
[0104] By the access control method of the application gateway, the access to the target service application is more secure and reliable, and the data security of the target service application is effectively guaranteed.
[0105] In the embodiment, an access control device of the application gateway is also provided, which is used to implement the above-described embodiments and preferred embodiments, and will not be described again. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, implementation of hardware, or a combination of software and hardware, is also possible and contemplated.
[0106] The embodiment provides an access control device of the application gateway, as shown in Figure 6 The access control device of the application gateway comprises:
[0107] The first receiving module 601 is configured to receive a uniform resource locator (URL) request sent by a first terminal device, the URL request being used to request access to a target service application deployed in a first network;
[0108] The parsing module 602 is configured to parse the URL request, and determine an access demand for the target service application and a current access record of the first terminal device;
[0109] The first processing module 603 is configured to determine, by using a preset first configuration file, an access right of the first terminal device to the target service application, the first configuration file comprising a plurality of access rights between service applications and the first network;
[0110] The second processing module 604 is configured to, if the access right represents that the first terminal device is allowed to access, perform identity verification on the first terminal device based on the current access record, and determine a target access result of accessing the target service application based on the access demand when the identity verification result is passed;
[0111] The feedback module 605 is configured to feed back the target access result to the first terminal device, to respond to the URL request.
[0112] In some optional embodiments, the second processing module 604 comprises:
[0113] The obtaining unit is configured to obtain a historical access record of the first terminal device;
[0114] The first verification unit is configured to perform identity verification on the first terminal device based on a matching result between the current access record and the historical access record.
[0115] The first determination unit is configured to determine that the identity verification result is a verification pass if the matching result indicates that there is an access record identical to the current access record in the historical access record.
[0116] The second determination unit is configured to determine that the identity verification result is a verification fail if the matching result indicates that there is no access record identical to the current access record in the historical access record.
[0117] The access record includes any one or more of the following record data: a device identifier of the first terminal device, a currently used access account, a request initiation location corresponding to the URL request, an operating system corresponding to the first terminal device, an Internet protocol address or a local area network address corresponding to the first terminal device.
[0118] In some optional embodiments, the parsing module 602 includes:
[0119] The first parsing unit is configured to determine that the access demand for the target service application is data download if the URL request includes a download field.
[0120] The second parsing unit is configured to determine that the access demand for the target service application is to access protected data in the target service application if the URL request includes a target field indicating data protection.
[0121] In some optional embodiments, the second processing module 604 includes:
[0122] The first determination unit is configured to determine, by using a preset second configuration file, a first operation permission allowing the first terminal device to access the target service application if the access demand is data download, the second configuration file including at least one data operation permission allowing the first terminal device to access the target service application, the second configuration file being obtained through a permission configuration platform, and the data operation permission corresponding to data download being a download permission.
[0123] The first execution unit is configured to block the URL request and use a preset access error page as a target access result for the target service application if the operation corresponding to the first operation permission does not include the download permission.
[0124] In some optional embodiments, the second processing module 604 includes:
[0125] The second execution unit is configured to perform secondary identity verification on the first terminal device if the access demand is to access protected data in the target service application.
[0126] The third execution unit is configured to, if the secondary identity verification of the first terminal device is passed, perform data protection processing on an application access result page corresponding to the access demand in the target service application, and take the processed application access result page as the target access result.
[0127] In some optional embodiments, the third execution unit comprises:
[0128] The second determination unit is configured to determine an application access result page corresponding to the access demand in the target service application.
[0129] The identification adding unit is configured to add a preset target identification to the application access result page to obtain a processed application access result page.
[0130] In some optional embodiments, the apparatus further comprises:
[0131] The first obtaining module is configured to obtain a data access record of the first terminal device accessing protected data in the target service application.
[0132] The third processing module is configured to perform data processing on the protected data in the data access record to obtain a target access record.
[0133] In some optional embodiments, the first configuration file obtaining apparatus comprises:
[0134] The second obtaining module is configured to obtain the first configuration file from the permission configuration platform according to a preset period and save the first configuration file.
[0135] In some optional embodiments, the first configuration file obtaining apparatus further comprises:
[0136] The second receiving module is configured to receive an incremental first configuration file pushed by the permission configuration platform.
[0137] The updating module is configured to update the first configuration file by using the incremental first configuration file, and save the updated first configuration file.
[0138] Further function descriptions of the above-mentioned various modules and units are the same as those of the above-mentioned corresponding embodiments, and will not be described here.
[0139] The access control apparatus of the application gateway in the embodiment is presented in the form of a functional unit. The unit herein refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and a memory executing one or more software or fixed programs, and / or other devices that can provide the above-mentioned functions.
[0140] The present disclosure further provides a computer device having the above-mentionedFigure 6 The access control device of the application gateway.
[0141] Referring to Figure 7 Figure 7 is a structural schematic diagram of a computer device provided by an optional embodiment of the present disclosure, as Figure 7 shown, the computer device includes one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are communicatively connected by different buses, and can be installed on a common motherboard or in other manners as needed. The processor can process instructions executed within the computer device, including instructions stored in the memory or on the memory to display a GUI on an external input / output device, such as a display device coupled to the interface. In some optional embodiments, multiple processors and / or buses can be used with multiple memories and multiple memories, if necessary. Similarly, multiple computer devices can be connected, each providing part of the necessary operations (e.g., as a server array, a group of blade servers, or a multi-processor system). Figure 7 In the above description, the processor 10 is taken as an example.
[0142] The processor 10 can be a central processor, a network processor, or a combination thereof. The processor 10 can further include a hardware chip. The hardware chip can be an application specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device can be a complex programmable logic device, a field programmable logic gate array, a generic array logic, or any combination thereof.
[0143] The memory 20 stores instructions executable by the at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiments.
[0144] The memory 20 can include a program storage area and a data storage area. The program storage area can store an operating system and application programs required by at least one function; the data storage area can store data created according to the use of the computer device, etc. In addition, the memory 20 can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some optional embodiments, the memory 20 can optionally include a memory remotely arranged with respect to the processor 10, which can be connected to the computer device through a network. Examples of the network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0145] The memory 20 can include a volatile memory, such as a random access memory, and / or can include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive. The memory 20 can also include a combination of the above-mentioned types of memory.
[0146] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 can be connected by a bus or other means, Figure 7 The bus connection is taken as an example.
[0147] The input device 30 can receive inputted digital or character information and generate key signal inputs related to user settings and function controls of the computer device, such as a touch screen, a keypad, a mouse, a trackpad, a touchpad, a pointing stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 can include a display device, an auxiliary lighting device (e.g., an LED), a tactile feedback device (e.g., a vibration motor), etc. The display device includes, but is not limited to, a liquid crystal display, a light emitting diode, a display and a plasma display. In some alternative embodiments, the display device can be a touch screen.
[0148] The embodiments of the present disclosure further provide a computer readable storage medium, and the method according to the embodiments of the present disclosure can be implemented in hardware, firmware, or recorded in a storage medium, or be implemented by computer code originally stored in a remote storage medium or a non-transitory machine readable storage medium and downloaded to a local storage medium, so that the method described herein can be processed by such software on a storage medium using a general purpose computer, a special purpose processor or programmable or special hardware. The storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk or a solid state disk, etc. Further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that the computer, the processor, the microprocessor controller or the programmable hardware include a storage component that can store or receive software or computer code, when the software or computer code is accessed and executed by the computer, the processor or the hardware, the method shown in the above embodiments is implemented.
[0149] Part of the present application can be applied as a computer program product, for example, computer program instructions, when executed by a computer, through the operation of the computer, can invoke or provide the method and / or technical solutions according to the present application. Those skilled in the art should understand that the form of computer program instructions in computer readable medium includes but is not limited to source file, executable file, installation package file and the like, and accordingly, the way of computer program instructions executed by computer includes but is not limited to: the computer directly executes the instructions, or the computer compiles the instructions and then executes the corresponding compiled program, or the computer reads and executes the instructions, or the computer reads and installs the instructions and then executes the corresponding installed program. Here, the computer readable medium can be any available computer readable storage medium or communication medium accessible to the computer.
[0150] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the type of personal information involved in the present disclosure, the use range, the use scene and the like should be informed to the user and the authorization of the user should be obtained through appropriate means according to relevant laws and regulations.
[0151] For example, in response to receiving the active request of the user, the prompt information is sent to the user to explicitly prompt the user that the operation requested to be executed will need to obtain and use the personal information of the user. Thus, the user can voluntarily choose whether to provide the personal information to the software or hardware such as electronic device, application program, server or storage medium which executes the operation of the technical solutions of the present disclosure according to the prompt information.
[0152] As an optional but non-limiting implementation manner, in response to receiving the active request of the user, the way of sending the prompt information to the user may, for example, be the way of pop-up window, and the prompt information may, for example, be presented in the form of text in the pop-up window. In addition, the pop-up window may, for example, carry the selection control for the user to select "agree" or "disagree" to provide the personal information to the electronic device.
[0153] It can be understood that the above notification and obtaining of user authorization process is only illustrative, and does not limit the implementation manner of the present disclosure, and other manners meeting the relevant laws and regulations can also be applied to the implementation manner of the present disclosure.
[0154] Although the embodiments of the present disclosure are described in conjunction with the drawings, various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present disclosure, and such modifications and changes fall within the scope defined by the appended claims.
Claims
1. An access control method for an application gateway, characterized in that, The method includes: The system receives a network resource locator (URL) request sent by a first terminal device. The URL request is used to request access to a target business application deployed in a first network. The target business application is a business application that is pre-deployed in the first network and needs to be managed. Parse the URL request to determine the access requirement for the target business application and the current access record of the first terminal device; The access permissions of the first terminal device to the target service application are determined by a preset first configuration file. The first configuration file includes access permissions between multiple service applications and the first network. If the access permission indicates that the first terminal device is allowed to access, then based on the current access record, the first terminal device is authenticated, and if the authentication result is successful, the target access result for accessing the target business application is determined based on the access requirement. The target access result is fed back to the first terminal device in response to the URL request; Determining the target access result for the target business application based on the access request includes: If the access request is data download, then a first operation permission is determined by a preset second configuration file to allow the first terminal device to access the target business application. The second configuration file includes at least one data operation permission that allows the first terminal device to access the target business application. The second configuration file is obtained through a permission configuration platform, and the data operation permission corresponding to the data download is a download permission. If the operation corresponding to the first operation permission does not include the download permission, then the URL request is blocked, and the preset access error page is used as the target access result for the target business application. If the access request is to access protected data in the target business application, then the first terminal device will undergo secondary authentication. If the second authentication of the first terminal device is successful, data protection processing is performed on the application access result page corresponding to the access requirement in the target business application, and the processed application access result page is used as the target access result.
2. The method according to claim 1, characterized in that, The step of authenticating the first terminal device based on the current access record includes: Obtain the historical access records of the first terminal device; Based on the matching result between the current access record and the historical access record, the first terminal device is authenticated; If the matching result indicates that there is an access record in the historical access record that is identical to the current access record, then the authentication result is determined to be successful. If the matching result indicates that there is no access record in the historical access records that is identical to the current access record, then the authentication result is determined to be authentication failure. The access record includes any one or more of the following record data: the device identifier of the first terminal device, the currently used access account, the request initiation location corresponding to the URL request, the operating system corresponding to the first terminal device, and the Internet Protocol address or local area network address corresponding to the first terminal device.
3. The method according to claim 1, characterized in that, The process of parsing the URL request to determine the access requirement for the target business application includes: If the URL request includes a download field, then the access requirement for the target business application is determined to be data download; If the URL request includes a target field representing data protection, then the access request for the target business application is determined to be access to the protected data in the target business application.
4. The method according to claim 1, characterized in that, The secondary authentication of the first terminal device includes: The URL request is redirected to the identity authentication page of the identity authentication system, and the identity authentication page is sent to the first terminal device so as to perform secondary authentication on the first terminal device through the identity authentication system; If the URL request is received again from the first terminal device within the specified time period, it is determined that the second authentication of the first terminal device has passed. If no URL request is received again from the first terminal device within the specified time period, it is determined that the second authentication of the first terminal device has failed.
5. The method according to claim 1, characterized in that, The data protection processing for the application access result page corresponding to the access request in the target business application includes: Determine the application access result page in the target business application that corresponds to the access requirement; A preset target identifier is added to the application access results page to obtain the processed application access results page.
6. The method according to claim 1, characterized in that, The methods for obtaining the first configuration file include: According to a preset cycle, the first configuration file is retrieved from the permission configuration platform and saved.
7. The method according to claim 6, characterized in that, The method for obtaining the first configuration file also includes: Receive the incremental first configuration file pushed by the permission configuration platform; The first configuration file is updated using the incremental first configuration file, and the updated first configuration file is saved.
8. An access control device for an application gateway, characterized in that, The device includes: The first receiving module is used to receive a network resource locator (URL) request sent by the first terminal device. The URL request is used to request access to a target business application deployed in the first network. The target business application is a business application that is pre-deployed in the first network and needs to be managed in a targeted manner. The parsing module is used to parse the URL request, determine the access requirements for the target business application and the current access records of the first terminal device; The first processing module is used to determine the access permissions of the first terminal device to the target service application through a preset first configuration file, wherein the first configuration file includes access permissions between multiple service applications and the first network. The second processing module is configured to, if the access permission characterization allows the first terminal device to access, authenticate the first terminal device based on the current access record, and, if the authentication result is successful, determine the target access result for accessing the target business application based on the access requirement. The feedback module is used to send the target access result back to the first terminal device in response to the URL request; The second processing module includes: The first determining unit is configured to, if the access request is data download, determine a first operation permission that allows the first terminal device to access the target business application through a preset second configuration file. The second configuration file includes at least one data operation permission that allows the first terminal device to access the target business application. The second configuration file is obtained through a permission configuration platform, and the data operation permission corresponding to the data download is a download permission. The first execution unit is configured to block the URL request if the operation corresponding to the first operation permission does not include the download permission, and to use the preset access error page as the target access result for the target business application. The second execution unit is used to perform secondary authentication on the first terminal device if the access request is to access protected data in the target business application. The third execution unit is used to perform data protection processing on the application access result page corresponding to the access requirement in the target business application if the second authentication of the first terminal device is successful, and to use the processed application access result page as the target access result.
9. A computer device, characterized in that, include: A memory and a processor are communicatively connected, the memory stores computer instructions, and the processor executes the computer instructions to perform the access control method of the application gateway according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to execute the access control method of the application gateway according to any one of claims 1 to 7.
11. A computer program product, characterized in that, Includes computer instructions for causing a computer to execute the access control method of the application gateway according to any one of claims 1 to 7.
Citation Information
Patent Citations
Application access method and device, electronic equipment and storage medium
CN112131588A
Zero-trust network access request processing method and apparatus, and electronic device
CN115701019A
Resource access method and device, equipment and medium
CN116743472A
Access request processing method and device, electronic equipment and storage medium
CN117938515A