Network access methods, devices, electronic equipment, storage media and products

By using a 5G dual-domain network architecture and security gateway for traffic cleaning and authentication, the problem of secure access for e-government network user terminals has been solved, achieving a highly secure and flexibly controllable network access method.

CN118802320BActive Publication Date: 2025-11-14CHINA MOBILE GROUP ZHEJIANG +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410737220.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-07
Publication Date
2025-11-14
Estimated Expiration
2044-06-07

AI Technical Summary

Technical Problem

Existing network access methods have low security and cannot effectively guarantee the security of e-government network user terminals when accessing e-government network and Internet resources simultaneously.

Method used

A 5G dual-domain network architecture is adopted for data diversion. The access data of user terminals is cleaned and authenticated through a security gateway. Digital circuits are used to isolate the cloud server and the primary network to ensure the security of access data.

Benefits of technology

It improves the security of user terminals accessing the e-government network, prevents unauthorized external connections, enhances the stability and security of network connections, and enables flexible access control and event tracing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802320B_ABST
    Figure CN118802320B_ABST
Patent Text Reader

Abstract

This application relates to the field of network technology, providing a network access method, apparatus, electronic device, storage medium, and product. The method includes: receiving first access data; performing traffic scrubbing on the first access data based on a security gateway to obtain secure access data; and sending the secure access data to a first network via a digital circuit to enable a user terminal to access the first network. Through this method, since the cloud server and the first network can be isolated via digital circuits, even if the first access data contains security risks, it cannot directly affect the first network. Upon receiving the first access data, performing traffic scrubbing on the first access data based on a security gateway to remove potentially risky data and obtain secure access data, and then sending the secure access data to the first network via a digital circuit to enable the user terminal to access the first network, can effectively improve the security of the user terminal's access to the first network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network technology, specifically to a network access method, device, electronic device, storage medium, and product. Background Technology

[0002] E-government networks are an important public infrastructure, serving as public networks for economic regulation, market supervision, social management, and public services. They need to be logically isolated from the internet.

[0003] To ensure the operational security of the e-government network, it is necessary to ensure that every user terminal accessing the e-government network is monitored for unauthorized external connections. If a user terminal accesses both e-government network resources and internet resources simultaneously, there may be a security risk, which will generate an unauthorized external connection alarm and deny the user terminal access to the e-government network.

[0004] However, with the explosive growth of mobile government applications, the demand for mobile office work on e-government networks is constantly increasing. User terminals often need to access both e-government network resources and internet resources simultaneously. Therefore, how to enable user terminals to access e-government networks normally has become an urgent problem to be solved.

[0005] Currently, user terminals can directly access e-government networks via 5G networks or VPNs. However, existing network access methods have low security. Summary of the Invention

[0006] This application provides a network access method, apparatus, electronic device, storage medium, and product to solve the technical problem of low security in existing network access methods.

[0007] In a first aspect, embodiments of this application provide a network access method applied to a first network side, the first network side including a cloud server and a first network, the cloud server being equipped with a security gateway, and the cloud server and the first network being connected via digital circuits; the method includes: receiving first access data; the first access data being obtained by the 5G network side through traffic splitting processing based on the initial access data of the user terminal; performing traffic cleaning processing on the first access data based on the security gateway to obtain secure access data; and sending the secure access data to the first network via digital circuits to enable the user terminal to access the first network.

[0008] In one embodiment, the first network is equipped with a network boundary device, the cloud server is connected to a full-service router via a digital circuit, the full-service router is connected to the network boundary device via a digital circuit, the full-service router is configured with first routing information, and the full-service router and the cloud server are configured with second routing information; sending secure access data to the first network via a digital circuit to enable the user terminal to access the first network includes: sending secure access data to the full-service router via a digital circuit based on the second routing information; and sending secure access data to the first network via a digital circuit based on the full-service router and the first routing information to enable the user terminal to access the first network.

[0009] In one embodiment, the first access data carries first access address information, the cloud server is equipped with a firewall, and the firewall is equipped with third routing information; based on the security gateway, the first access data is subjected to traffic cleaning processing, and before obtaining secure access data, the method further includes: based on the firewall and the third routing information, the first access address information is subjected to address translation processing to generate second access address information; the secure access data is sent to the first network through a digital circuit so that the user terminal can access the first network, including: based on the second access address information, the secure access data is sent to the first network through a digital circuit so that the user terminal can access the first network.

[0010] In one embodiment, the first network is provided with a network boundary device; sending secure access data to the first network via digital circuitry to enable a user terminal to access the first network includes: sending secure access data to the network boundary device of the first network via digital circuitry; authenticating the user terminal based on the network boundary device; and if the user terminal is authenticated, granting access authorization to the user terminal to enable the user terminal to access the first network.

[0011] Secondly, embodiments of this application provide a network access method applied to a 5G network side. The method includes: responding to an access request from a user terminal, determining initial access data of the user terminal based on the access request; sending data splitting rules to a UPF based on an SMF; performing splitting processing on the initial access data based on the UPF and the data splitting rules to obtain first access data and second access data; sending the first access data to the first network side when the user terminal logs into the security gateway of the first network side; and sending the second access data to the Internet when the user terminal logs out of the security gateway.

[0012] In one embodiment, before sending the data splitting rules to the UPF based on the SMF, the method further includes: in response to the user terminal's access request, authenticating and authorizing the user terminal based on the AMF; if the user terminal passes the authentication and authorization, then selecting the corresponding SMF for the user terminal.

[0013] Thirdly, embodiments of this application provide a network access device applied to a first network side, the first network side including a cloud server and a first network, the cloud server being equipped with a security gateway, the cloud server and the first network being connected via digital circuits, the device including: a receiving module for receiving first access data; the first access data is obtained by the 5G network side through traffic splitting processing based on the initial access data of the user terminal; a cleaning module for performing traffic cleaning processing on the first access data based on the security gateway to obtain secure access data; and an access module for sending the secure access data to the first network via digital circuits so that the user terminal can access the first network.

[0014] Fourthly, embodiments of this application provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements any of the network access methods described above applied to the first network side.

[0015] Fifthly, embodiments of this application provide a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements any of the network access methods applied to the first network side as described above.

[0016] Sixthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements any of the network access methods applied to a first network side as described above.

[0017] This application provides a network access method, apparatus, electronic device, storage medium, and product, applied to a first network side. The first network side includes a cloud server and a first network. The cloud server is equipped with a security gateway, and the cloud server and the first network are connected via digital circuits. The method includes: receiving first access data; the first access data is obtained by the 5G network side through traffic splitting processing based on the initial access data of the user terminal; performing traffic cleaning processing on the first access data based on the security gateway to obtain secure access data; and sending the secure access data to the first network via digital circuits to enable the user terminal to access the first network. In this manner, the first network side includes a cloud server and a first network. The cloud server is equipped with a security gateway, and the cloud server and the first network are connected via digital circuits. Since the cloud server and the first network can be isolated through digital circuits, the first access data cannot be directly transmitted to the first network. Even if the first access data has security risks, it cannot directly affect the first network. When the first access data is received, the security gateway performs traffic cleaning processing on the first access data to remove any potentially risky data and obtain secure access data. The secure access data is then sent to the first network through digital circuits so that the user terminal can access the first network, which can effectively improve the security of the user terminal accessing the first network. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is one of the flowcharts illustrating the network access method provided in the embodiments of this application.

[0020] Figure 2 This is the second flowchart of the network access method provided in the embodiments of this application.

[0021] Figure 3 This is the third flowchart of the network access method provided in the embodiments of this application.

[0022] Figure 4 This is a schematic diagram of the network access device provided in the embodiments of this application.

[0023] Figure 5 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0024] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0025] Please see Figure 1 , Figure 1 This is one of the flowcharts illustrating the network access method provided in this application embodiment. In this application embodiment, the network access method is applied to a first network side, which includes a cloud server and a first network. The cloud server is equipped with a security gateway, and the cloud server and the first network are connected via digital circuits. The first network is an intranet of an e-government network. The network access method includes steps S110 to S130, each step as follows:

[0026] S110: Receive the first access data.

[0027] The first access data is obtained by the 5G network side through diversion processing based on the initial access data of the user terminal.

[0028] Please see Figure 2 , Figure 2 This is the second flowchart of the network access method provided in the embodiments of this application.

[0029] The network access method in this application embodiment is implemented based on a 5G dual-domain network architecture. The 5G dual-domain network architecture is a network architecture built on 5G (5th Generation Mobile Communication Technology) technology, designed to provide enterprises and organizations with a higher level of security and network performance. It integrates the advantages of public and private networks, providing users with a more secure and reliable connection through technologies such as physical isolation, encrypted communication, and network slicing.

[0030] like Figure 2 As shown, in the 5G dual-domain network architecture, if a user terminal of the e-government network needs to access both e-government network resources and Internet resources simultaneously, data splitting is required on the 5G network side to divide the user terminal's initial access data into first access data and second access data.

[0031] The first access data is the access data when a user terminal accesses e-government network resources. It is used to access the e-government network and belongs to private network traffic data, that is, traffic data for accessing the e-government network intranet.

[0032] The second access data is the access data when a user terminal accesses Internet resources. It is used to access the Internet and belongs to public network traffic data, that is, traffic data for accessing the external network.

[0033] By separating private network traffic from public network traffic through the 5G network side, the private network traffic data subsequently transmitted to the first network (i.e., the e-government network) does not contain public network traffic data, thus avoiding the security risks that public network traffic data may bring to the first network.

[0034] Optionally, such as Figure 2 As shown, the user terminal (UE) can be a mobile 5G terminal, such as a mobile phone, tablet computer, host computer, etc. that supports 5G communication.

[0035] Specifically, the user terminal can first send an access request to the 5G network side. The access request can also carry initial access data, which includes public network traffic data and private network traffic data.

[0036] Furthermore, in response to the user terminal's access request, the 5G network side determines and extracts the user terminal's initial access data based on the access request, and performs traffic splitting on the initial access data based on the shared UPF (User Plane Function) of the 5G network side to obtain the first access data and the second access data.

[0037] Furthermore, when the user terminal exits the security gateway, the UPF can send the second access data to the Internet; when the user terminal has logged into the security gateway on the first network side, the UPF can send the first access data to the first network side through the GRE tunnel.

[0038] Furthermore, after the UPF sends the first access data to the first network side, the first network side can receive the first access data.

[0039] S120: Based on the security gateway, perform traffic cleaning processing on the first access data to obtain secure access data.

[0040] like Figure 2 As shown, the first network side includes a cloud server and a first network.

[0041] The cloud server uses a private cloud as the government cloud system to ensure data security.

[0042] The cloud server is equipped with a firewall (i.e.) Figure 2 The government cloud boundary firewall connects to a zero-trust VPC (Virtual Private Cloud).

[0043] It's important to note that Zero Trust VPC is a VPC built upon the Zero Trust principle. Zero Trust is a next-generation network security concept that breaks the default "trust," meaning it doesn't trust anyone, device, or system inside or outside the enterprise network by default. It rebuilds the trust foundation of access control based on identity authentication and authorization, thereby ensuring trustworthy identities, devices, applications, and data links. A VPC is a dynamically configured pool of public cloud computing resources that requires the use of encryption protocols, tunneling protocols, and other security procedures to transmit data between the enterprise and the cloud service provider.

[0044] Zero Trust VPC is configured with a security gateway (i.e. Figure 2 The system includes a proxy gateway, a policy center, and a zero-trust system, which are used to implement traffic scrubbing and filtering.

[0045] Understandably, for the intranet of e-government networks, the first access data is not necessarily all secure data. Therefore, traffic cleaning and filtering are required before the first access data is connected to the intranet of e-government networks.

[0046] Specifically, based on the security gateway, the first access data is subjected to traffic scrubbing to obtain secure access data.

[0047] Specifically, when the security gateway receives the first access data, the forwarding gateway of the security gateway initiates an access request and guides the first access data to the e-government cloud security resource pool. After the e-government cloud security resource pool performs traffic cleaning and filtering, it can remove any potentially risky data in the first access data and obtain secure access data, which can then be connected to the e-government network intranet.

[0048] S130: Send secure access data to the first network via digital circuitry so that the user terminal can access the first network.

[0049] This application provides a network access method applied to a first network side, which includes a cloud server and a first network. The cloud server is equipped with a security gateway, and the cloud server and the first network are connected via digital circuits. The method includes: receiving first access data; the first access data is obtained by the 5G network side through traffic splitting processing based on the initial access data of the user terminal; performing traffic cleaning processing on the first access data based on the security gateway to obtain secure access data; and sending the secure access data to the first network via digital circuits to enable the user terminal to access the first network. In this manner, the first network side includes a cloud server and a first network. The cloud server is equipped with a security gateway, and the cloud server and the first network are connected via digital circuits. Since the cloud server and the first network can be isolated through digital circuits, the first access data cannot be directly transmitted to the first network. Even if the first access data has security risks, it cannot directly affect the first network. When the first access data is received, the security gateway performs traffic cleaning processing on the first access data to remove any potentially risky data and obtain secure access data. The secure access data is then sent to the first network through digital circuits so that the user terminal can access the first network, which can effectively improve the security of the user terminal accessing the first network.

[0050] In some embodiments, the first network is provided with a network boundary device, the cloud server is connected to the full-service router via a digital circuit, the full-service router is connected to the network boundary device via a digital circuit, the full-service router is provided with first routing information, and the full-service router and the cloud server are provided with second routing information.

[0051] Sending secure access data to a first network via digital circuitry to enable a user terminal to access the first network includes: sending secure access data to a full-service router via digital circuitry based on second routing information; and sending secure access data to the first network via digital circuitry based on the full-service router and the first routing information to enable a user terminal to access the first network.

[0052] Please continue reading. Figure 2 ,like Figure 2 As shown, the network application system of the first network is equipped with a network boundary device. The cloud server is connected to the full-service router (SR) via a digital circuit, and the full-service router is connected to the network boundary device via a digital circuit.

[0053] Specifically, the cloud server (i.e., the e-government cloud) is equipped with a security gateway and a firewall. The firewall can deploy digital circuits, and the cloud server is directly connected to the full-service router through the digital circuits deployed on the firewall. The full-service router is configured with primary routing information (static routing information), which can introduce the e-government network intranet routes into the full-service router through global traffic redirection technology, and then introduce the e-government network intranet routes into the cloud server globally through the full-service router.

[0054] Preferably, all traffic data accessing the e-government network intranet must undergo traffic cleaning and filtering processing through a security gateway, and then the traffic data is redirected to the e-government network intranet through digital circuits. This method ensures that the traffic data does not expose information such as the e-government network intranet and ports to the outside world before being authenticated by the security gateway, and can completely cut off the connection between the e-government network intranet and the Internet, thereby avoiding detection of unauthorized external connections.

[0055] A second routing information, namely BGP (Border Gateway Protocol) routing information, is set between the full-service router and the cloud server.

[0056] After obtaining secure access data, the cloud server can send the secure access data to the full-service router via digital circuitry based on the second routing information.

[0057] Preferably, the security gateway performs identity authentication and authorization authentication based on the authentication key and other information corresponding to the user terminal; if the authentication is successful, the corresponding access policy and access permissions are opened to the user terminal so that the user terminal can access the first network and access intranet resources.

[0058] Furthermore, the full-service router can send secure access data to the first network via digital circuits based on the first routing information, so that the user terminal can access the first network.

[0059] In some embodiments, the first access data carries first access address information, the cloud server is equipped with a firewall, and the firewall is equipped with third routing information.

[0060] Based on the security gateway, the first access data undergoes traffic cleaning processing. Before obtaining secure access data, the process further includes: based on the firewall and third routing information, address translation processing is performed on the first access address information to generate second access address information; the secure access data is then sent to the first network via digital circuitry to enable the user terminal to access the first network, including: based on the second access address information, the secure access data is sent to the first network via digital circuitry to enable the user terminal to access the first network.

[0061] Specifically, the first access data carries the first access address information, the cloud server is equipped with a firewall, and the firewall is equipped with third routing information (backhaul routing information).

[0062] Understandably, the address information used by the e-government intranet and the address information used by the user terminal may have different formats and protocols. Therefore, directly accessing e-government intranet resources based on the access address information carried by the user access data requires address translation processing to convert the address information used by the user terminal into the legal address information used by the e-government intranet in order to access intranet resources.

[0063] Specifically, based on the security gateway, the first access data is subjected to traffic cleaning processing. Before obtaining secure access data, the first access address information also needs to be processed by address translation based on the firewall and third-party routing information, namely SNAT (Source Network Address Translation) processing or NAT (Network Address Translation) processing, to generate the second access address information, which is the intranet IP (Internet Protocol) address information of the e-government network.

[0064] Understandably, in real-world scenarios, user terminals may access intranet resources by accessing domain names through 5G terminals, meaning that the first access address information is the access domain name information.

[0065] Therefore, in order to achieve domain name resolution, convert domain names into internal network IP addresses, and achieve accurate data routing, the security gateway can be configured with the DNS (Domain Name System) of the e-government network to resolve the address corresponding to the access domain name, so that the security gateway can resolve the access domain name into an internal network IP address.

[0066] For example, the domain name “newoa.kfq.ls.local” is resolved to the internal IP address “10.53.136.90”.

[0067] Furthermore, based on the security gateway, the first access data is subjected to traffic scrubbing processing to obtain secure access data, which carries second access address information; based on the second access address information, the secure access data is sent to the first network through digital circuitry so that the user terminal can access the first network.

[0068] In some embodiments, the first network is provided with a network boundary device.

[0069] Sending secure access data to a first network via digital circuitry to enable a user terminal to access the first network includes: sending secure access data to a network boundary device of the first network via digital circuitry; authenticating the user terminal based on the network boundary device; and, if the user terminal is authenticated, authorizing access to the user terminal to enable the user terminal to access the first network.

[0070] Specifically, the security gateway control center set up on the cloud server can dynamically evaluate and authenticate the identity and permissions of user terminals. After successful authentication, the security gateway control center can notify the security gateway to load and maintain the access control policy of the corresponding user terminal. The evaluated trusted access request data can be sent to the network boundary device of the first network through digital circuits.

[0071] Network boundary devices can serve as security devices, enabling them to authenticate user terminals.

[0072] Optionally, the network boundary device can obtain information such as the mobile phone number bound to the user terminal and the IP address bound to the mobile phone number for identity verification, and determine whether the user can access the first network.

[0073] If the user terminal passes authentication, access is authorized for the user terminal to access the first network.

[0074] Specifically, if the user terminal passes authentication, the network boundary device can authorize the user terminal with the corresponding access policy based on the internal network IP address obtained after address translation processing, and allow the user terminal to access the first network after traffic cleaning processing, thereby realizing end-to-end secure access between the user terminal and the first network.

[0075] Please see Figure 3 , Figure 3 This is the third flowchart illustrating the network access method provided in this application embodiment. In this application embodiment, the network access method is applied to the 5G network side, and the network access method includes steps S310 to S330, each step being as follows:

[0076] S310: In response to an access request from a user terminal, determine the initial access data for the user terminal based on the access request.

[0077] Specifically, the user terminal (UE) can first send an access request to the 5G network side. The access request can also carry initial access data, which includes public network traffic data and private network traffic data.

[0078] Furthermore, in response to the user terminal's access request, the 5G network side determines and extracts the user terminal's initial access data based on the access request.

[0079] S320: Based on SMF, send data splitting rules to UPF.

[0080] The 5G network side is equipped with SMF (Session Management Function) network elements. The SMF network elements can issue preset data offloading rules (i.e. offloading policies) to UPF network elements based on PCF (Policy Control Function).

[0081] S330: Based on UPF, it performs data splitting processing on the initial access data through data splitting rules to obtain the first access data and the second access data.

[0082] Specifically, for user terminals that have signed up for the offloading service, the 5G network side can insert ULCL UPF (Uplink Classifier User Plane Function) network element. The ULCL UPF network element can perform offloading processing on the initial access data according to the preset data offloading rules issued by the SMF network element (such as the Layer 3 IP address corresponding to the security gateway) to obtain the first access data and the second access data.

[0083] S340: When the user terminal logs into the security gateway on the first network side, the first access data is sent to the first network side.

[0084] The network access method in this application is implemented based on a 5G dual-domain network architecture.

[0085] In a 5G dual-domain network architecture, 5G network slicing technology can be used to ensure data isolation.

[0086] Network slicing technology is a virtual segmentation of a network that can provide complete end-to-end connectivity for specific services or tenants.

[0087] In this embodiment, the user's 5G terminal can access a shared UPF network element (e.g., an ULCL UPF network element) on the 5G network side via the 5G network. The UPF network element is deployed with physical links for connecting to the 5G public VRF (Virtual Routing and Forwarding) network of the CM2 cloud private network. Simultaneously, the cloud server on the first network side can connect to the 5G public VRF network of the CM2 cloud private network through a firewall, connecting the UPF network element on the 5G network side and the firewall of the cloud server on the first network side through the 5G public VRF network. As an Underlay network (i.e., the underlying physical network), the 5G public VRF network can encapsulate the first access data at the underlying physical layer using the GRE (Generic Route Encapsulation) protocol, establishing a GRE tunnel between the UPF network element and the firewall of the cloud server on the first network side. Isolation forwarding is performed within the GRE tunnel, forwarding the first access data to the first network side.

[0088] S350: When the user terminal exits the security gateway, the second access data is sent to the Internet.

[0089] Specifically, when a user terminal exits the security gateway, the 5G network side can send the second access data, i.e. public network traffic data, to the 2C UPF through the N9 user plane interface, enabling the user terminal to access Internet (i.e. public network) resources.

[0090] In some embodiments, before sending the data splitting rules to the UPF based on the SMF, the method further includes: in response to the user terminal's access request, authenticating and authorizing the user terminal based on the AMF; if the user terminal passes the authentication and authorization, then selecting the corresponding SMF for the user terminal.

[0091] Understandably, to ensure data security, user registration and authentication of the user terminal are required before processing the initial access data of the user terminal.

[0092] Specifically, users of the e-government network can log in to the service platform to bind their identity information (such as mobile phone number, terminal information, etc.) and PCF policies (i.e., data diversion rules). At the same time, users of the e-government network also need to create users through the DMP console of the security gateway on the first network side, and bind identity information (such as mobile phone number, terminal information, etc.) and corresponding security policies and access permissions to the created users to achieve user registration.

[0093] Furthermore, based on SMF, before sending the data offloading rules to UPF, the 5G network side responds to the user terminal's access request. The user UE can register with the 5G network side based on the general DNN (Data Network Name). The 5GC (5G Core Network) network elements on the 5G network side include AMF (Access and Mobility Management Function) network elements. The AMF network elements can authenticate and authorize the user terminal based on information such as the user terminal's DNAI (DN Access Identifier).

[0094] Furthermore, if the user terminal passes the authentication and authorization process, the corresponding SMF network element is selected for the user terminal; based on the SMF, the data diversion rules are sent to the UPF.

[0095] It should be noted that the network access method in this application embodiment is implemented based on a 5G dual-domain network architecture, and the security authentication process for user terminals accessing the first network can be divided into three stages:

[0096] (1) Two-way authentication master authentication: The first security authentication stage is the two-way legitimacy authentication between the user terminal and the 5G network side. The AMF network element performs two-way authentication and authorization for the user terminal, which can ensure the mutual security between the user terminal and the 5G network. The 5G network side is designed based on the concept of a mutually distrustful network, and has designed a multi-layer security protection mechanism including the user and the 5G access network, the 5G core network, and the user and applications, to ensure the access security of the user terminal and the 5G network, and to ensure that the user terminal can legally access the 5G network side.

[0097] (2) Security Gateway Additional Authentication: The second security authentication stage is security gateway authentication. The security gateway allows enterprises to formulate security policies based on various factors such as device identification code IMEI, user terminal access location, application access permissions, and access time, and conduct real-time dynamic evaluation. It blocks user terminals that do not meet the security check, restricts their access, ensures the security of enterprise intranet resources, and enhances the security of user terminal access to the intranet.

[0098] (3) Enterprise control third authentication: The third security authentication stage places control in the enterprise network. The enterprise performs three authentications on user terminals that access the intranet based on information such as IMSI number, mobile phone number, and corresponding IP address to determine whether the user can be granted intranet access permission, ensuring that the user terminal can legally access the intranet.

[0099] Preferably, to further enhance network access security, security management and protection can be achieved through a security gateway:

[0100] (1) Access Management: The security gateway provides advanced access management, supports signing / unsigning for each member (user) in the 5G dual-domain network architecture, and supports services such as locking and resetting passwords for users.

[0101] (2) Application authorization: The 5G dual-domain network architecture supports enterprise authorization services. The security gateway can provide fine-grained business access control authorization. Based on fine-grained business access control authorization, application resources are authorized and allocated. After authorization, members of the corresponding authorized group can access the corresponding application resources in the intranet through the 5G dual-domain network and the security gateway.

[0102] (3) Terminal binding: The security gateway provides terminal binding management for access users. This function can be used to bind users to hardware devices. After successful binding, users are only allowed to log in to the security gateway using the bound hardware devices, and users are prohibited from logging in using other unbound devices.

[0103] (4) Compliance detection: The security gateway provides terminal compliance detection for access users. This function can be used to detect the antivirus software, client version, patch deployment and update status of access terminals, and to set ratings for terminals with risks, and to collect risk information of access terminals to reduce the risk of application attacks.

[0104] (5) Application access logs: The security gateway provides application access logs, which can record the logs of 5G dual-domain network users accessing applications, and the logs can be viewed.

[0105] The network access method provided in this application has the following advantages compared with the prior art:

[0106] (1) Fast and stable connection speed: 5G network has the advantages of large bandwidth and low latency. The 5G dual-domain network built by 5G networking + general DNN + UPF ULCL networking can solve the problem of slow and unstable network connection when using traditional VPN to access intranet resources.

[0107] (2) Avoid detection of illegal and irregular external connections: By using a security gateway to start a security mode, private network traffic data is diverted to the e-government network intranet, completely cutting off the connection between the e-government network intranet and the Internet, thus avoiding detection of illegal and irregular external connections; at the same time, with the help of the security gateway's terminal security detection, multi-factor authentication and other functions, the security needs of various scenarios can be fully met.

[0108] (3) High flexibility of user authorization: Through the fine-grained access control function of the security gateway, a security architecture of trusted access + intelligent permissions + simplified operation and maintenance is built with user identity as the center. Through the minimal authorization mechanism, users and services are authorized individually or in groups, which strengthens the granularity of access control and allows for flexible configuration of access control rules.

[0109] (4) Simple security incident tracing: The application access log function of the security gateway enables auditing of online user logs, login logs, and resource access logs.

[0110] This application also provides a network access device. Please refer to [link to relevant documentation]. Figure 4 , Figure 4 This is a schematic diagram of the network access device provided in an embodiment of this application. In this embodiment, the network access device is applied to a first network side, which includes a cloud server and a first network. The cloud server is equipped with a security gateway, and the cloud server and the first network are connected through a digital circuit. The network access device includes a receiving module 410, a cleaning module 420, and an access module 430.

[0111] The receiving module 410 is used to receive the first access data.

[0112] The first access data is obtained by the 5G network side through diversion processing based on the initial access data of the user terminal.

[0113] The cleaning module 420 is used to perform traffic cleaning processing on the first access data based on the security gateway to obtain secure access data.

[0114] Access module 430 is used to send secure access data to the first network via digital circuitry so that the user terminal can access the first network.

[0115] In some embodiments, the first network is provided with a network boundary device, the cloud server is connected to the full-service router via a digital circuit, the full-service router is connected to the network boundary device via a digital circuit, the full-service router is provided with first routing information, and the full-service router and the cloud server are provided with second routing information.

[0116] Access module 430 is used to send secure access data to the full-service router via digital circuit based on the second routing information; and to send secure access data to the first network via digital circuit based on the full-service router and the first routing information, so that the user terminal can access the first network.

[0117] In some embodiments, the first access data carries first access address information, the cloud server is equipped with a firewall, and the firewall is equipped with third routing information.

[0118] Access module 430 is used to perform address translation processing on the first access address information based on firewall and third-party routing information to generate second access address information.

[0119] Access module 430 is used to send secure access data to the first network via digital circuits based on the second access address information, so that the user terminal can access the first network.

[0120] In some embodiments, the first network is provided with a network boundary device.

[0121] Access module 430 is used to send secure access data to the network boundary device of the first network via digital circuits; to authenticate the user terminal based on the network boundary device; and to authorize access for the user terminal if the user terminal is authenticated, so that the user terminal can access the first network.

[0122] This application also provides an electronic device. Figure 5 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application, such as... Figure 5 As shown, the electronic device may include a processor 510, a communications interface 520, a memory 530, and a communication bus 540, wherein the processor 510, the communications interface 520, and the memory 530 communicate with each other via the communication bus 540. The processor 510 can call logical instructions in the memory 530 to execute a network access method applied to the first network side.

[0123] Furthermore, the logical instructions in the aforementioned memory 530 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0124] This application also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, is implemented to perform the network access methods applied to the first network side provided by the above methods.

[0125] This application also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the network access method applied to the first network side provided by the above methods.

[0126] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0127] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0128] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A network access method, characterized in that, Applied to a first network side, the first network side includes a cloud server and a first network, the cloud server is equipped with a security gateway, and the cloud server and the first network are connected via a digital circuit; the method includes: Receive first access data; the first access data is obtained by the 5G network side through diversion processing based on the initial access data of the user terminal; Based on the security gateway, the first access data is subjected to traffic cleaning processing to obtain secure access data; The secure access data is transmitted to the first network via the digital circuit so that the user terminal can access the first network.

2. The network access method according to claim 1, characterized in that, The first network is equipped with a network boundary device. The cloud server is connected to the full-service router via a digital circuit. The full-service router is connected to the network boundary device via a digital circuit. The full-service router is equipped with first routing information. The full-service router and the cloud server are equipped with second routing information. The step of sending the secure access data to the first network via the digital circuit to enable the user terminal to access the first network includes: Based on the second routing information, the secure access data is sent to the full-service router via the digital circuit; Based on the full-service router and the first routing information, the secure access data is sent to the first network through the digital circuit so that the user terminal can access the first network.

3. The network access method according to claim 1, characterized in that, The first access data carries first access address information, the cloud server is equipped with a firewall, and the firewall is equipped with third routing information; Before performing traffic scrubbing on the first access data based on the security gateway to obtain secure access data, the process further includes: Based on the firewall and the third routing information, the first access address information is processed by address translation to generate the second access address information; The step of sending the secure access data to the first network via the digital circuit to enable the user terminal to access the first network includes: Based on the second access address information, the secure access data is sent to the first network through the digital circuit so that the user terminal can access the first network.

4. The network access method according to claim 1, characterized in that, The first network is equipped with a network boundary device; the step of sending the secure access data to the first network through the digital circuit to enable the user terminal to access the first network includes: The secure access data is transmitted to the network boundary device of the first network via the digital circuit. The user terminal is authenticated based on the network boundary device. If the user terminal passes authentication, access authorization is granted to the user terminal so that the user terminal can access the first network.

5. A network access method, characterized in that, Applied to the 5G network side, the methods include: In response to an access request from a user terminal, the initial access data of the user terminal is determined based on the access request. Based on SMF, the data splitting rules are sent to UPF; Based on UPF, the initial access data is split according to the data splitting rules to obtain the first access data and the second access data. When the user terminal logs into the security gateway on the first network side, the first access data is sent to the first network side; when the user terminal logs out of the security gateway, the second access data is sent to the Internet.

6. The network access method according to claim 5, characterized in that, Before sending the data splitting rules to the UPF based on SMF, the process also includes: In response to an access request from a user terminal, the user terminal is authenticated and authorized based on the AMF. If the user terminal passes authentication, then the corresponding SMF is selected for the user terminal.

7. A network access device, characterized in that, Applied to a first network side, the first network side includes a cloud server and a first network, the cloud server is equipped with a security gateway, and the cloud server and the first network are connected via a digital circuit. The device includes: The receiving module is used to receive the first access data; the first access data is obtained by the 5G network side through diversion processing based on the initial access data of the user terminal. The cleaning module is used to perform traffic cleaning processing on the first access data based on the security gateway to obtain secure access data; An access module is used to send the secure access data to the first network through the digital circuit, so that the user terminal can access the first network.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the network access method as described in any one of claims 1 to 4.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the network access method as described in any one of claims 1 to 4.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the network access method as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Network intrusion safety early warning system based on cloud computing

    CN111832027A

  • Method and apparatus for authentication of integrated access and backhaul (IAB) nodes in wireless networks

    CN114342439A