An access method, device, platform, equipment and medium of an intranet and extranet terminal
By using a software-defined boundary architecture and a zero-trust system, and leveraging door-knock packet technology and a zero-trust sandbox for secure access to internal and external network terminals, the security risks arising from the complexity of access in remote work are resolved. This achieves isolation and secure management of internal and external networks, thereby improving office efficiency and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CORP LTD
- Filing Date
- 2024-09-10
- Publication Date
- 2026-04-17
AI Technical Summary
Remote work has led to a diversification of access roles, usage scenarios, access environments, and access terminals, which has broken down traditional security boundaries and increased data leakage and security risks.
By adopting a software-defined perimeter architecture (SDP) and a zero-trust system, internet port access permissions are opened through door-knocking packet technology. Combined with a zero-trust sandbox for dual-domain isolation, secure access to internal and external network terminals is achieved. Identity authentication and access control are performed through the zero-trust integrated 4A system, thereby converging the internet exposure surface and isolating internal and external networks.
It reduces the risk of internal network intrusion after the computer is remotely controlled, improves office efficiency and security, and enhances terminal access security and management efficiency by switching between internal and external networks with one click.
Smart Images

Figure CN119094586B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to an access method for internal and external network terminals, an access device for internal and external network terminals, a corresponding internal and external network access platform, a corresponding electronic device, and a corresponding computer-readable storage medium. Background Technology
[0002] Remote work is an important work mode that enables greater convenience in the workplace.
[0003] However, there is often a conflict between convenience and security. To ensure the operation and efficiency of remote work, most companies conduct remote work through VPNs (Virtual Private Networks) or the Internet. The diversification of access roles, usage scenarios, access environments, and access terminals caused by remote work will break the boundaries of traditional office networks. The traditional, easily identifiable security boundaries will no longer exist. Due to the lack of security boundaries, the interconnection of data between various links can easily lead to problems such as lost credentials, abuse of permissions, or malicious access, resulting in data leakage and serious security risks to the office network. Summary of the Invention
[0004] In view of the above problems, embodiments of the present invention are proposed to provide an access method for internal and external network terminals, an access device for internal and external network terminals, a corresponding internal and external network access platform, a corresponding electronic device, and a corresponding computer-readable storage medium to overcome or at least partially solve the above problems.
[0005] This invention discloses an access method for internal and external network terminals, involving an internal and external network access platform. The platform is deployed with a software-defined boundary architecture, which includes a zero-trust system. The method includes:
[0006] The zero-trust system receives communication connection requests from internal and external network terminals, and the communication connection includes a knock packet.
[0007] In response to the communication connection request, access to the Internet port is granted to the internal and external network terminals based on the knock packet;
[0008] Based on the access permissions, a communication connection is established with the internal and external network terminals to receive office business access requests from the internal and external network terminals; wherein, the internal and external network terminals include a personal space domain and a work space domain divided based on a zero-trust sandbox.
[0009] In response to the office business access request, the system obtains office data and returns the office data to the workspace domain of the internal and external network terminals.
[0010] This invention also discloses an access device for internal and external network terminals, relating to an internal and external network access platform. The internal and external network access platform is deployed with a software-defined boundary architecture, which includes a zero-trust system. The device includes:
[0011] A communication connection request receiving module is used to receive communication connection requests from the internal and external network terminals, wherein the communication connection includes a knock packet;
[0012] The access permission opening module is used to respond to the communication connection request and, based on the knock packet, open access permissions for the Internet port to the internal and external network terminals;
[0013] The business access request receiving module is used to establish a communication connection with the internal and external network terminals based on the access permissions, and to receive office business access requests from the internal and external network terminals; wherein, the internal and external network terminals include a personal space domain and a work space domain divided based on a zero-trust sandbox.
[0014] The office data return module is used to respond to the office business access request, obtain office data, and return the office data to the workspace domain of the internal and external network terminals.
[0015] This invention also discloses an internal / external network access platform, which is deployed with a software-defined boundary architecture. The software-defined boundary architecture includes a zero-trust system, which comprises a zero-trust controller and a zero-trust gateway.
[0016] The zero-trust controller is used to receive communication connection requests from the internal and external network terminals, respond to the communication connection requests, grant access permissions to the internet ports of the internal and external network terminals based on the knocking packet included in the communication connection, establish a communication connection with the internal and external network terminals based on the access permissions, and receive office business access requests from the internal and external network terminals.
[0017] The zero-trust gateway is used to respond to the office business access request, obtain office data, and return the office data to the workspace domain of the internal and external network terminals.
[0018] This invention also discloses an electronic device, including: a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, it implements any of the aforementioned access methods for internal and external network terminals.
[0019] This invention also discloses a computer-readable storage medium storing a computer program, which, when executed by a processor, implements any of the aforementioned methods for accessing internal and external network terminals.
[0020] The embodiments of the present invention have the following advantages:
[0021] In this embodiment of the invention, the zero-trust system of the internal and external network access platform receives communication connection requests from internal and external network terminals. Based on the knock packet included in the communication connection request, access permissions to the internet ports of the internal and external network terminals are granted, so as to establish a communication connection between the internal and external network terminals and the internal and external network access platform based on the access permissions. Office data is obtained by responding to office business access requests, and the obtained office data is returned to the workspace domain of the internal and external network terminals. The zero-trust policy is implemented through a software-defined boundary architecture, granting access permissions to the internet ports of internal and external network terminals based on the knock packet, and then using internet port hiding technology to reduce the internet exposure surface. Furthermore, a zero-trust sandbox provides security by isolating the internal and external network terminals in personal and workspaces, achieving internal and external network isolation during office work and maintenance, reducing the risk of internal network intrusion after remote control of the computer, and improving office efficiency through one-click switching between internal and external networks. Attached Figure Description
[0022] Figure 1 This is a schematic diagram of the software-defined boundary architecture provided in an embodiment of the present invention;
[0023] Figure 2 This is a flowchart illustrating the steps of an embodiment of the access method for internal and external network terminals according to the present invention;
[0024] Figure 3 This is a schematic diagram of the converged Internet exposure surface provided in an embodiment of the present invention;
[0025] Figures 4A to 4B This is a schematic diagram illustrating the distribution of a security code according to an embodiment of the present invention;
[0026] Figures 5A to 5B This is a schematic diagram illustrating another security code distribution provided by an embodiment of the present invention;
[0027] Figure 6 This is a schematic diagram of data transmission in a secure tunnel provided in an embodiment of the present invention;
[0028] Figures 7A to 7B This is a schematic diagram illustrating the establishment of a communication connection according to an embodiment of the present invention;
[0029] Figures 8A to 8B This is a schematic diagram illustrating the establishment of another communication connection provided in an embodiment of the present invention;
[0030] Figures 9A to 9BThis is a schematic diagram illustrating the establishment of another communication connection provided in an embodiment of the present invention;
[0031] Figure 10 This is a schematic diagram of sandbox isolation provided in an embodiment of the present invention;
[0032] Figure 11 This is a structural block diagram of an embodiment of an access device for internal and external network terminals according to the present invention. Detailed Implementation
[0033] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0034] To facilitate understanding of the present invention by those skilled in the art, the terms or nouns involved in the following embodiments of the present invention are explained below:
[0035] Zero-trust architecture: By default, no user, device, or network traffic is trusted, whether it comes from the internal or external network. Instead, all access requests must go through a strict authentication and authorization process.
[0036] BYOD: Bring Your Own Device. This refers to a policy in some companies that allows employees to bring their own laptops, tablets, smartphones, and other mobile devices to the workplace, and to use these devices to access internal company information and use licensed applications.
[0037] SDP: Software Defined Perimeter, is a new generation of network security technology architecture based on zero trust.
[0038] The 4A system refers to an integrated solution for unified identity authentication, authorization, account, and audit management.
[0039] IPS: Intrusion Prevention System, used to help organizations identify malicious traffic and proactively block such traffic from entering their networks. Specifically, products using IPS technology can be continuously deployed to monitor incoming traffic and check for vulnerabilities and exploitable opportunities. If vulnerabilities and exploitable opportunities are detected, appropriate measures defined in the security policy will be taken, such as blocking access, isolating the host, or blocking access to external websites that may pose a risk of data breaches.
[0040] TCP: Transmission Control Protocol, is a connection-oriented, reliable transport protocol.
[0041] UDP: User Datagram Protocol, is a connectionless and unreliable transport protocol.
[0042] A knock packet is a specific data packet used to trigger certain actions on network devices such as firewalls or servers. Knock packet technology is often used to implement so-called "port knocking," a network security technique that unlocks or activates specific network services or ports by sending a series of predefined network data packets (knock packets).
[0043] SDK: Software Development Kit, is a set of tools used to help developers create, test, and deploy software applications on a specific platform or service.
[0044] DNS: Domain Name System, is a core service of the Internet. As a distributed database that maps domain names to IP addresses, it enables users to access the Internet more conveniently without having to remember IP address strings that can be directly read by machines.
[0045] DDoS: Distributed Denial of Service is a network attack method that aims to overwhelm network resources with a large number of legitimate requests, preventing the target system from providing normal services and thus rendering the service unavailable.
[0046] DCN: Data Communication Network, refers to a network system used to transmit data between different devices.
[0047] WAF: Web Application Firewall, is a security device or service used to protect web applications from various network attacks.
[0048] SNAT: Source Network Address Translation.
[0049] ACL: Access Control List.
[0050] Remote work is an important work mode that enables greater convenience in the workplace.
[0051] However, the convenience of remote work will bring about the complexity of secure access and increase security risks.
[0052] As one example, remote work will lead to a diversification of access roles, specifically resulting in a greater variety of user roles accessing the network, including various employees, supervisors at all levels, functional personnel, developers, partners, suppliers, and many others. The identities and permissions of these access personnel differ, posing a greater challenge to enterprise security management. As another example, remote work will lead to a diversification of use cases, specifically resulting in a rapid expansion and diversification of use cases. These include various remote operation and maintenance support, remote workflow approval, remote collaborative work, remote development and testing, and home-based agents. Different user roles require access to different use cases; for example, suppliers need to access procurement systems, sales personnel need to access sales management systems, finance managers need to access financial management platforms, and developers need to access sensitive systems. Code and data platforms, facing numerous users and usage scenarios, further increase the difficulty of security management. As another example, remote work complicates the access environment, transforming it from a traditional, single office environment to a nationwide, 24 / 7 access environment. No longer limited by geographical location, it becomes difficult to guarantee the security of the access environment, blurring network boundaries and introducing new security risks. As yet another example, remote work complicates the access terminals, making the terminals accessing the work platform more complex. They evolve from the company's intranet PCs and centrally procured PCs to various employee home computers and other BYOD personal terminals. With a large number of users and terminals, the security of the terminal environment cannot be effectively guaranteed, significantly increasing security risks once again.
[0053] This invention proposes a unified access platform for internal and external networks. This platform implements a zero-trust policy using an SDP architecture, achieves dual-domain isolation between personal and work spaces through a zero-trust sandbox, and integrates the authentication, organizational structure, and permission system of the 4A system through zero-trust. This enables secure access to the office network for remote and mobile office terminals, solving problems related to diverse access roles, usage scenarios, access environments, and access terminals. It narrows the exposure surface of the Internet, ensuring that the internal network does not leave the data center, thereby increasing the security of internal and external network terminals accessing the office network.
[0054] Specifically, by employing internet port hiding technology and granting internet access permissions to internal and external network terminals based on the "knock-on package," the internet exposure surface is reduced. Through the integration of the Zero Trust system and the work assistant, using a master-slave APP model, the work assistant and all APPs inherit the Zero Trust SDK, achieving centralized management of APPs and eliminating their exposure surface. Furthermore, the Zero Trust sandbox provides dual-domain security assurance by isolating internal and external network terminals into personal and work spaces, achieving internal and external network isolation during office work and maintenance, reducing the risk of internal network intrusion after remote control of computers, and enhancing office efficiency through one-click switching between internal and external networks. Finally, by integrating the authentication, organizational structure, and permission system of the Zero Trust 4A system, the management of employee ID permissions is minimized, enabling one account, one authentication, and full network roaming, greatly improving user login system and maintenance efficiency.
[0055] When granting access to internet ports, multi-factor trusted authentication can be used to ensure the absolute security of access terminals. Furthermore, SDP (Software as a Platform) can be used, centered on identity and based on the zero-trust principle, to provide multi-dimensional dynamic trust authorization. Additionally, adhering to the principle of keeping the internal network within the data center, all other branch and office internal networks can be brought back to the data center, accessing the internal network via zero-trust internet login, and only after successful authentication.
[0056] In the process of centralized management and control, it can be mainly based on the integration of the work assistant and the zero-trust SDK, forming a unique 1+1+N security protection model. "1": one APP portal (the work assistant portal integrates all self-used APPs), "1": one self-used system portal (the zero-trust platform portal integrates all self-used systems), "N": N public Internet systems (centralized protection through the WEB dynamic defense system), which completely eliminates the exposure surface of self-used systems.
[0057] Furthermore, the zero-trust controller can also adopt a three-cluster mode, with three devices per cluster. This ensures that even if one cluster fails, the remaining control center devices can still guarantee secure access and stable operation for end users, without affecting normal business operations. It should be noted that the internal and external network access platform provided in this embodiment of the invention has good system adaptability, can be adapted to and used normally on multiple systems, and has a wide range of application scenarios, good adaptability, and high support.
[0058] Reference Figure 1 This diagram illustrates the architecture of the software-defined boundary architecture provided in an embodiment of the present invention. Embodiments of the present invention can implement a zero-trust strategy using an SDP architecture, such as... Figure 1 The software-defined boundary architecture shown is a zero-trust deployment architecture. The aforementioned architecture can be deployed on internal and external network access platforms to achieve unified access to the office network for internal and external network terminals.
[0059] The aforementioned software-defined boundary architecture may include office network boundary security protection equipment.
[0060] When internal and external network terminals, such as mobile devices or PCs, access the business systems of the office network, specifically when mobile devices access the system through applications or PCs access it via the web based on DNS, access control can be implemented through the office network boundary security protection equipment.
[0061] For example, office network boundary security protection equipment may include security components such as firewalls, internet behavior management, zero-trust systems, national cryptographic gateways, and endpoint antivirus software to build an overall office network security protection system.
[0062] The zero-trust system can include a zero-trust controller and a zero-trust gateway. The zero-trust system can provide zero-trust services to internal and external network terminals through the aforementioned zero-trust platform containing the zero-trust controller and zero-trust gateway. For example... Figure 1 As shown, the zero-trust controller may include, for example, controller A1, controller A2, controller A3, controller B1, controller B2, controller B3, controller C1, controller C2, controller C3, etc.; the zero-trust gateway may include, for example, (non-national cryptographic) gateway A1, (non-national cryptographic) gateway A2, (national cryptographic) gateway B1, (national cryptographic) gateway B2, (national cryptographic) gateway C1, (national cryptographic) gateway C2, etc.
[0063] Optionally, the zero-trust controller can primarily function as a control center, while the zero-trust gateway can act as a security proxy gateway, achieving separation of the control plane and the data plane. The zero-trust controller is mainly used for authentication and policy distribution, while the security proxy gateway is used for proxying and forwarding data traffic. The zero-trust controller and the security proxy gateway typically interact through a secure control channel.
[0064] In one possible implementation, the software-defined boundary architecture described above may also include a zero-trust sandbox.
[0065] Optionally, zero-trust sandboxes can be used to provide data security through technologies such as endpoint data encryption, environment isolation, and behavior monitoring. Specifically, this can manifest as a security guarantee through dual-domain isolation of the personal space and work space within the zero-trust sandbox.
[0066] In one possible implementation, the software-defined boundary architecture described above may also include DCN services, namely, office business systems related to the office network, such as work assistants, OA, and 4A.
[0067] Specifically, Zero Trust and Work Assistant can be used to integrate various application systems to solve application security access issues. This is manifested in the integration with Work Assistant, using a master-slave APP model, where Work Assistant and all APPs inherit the Zero Trust SDK, achieving centralized management of APPs and eliminating APP exposure surfaces. Furthermore, the Zero Trust platform can centralize the entry points of self-used systems. Specifically, Zero Trust integrates the authentication, organizational structure, and permission system of 4A systems, enabling one account, one authentication, and roaming across the entire network, improving employee perception and facilitating operation and maintenance.
[0068] In practical applications, the Zero Trust Controller is mainly used to receive and respond to communication connection requests from internal and external network terminals, grant access permissions to the Internet ports of internal and external network terminals based on the knock packet included in the communication connection, and establish communication connections with internal and external network terminals based on the access permissions, and receive office business access requests from internal and external network terminals; the Zero Trust Gateway is mainly used to respond to office business access requests, obtain office data, and return the office data to the workspace domain of internal and external network terminals, thereby enabling internal and external network terminals to access office business.
[0069] The essence of the aforementioned zero-trust architecture is identity-centric dynamic trusted access control, focusing on security capabilities in dimensions such as identity, trust, business access, and dynamic access control. Based on multiple factors such as people, processes, environment, and access context in business scenarios, it dynamically and continuously evaluates and adjusts trust to form a dynamic and adaptive security closed-loop system with strong risk response capabilities.
[0070] The SDP architecture provided in this invention enables single sign-on for OA and 4A systems, unifies the web system portal, integrates the work assistant and zero-trust systems, unifies the APP portal, and completes user management through the account lifecycle system. It achieves unified identity authentication and management on mobile and PC terminals, and ultimately achieves unified secure access control and convergence of the Internet exposure surface. This addresses issues such as the security environment of mobile access terminal devices, user identity authentication, national cryptographic data transmission, access control, terminal data security, Internet convergence, and intranet access outside the data center. Together with the work assistant, 4A, OA platform, and boundary security protection equipment, it constructs secure access to business systems, identity and permission management, and network boundary security.
[0071] Reference Figure 2 This document illustrates a flowchart of an embodiment of an access method for internal and external network terminals according to the present invention, involving, for example... Figure 1 The software-defined boundary architecture shown may specifically include the following steps:
[0072] Step 201: Receive communication connection requests from internal and external network terminals through the zero-trust system;
[0073] This invention employs Internet port hiding technology to hide Internet ports, specifically TCP ports, allowing internal and external network terminals to maintain a communication tunnel with the zero-trust system for accessing UDP ports.
[0074] In one embodiment of the present invention, it is assumed that the internal and external network terminals are SDP clients with identity authentication. The internal and external network terminals can initiate a communication connection to the zero-trust system (i.e., SDP) to access internal network applications.
[0075] Specifically, the communication connection request sent by internal and external network terminals to the zero-trust system may include a knock packet. This knock packet can be used to indicate the user identity of the internal and external network terminals, so as to achieve network invisibility to the backend of the proxy gateway, transform the original network location-based access control into identity-centric access control, that is, upgrade from IP-based ACL to identity-based ACL, eliminate the dependence on IP, break through geographical location restrictions, realize business follow-up, prevent ACL corruption, ensure data transmission security, strengthen access control, reduce Internet exposure, improve user experience perception, and realize intelligent operation and maintenance management.
[0076] like Figure 3 As shown, a "trust first, then authentication, then connection" approach can be adopted for each accessing user. When an untrusted client logs in, it cannot open the login page or access any interfaces (including TCP and UDP ports). This prevents malicious scanning, vulnerability probing attacks, and weak password brute-force attacks by attackers, minimizing the business exposure surface and ensuring security. Specifically, the TCP port is not open to internal or external network terminals, and the UDP interface does not respond to clients from unauthorized users. When an SDP client performs SPA knock-door authentication on the UDP port, it can send a knock-door packet to the zero-trust system to request a communication connection.
[0077] Step 202: Respond to the communication connection request and grant access to the Internet port to internal and external network terminals based on the knock packet;
[0078] When employees remotely access systems such as office automation (OA), network management and maintenance, billing, CRM, and internal apps, the user roles and groups are complex, so it is necessary to perform reasonable and effective authentication of the users' identities. Moreover, when the access environment or access time changes, it is necessary to ensure the legitimacy of the identity again.
[0079] Zero-trust systems can authenticate internal and external network terminals based on the knocking information contained in the knocking packet, thereby granting access to internet ports to internal and external network terminals based on the knocking information in the knocking packet.
[0080] Specifically, the internet port that is opened is the TCP port. Both internal and external network terminals have access to the TCP port, and can access the office business system through the TCP port.
[0081] Step 203: Establish a communication connection with internal and external network terminals based on access permissions, and receive office business access requests from internal and external network terminals.
[0082] Office business access requests can be used by internal and external network terminals to request business access or data access from the office business system.
[0083] Step 204: Respond to the office business access request, obtain office data, and return the office data to the workspace domain of the internal and external network terminals.
[0084] Among them, on both internal and external network terminals, personal space domains and work space domains can be included based on zero-trust sandbox partitioning.
[0085] In practical applications, the zero-trust system can respond to office business access requests, obtain office data, and return the office data to the workspace domain of internal and external network terminals.
[0086] It should be noted that shrinking the business from the internet to the internal network does not change user access habits; for example, the access domain name remains unchanged, and B / S services do not require mandatory client installation.
[0087] In this embodiment of the invention, the zero-trust system of the internal and external network access platform receives communication connection requests from internal and external network terminals. Based on the knock packet included in the communication connection request, access permissions to the internet ports of the internal and external network terminals are granted, so as to establish a communication connection between the internal and external network terminals and the internal and external network access platform based on the access permissions. Office data is obtained by responding to office business access requests, and the obtained office data is returned to the workspace domain of the internal and external network terminals. The zero-trust policy is implemented through a software-defined boundary architecture, granting access permissions to the internet ports of internal and external network terminals based on the knock packet, and then using internet port hiding technology to reduce the internet exposure surface. Furthermore, a zero-trust sandbox provides security by isolating the internal and external network terminals in personal and workspaces, achieving internal and external network isolation during office work and maintenance, reducing the risk of internal network intrusion after remote control of the computer, and improving office efficiency through one-click switching between internal and external networks.
[0088] In some embodiments of the present invention, step 202, granting access permissions to internet ports to internal and external network terminals based on the "knock-on packet," includes:
[0089] Verify that the data packet format of the knocking packet is correct; if the data packet format of the knocking packet is correct, verify the knocking packet information; when the knocking packet information is verified, grant access to the Internet port to internal and external network terminals.
[0090] In this embodiment of the invention, the SPA single-packet authorization security mechanism can achieve network stealth, hiding critical business to the backend and minimizing the exposure surface as much as possible.
[0091] Optionally, the knock packet information may include at least one or more of the following: user identity information, terminal device information, timestamp, network information, and location information; wherein, the user identity information includes at least one or more of the following: security code information and random number, and the terminal device information includes at least one or more of the following: device physical address information and device name.
[0092] Optionally, the security code information is bound to internal and external network terminal users; the security code information has a valid usage period and / or a number of uses.
[0093] As an example, a one-person-one-code management model can be adopted to effectively solve problems such as lost security codes and misuse of security codes, thereby further improving the security of user access.
[0094] For specific details, please refer to Figures 4A to 4B This diagram illustrates a security code distribution method provided by an embodiment of the present invention. In a one-person-one-code mode, the security code can be bound to the user, giving each person their own unique security code. Administrators can also set a separate validity period for each unique security code to meet the temporary access needs of outsourced maintenance personnel during major security exercises. When a SPA security code is discovered to be leaked, a reset operation can be performed in the console to quickly cancel the leaked SPA security code, assigning a unique SPA security code to each user. This perfectly solves problems such as lost security codes and misuse of security codes, achieving refined management.
[0095] As another example, the SPA one-person-one-code system can be further upgraded and updated to greatly improve the security of the authentication mode and prevent the security code from being leaked.
[0096] For specific details, please refer to Figures 5A to 5BThis diagram illustrates another security code distribution method provided by an embodiment of the present invention. In the SPA one-time-one-code mode, all security codes are distributed and stored in encrypted form, whether on the server or client side. Neither administrators nor users can view the security code in plaintext; instead, the encrypted security code is replaced by a plaintext activation code, thus preventing security code exposure. Furthermore, for a user to obtain a security code, they must not only enter a valid activation code to pass SPA authentication but also complete identity verification. Only after confirming the consistency between the user and the code will the server issue the encrypted security code. In other words, even if an administrator leaves the company or an attacker obtains a valid activation code through phishing, they cannot replace it with the final security code without the corresponding user's identity credentials, thus strengthening security code exchange verification. Additionally, since security codes are used long-term with business operations, their validity period often coincides with the user account's validity period, i.e., a long-term key. However, the activation code serves as an intermediate step between the initial activation and security code replacement, and its validity period can be narrowed to minutes or hours, becoming invalid after one security code exchange. By limiting the validity period and number of uses, the exposure cycle is greatly reduced, i.e., a one-time key, thus reducing the activation code exposure cycle.
[0097] It should be noted that because the security code is a one-time code that can be changed, unlike a security code which can be used indefinitely after being entered by the user (if it has not expired or been reset), the user needs to log in and successfully change the code to use the long-term valid security code. Otherwise, the user will fail to access the system after obtaining the activation code. Furthermore, a security code can be obtained by distributing activation codes and using multi-factor authentication to prevent the security code from being leaked and to further improve access security. This embodiment of the invention does not impose any limitations on this approach.
[0098] Optionally, the knock packet information can be verified by at least one of the following methods: data packet replay verification, data packet forgery verification, and user security code verification.
[0099] In this embodiment of the invention, the multi-factor trusted authentication that ensures the security of the access terminal may include multiple factors such as the aforementioned user identity information, terminal device information, timestamp, network information and location information, or a two-factor combination of the aforementioned two factors. When any one of them fails to meet the requirements, the UDP protocol will refuse access to the TCP port by the internal and external network terminals, that is, it will not grant access permissions to the TCP port to the internal and external network terminals.
[0100] Optionally, an SDP (Software Defined Perimeter) approach can also be adopted, centered on identity and based on the zero-trust concept, to achieve trusted authentication of internal and external network terminals through multi-dimensional dynamic trust authorization. For example, it can include identity authentication based on multi-factor identity information, trust assessment based on trust level evaluation, terminal device authentication based on terminal device environment and security status, behavior monitoring based on continuous monitoring of behavior, traffic and logs, and access authorization authentication based on trust level authorization access permissions, etc. The embodiments of the present invention do not limit this.
[0101] In one possible implementation, a zero-trust controller can grant access to internet ports to internal and external network terminals based on door-knocking packets.
[0102] In one possible implementation, a zero-trust gateway can respond to office service access requests, obtain office data, and return the office data to the workspace domain of internal and external network terminals. Specifically, the zero-trust gateway can forward the office data to the zero-trust controller, which then returns the office data to the workspace domain of the internal and external network terminals.
[0103] On the server side, the zero-trust platform consists of two parts: a control center and a security proxy gateway. This separates the control plane from the data plane. The controller handles authentication and policy distribution, while the security proxy gateway is solely responsible for proxying and forwarding data traffic. Figure 6 As shown, the control center and the security proxy gateway interact through a secure control channel.
[0104] For example, the zero-trust controller is the brain of the internal and external network access platform. It can mainly establish dynamic and fine-grained access rules between visitors and resources, and distribute these access rules to the security proxy gateway. Based on the rules, the gateway forwards user traffic. The rules established by the controller are only open to authorized users. This whitelist access control mode can make unauthorized access traffic rejected at the TCP stage, greatly reducing the network attack exposure surface.
[0105] It should be noted that the access rules provided by the controller are not static. Its trust engine makes a comprehensive judgment based on user access behavior, the environment, and the characteristics of the business system itself, dynamically adjusting the access rules to prevent threats to the business server. Simultaneously, the zero-trust engine can provide open APIs to interact with other security components, achieving a comprehensive and multi-dimensional security protection system through unified processing of information reported by security components. This embodiment of the invention does not impose any limitations on this.
[0106] In practical applications, on the terminal device side, the client can be provided with the ability to report terminal security risks and redirect network data. Specifically, the client can periodically detect the terminal environment and report the data to the control center. The control center can adjust access policies in real time based on the reporting results to avoid access risks that may be caused by terminal security issues. At the same time, the client can tag specific network traffic with identity labels and access process information and redirect it to a secure access gateway for processing. Trusted access determines whether to proxy the traffic based on the access policy.
[0107] Specifically, by granting trust first and then authenticating, untrusted clients cannot open the login page or access any interfaces when establishing a TLS connection because they do not carry a valid SPA password; while trusted terminals carrying the SPA seed can successfully establish a connection and log in because they carry a valid password.
[0108] As an example, refer to Figures 7A to 7B The diagram illustrates the establishment of a communication connection according to an embodiment of the present invention, which mainly embodies the zero-trust service hiding method of UDP-based SPA mode.
[0109] like Figure 7A As shown, firstly, a DTLS UDP SPA knock packet is sent to the UDP port. This knock packet may contain information such as the user's pre-shared key, device identifier, client source IP, and target port. Then, the zero-trust component can capture the SPA packets flowing through the network interface card and verify the data legitimacy of the SPA packets, such as through replay verification, forgery verification, user authentication, and device identifier verification. After successful verification, local firewall rules can be updated to grant TCP port access permissions (for a fixed period) to the source IP of legitimate users / devices. After a TCP three-way handshake and an SSL four-way handshake, an HTTPS connection can be established. In other words, in UDP-based SPA mode, the server closes all ports by default. Before a legitimate user can access the service, they need to send a UDP SPA knock packet containing authentication credentials. After successful verification, the corresponding service is opened to the specified source IP.
[0110] However, in actual operation, such as Figure 7BAs shown, while the UDP-based SPA mode has the advantage of not listening to any ports by default, which can prevent scanning and detection of hacker attacks and DDoS attacks from the source, it has the following disadvantages: 1) SNAT knocking amplification: Due to the SNAT translation resulting in the same public network exit IP, once a terminal successfully knocks, all terminals under that public network IP do not need to knock again, which is almost ineffective when a large number of employees remotely access the network; 2) Unstable UDP transmission: Since operators suppress UDP to a certain extent, there is usually a possibility of QoS rate limiting and packet loss. It is possible that UDP knocking packets will be lost, resulting in the inability to access services normally.
[0111] As another example, see Figures 8A to 8B This diagram illustrates another communication connection establishment method provided by an embodiment of the present invention, which mainly embodies the zero-trust service hiding method of TCP-based SPA mode.
[0112] like Figure 8A As shown, in TCP-based SPA mode, when the client initiates a connection, it does not need to send an additional UDP knock packet. Instead, the client hello packet in the TLS handshake process carries an SPA authorization packet containing the identity identifier to the service. If the server verifies the identity, a complete TLS connection is established; otherwise, the TCP connection is directly closed.
[0113] However, in actual operation, such as Figure 8B As shown, while TCP-based SPA mode has the following advantages: 1) Security: It cannot obtain port service type and version information, cannot be associated with vulnerability detection, and cannot launch further attacks; 2) Fine-grained control: Terminal-level port hiding enables fine-grained control; 3) Availability: It avoids the risk of packet loss in UDP transmission, greatly improving availability. However, it has the disadvantage of open TCP ports. Compared with UDP-based SPA, TCP-based SPA exposes ports, which can be scanned from the external network.
[0114] As yet another example, see reference Figures 9A to 9B This diagram illustrates another communication connection establishment method provided by an embodiment of the present invention, which mainly embodies the zero-trust service hiding method of UDP+TCP SPA hybrid mode.
[0115] The zero-trust service hiding method using a hybrid UDP+TCP SPA mode combines the advantages of the previous two SPA single-packet authorization methods. By adding TCP SPA capabilities on top of UDP SPA, the server closes all ports by default. Before a normal user can access the device, the client needs to send a UDP SPA knock packet containing identity credentials. After successful verification, the local firewall rules are updated to temporarily allow access to the device's TCP port by the specified source IP for a very short time window. During the subsequent connection establishment process, the TCP SPA process is followed to complete the TLS negotiation, which can further enhance security. For example, the entire process uses national cryptographic algorithms, the security code information of the knock packet can prevent HASH collision, and it supports brute-force locking.
[0116] In one possible embodiment, when the access duration of the Internet port reaches a preset time threshold, the access permission of the Internet port is closed to both internal and external network terminals.
[0117] like Figure 9A and 9B As shown, in the UDP+TCP SPA hybrid mode, the zero-trust client can send a UDP SPA knock packet in DTLS format to the server in advance. The payload of the knock packet can include the user's personal security code, random number, timestamp, and the MAC address and name of the terminal device. The zero-trust service SPAD on the device receives the UDP SPA knock packet and verifies whether the format of the knock packet is correct. If it is incorrect, the packet is dropped directly. Once the format is correct, the payload is decrypted and verified, including packet replay verification, packet spoofing verification, and user security code verification. After successful verification, the Zero Trust Service SPAD updates the device's local firewall rules, temporarily (e.g., for 60 seconds) opening TCP port access permissions for the source IP of legitimate users / devices. The Zero Trust client initiates a TCP connection request with the Zero Trust gateway, and successfully establishes a TCP connection after a TCP three-way handshake. The Zero Trust client initiates the TLS Secure Sockets Protocol, sending a TLS client hello handshake packet, with the SPA knock packet carried in the extended field of the TLS client hello. The Zero Trust Service SPAD parses the SPA knock packet from the extended field of the TLS client hello, decrypts and verifies the payload, including packet replay verification, packet spoofing verification, and user security code verification. After successful verification, the TLS handshake negotiation is successfully completed, an SSL encrypted transmission tunnel is established, and business data transmission begins.
[0118] In one possible embodiment, the internal and external network terminals include a personal space domain and a work space domain based on a zero-trust sandbox.
[0119] Specifically, based on the existing zero-trust access security platform, a security sandbox can be deployed on all PC terminals to prevent data leakage. With the security sandbox feature, a personal space and a work space can be distinguished on a single device. All systems run in the work space, and business access and related data are handled within the sandbox (i.e., the work space), ensuring data leakage prevention. The personal space does not use business or office systems and therefore is not subject to mandatory control, ensuring a smooth personal experience.
[0120] A security sandbox is an independent, encrypted data leak prevention workspace opened on the terminal side. Users access business systems in the workspace via a secure and encrypted link. All data is also encrypted and stored in the workspace and cannot be copied to the personal space. It also features network isolation between the personal space and the workspace, clipboard isolation, data import and export control, process protection, anti-screenshot, screen watermark deterrence and source tracing, and other data security and leak prevention features.
[0121] Optionally, depending on actual business needs, the following data leakage prevention functions and strategies can be implemented:
[0122] (1) File encryption: When creating, downloading, receiving and editing files in the workspace, the files are automatically encrypted and stored in the sandbox, so that even if the personal space is infected with ransomware, the files in the workspace will not be affected.
[0123] (2) Network isolation: The target address ranges accessible by workspace processes and personal space processes are isolated from each other by default.
[0124] (3) Application Management: The application management function allows you to set a list of programs that are only allowed to run within the workspace. When an end user runs a program not on the list, it will be blocked and a prompt will be displayed. This prevents applications from running freely within the sandbox and thus avoids security risks.
[0125] (4) File import and export control: policies can be used to restrict bidirectional file import and export operations between workspace and personal space.
[0126] (5) Clipboard isolation: Clipboard isolation can be configured with one-way or two-way isolation, such as only allowing copying from personal space to work space; fine-grained management of clipboard, allowing only N-byte strings to be copied, for example, in the outsourced debt collection scenario, it can be restricted to only allowing the copying of mobile phone numbers; when copying to personal space is allowed, the copied content is audited; copying and pasting within personal space is unrestricted;
[0127] (6) Screenshot prevention: Screenshot / screen recording tools in personal space cannot capture images in work space; content captured by screenshot / screen recording tools in work space cannot be taken out of work space; screenshot / screen recording tools can be restricted from running in work space through program management.
[0128] (7) Screen watermark: The workspace screen is watermarked to deter, audit and trace behaviors such as taking pictures of the screen.
[0129] This means that the security guarantee of dual-domain isolation between personal and workspaces through a zero-trust sandbox can achieve internal and external network isolation during office work and maintenance, reducing the risk of internal network intrusion after remote control of the computer; and it can improve office efficiency by switching between internal and external networks with one click. In practical applications, the workspace and personal space are dual-domain isolated and cannot access each other, copy and paste are not allowed, and interaction can only be carried out through the cloud document system. Downloading documents requires approval; system, host, database, and document operations within the workspace are all watermarked, including host screen watermarks, database screen watermarks, and document screen watermarks.
[0130] For example, such as Figure 10 As shown, working files can be encrypted and isolated through a sandbox. This feature builds a secure file system dedicated to the security domain within the mobile device's file system. It intercepts all file operations of the security domain application through hook technology, isolates the application data of the personal domain from the security domain, and performs high-strength encryption on both the file path (file isolation) and file content (file encryption) within the file sandbox. It also enables the security domain application to access files in both the security domain and the personal domain (file transfer).
[0131] In one possible embodiment, it can also respond to user login requests from internal and external network terminals to multiple business systems; the login accounts in the user login requests of multiple business systems are the same; and when internet port access permissions are opened to internal and external network terminals, internal and external network terminals are allowed to log in to multiple business systems based on the login account.
[0132] For example, the authentication, organizational structure, and permission system of the 4A system can be integrated through zero-trust, enabling one account, one authentication, and roaming across the entire network, improving employee perception and facilitating operation and maintenance. For instance, login can be achieved through a 4A account and password or by scanning a QR code with a work assistant (both using 4A authentication, a unified authentication system across the province); or through single sign-on to 4A and OA systems on the platform; or single sign-on to 4A; or single sign-on to OA, etc., achieving single sign-on between the OA system and the 4A system, unifying the web system portal, completing the integration of the work assistant and zero-trust, unifying the APP portal, and completing user management through an account lifecycle system, achieving unified identity authentication and management on mobile and PC terminals, ultimately achieving unified secure access control and convergence of internet exposure surfaces.
[0133] Optionally, embodiments of the present invention may also employ a zero-trust client for the application, which can create a virtual network interface card and introduce traffic to the national cryptographic proxy gateway through the zero-trust client, supporting two different tunnel connection technologies: long connection and short connection.
[0134] It should be noted that after a user accesses the intranet, their access behavior needs to be audited for security. If suspicious or abnormal access behavior is detected, access permissions need to be restricted, blocked, or the user's identity needs to be re-verified. When accessing highly sensitive services, more secure permission restriction policies are required.
[0135] Long connections, comparable to L3VPN resources in SSL VPNs, are often referred to as Layer 3 tunnels or system-level VPNs. When a client has multiple client / server applications, they connect to the proxy gateway via a single TCP connection. Short connections improve upon the original SSL VPN's TCP resources by employing Layer 3 to Layer 4 conversion technology. Traffic redirection is based on virtual network interface cards (SSL VPN's TCP resources use application-layer hooking technology). When a client has multiple client / server applications, a separate short TCP connection is established for each application through the Layer 3 to Layer 4 conversion mechanism. This enables proxy access and thus supports a wider range of applications, including both B / S and C / S applications. Furthermore, to overcome the shortcomings of traditional tunneling technologies and avoid compatibility issues with web resources, Zero Trust innovatively proposes tunnel-to-web technology. Zero Trust proxies client access traffic through the tunnel technology and then forwards it to a local web proxy service, which then forwards the traffic to the upstream resource server. Access traffic passing through a tunnel proxy retains the advantages of good compatibility and fast transmission speed of tunnel applications; while converting the tunnel proxy to a web proxy enables application layer functions such as URL auditing and web watermarking.
[0136] Optionally, embodiments of the present invention can also create a unique 1+1+N security protection model based on the integration of the work assistant and the zero-trust SDK. "1": One APP portal (the work assistant portal aggregates all self-used APPs); "1": One self-used system portal (the zero-trust platform portal aggregates all self-used systems); "N": N public internet systems (aggregated protection through a WEB dynamic defense system), completely eliminating the self-used exposure surface. Based on its strong data transmission security capabilities and solid technical accumulation in mobile security, the SDK provides the integrated mobile work assistant with secure access capabilities and a dual-domain isolation security sandbox. By integrating the lightweight SDK, the mobile work assistant achieves dual-domain isolation protection, encrypting and isolating data within the work assistant, allowing the work assistant to securely access internal network business systems, enabling secure and rapid mobile office work anytime, anywhere using mobile terminals.
[0137] Optionally, in this embodiment of the invention, in accordance with the principle that the intranet does not leave the computer room, all other branch intranets and office intranets are brought back to the computer room, and the entire province logs in via the Internet with zero trust, and then accesses the intranet after authentication.
[0138] Optionally, embodiments of the present invention can also use zero-trust integration of 4A authentication and permissions to minimize the control of employee ID permissions, avoid data leakage, achieve one account, one authentication, and roaming across the entire network, greatly improve user login system and operation and maintenance efficiency, and achieve minimal permission contraction.
[0139] In this embodiment of the invention, a unified access platform for internal and external networks is proposed. This unified access platform implements a zero-trust policy by adopting an SDP architecture, performs dual-domain isolation of personal space and work space through a zero-trust sandbox, and integrates the authentication, organizational structure, and permission system of the 4A system through zero trust. This enables remote office terminals and mobile office terminals to securely access the office network, solving problems such as diversified access roles, diversified usage scenarios, diversified access environments, and diversified access terminals. It aims to reduce the exposure surface of the Internet, ensure that the internal network does not leave the computer room, and thus increase the security of internal and external network terminals accessing the office network.
[0140] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.
[0141] Reference Figure 11 This diagram illustrates a structural block diagram of an embodiment of an access device for internal and external network terminals according to the present invention. It relates to an internal and external network access platform, which is deployed with a software-defined boundary architecture. The software-defined boundary architecture includes a zero-trust system and may specifically include the following modules:
[0142] The communication connection request receiving module 1101 is used to receive the communication connection request from the internal and external network terminals, wherein the communication connection includes a knock packet;
[0143] Access permission opening module 1102 is used to respond to the communication connection request and open Internet port access permissions to the internal and external network terminals based on the knock packet;
[0144] The business access request receiving module 1103 is used to establish a communication connection with the internal and external network terminals based on the access permissions, and to receive office business access requests from the internal and external network terminals; wherein, the internal and external network terminals include a personal space domain and a work space domain divided based on a zero-trust sandbox.
[0145] The office data return module 1104 is used to respond to the office business access request, obtain office data, and return the office data to the workspace domain of the internal and external network terminals.
[0146] In one embodiment of the present invention, the zero-trust system includes a zero-trust controller; the access permission opening module 1102 may include the following sub-modules:
[0147] The access permission opening submodule is used to grant access permissions to the Internet ports of the internal and external network terminals through the zero-trust controller based on the knock packet.
[0148] In one embodiment of the present invention, the access permission opening submodule may include the following units:
[0149] The access permission opening unit is used to verify whether the data packet format of the knocking packet is correct; if the data packet format of the knocking packet is correct, the knocking packet information of the knocking packet is verified; when the knocking packet information is verified, access permission to the Internet port is opened to the internal and external network terminals.
[0150] In one embodiment of the present invention, the door-knocking package information includes at least one or more of the following: user identity information, terminal device information, timestamp, network information, and location information;
[0151] The user identity information includes at least one or more of the following: security code information and random number; the terminal device information includes at least one or more of the following: device physical address information and device name.
[0152] In one embodiment of the present invention, the security code information is bound to internal and external network terminal users;
[0153] The security code information has a valid usage period and / or a number of uses.
[0154] In one embodiment of the present invention, the access permission opening unit may include the following sub-units:
[0155] The access permission opening subunit is used to perform at least one of the following verification processes on the knock packet information: data packet replay verification, data packet forgery verification, and user security code verification.
[0156] In one embodiment of the present invention, the access permission opening submodule may further include the following units:
[0157] The access permission closing unit is used to close the access permission of the Internet port to the internal and external network terminals when the open access duration of the Internet port reaches a preset duration threshold.
[0158] In one embodiment of the present invention, the zero-trust system includes a zero-trust gateway, and the office data return module 1104 may include the following sub-modules:
[0159] The office data return submodule is used to respond to the office business access request through the zero-trust gateway, obtain office data, and return the office data to the workspace domain of the internal and external network terminals.
[0160] In one embodiment of the present invention, the office data return submodule may include the following units:
[0161] The office data return unit is used to forward the office business access request to the office business server through the zero-trust gateway, obtain the office data returned by the office business server in response to the office business access request, forward the office data to the zero-trust controller through the zero-trust gateway, and return the office data to the workspace domain of the internal and external network terminals through the zero-trust controller.
[0162] In one embodiment of the present invention, the zero-trust system integrates multiple business systems, and the apparatus provided in this embodiment of the present invention may further include the following modules:
[0163] The business login module is used to respond to user login requests from the internal and external network terminals to the multiple business systems; the login accounts in the user login requests of the multiple business systems are the same; and when the internal and external network terminals have access to the Internet port, the internal and external network terminals are allowed to log in to the multiple business systems based on the login account.
[0164] In this embodiment of the invention, the access device for internal and external network terminals provided by this embodiment receives communication connection requests from internal and external network terminals through the zero-trust system of the internal and external network access platform. Based on the knock packet included in the communication connection request, it opens access permissions to the Internet ports of the internal and external network terminals to establish a communication connection between the internal and external network terminals and the internal and external network access platform based on the access permissions. It also obtains office data by responding to office business access requests and returns the obtained office data to the workspace domain of the internal and external network terminals. The zero-trust policy is implemented through a software-defined boundary architecture. Access permissions to the Internet ports of internal and external network terminals are opened based on the knock packet, and Internet port hiding technology is used to reduce the Internet exposure surface. Furthermore, the zero-trust sandbox provides security by isolating the internal and external network terminals in personal and workspaces, achieving isolation between internal and external networks during office work and maintenance, reducing the risk of internal network intrusion after remote control of the computer, and improving office efficiency by switching between internal and external networks with one click.
[0165] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.
[0166] This invention also provides an electronic device, comprising:
[0167] It includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, it implements the various processes of the above-described embodiments of the access method for internal and external network terminals and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0168] This invention also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the various processes of the above-described methods for accessing internal and external network terminals and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0169] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0170] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0171] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0172] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0173] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0174] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.
[0175] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.
[0176] The foregoing has provided a detailed description of the access method for internal and external network terminals, an access device for internal and external network terminals, a corresponding internal and external network access platform, a corresponding electronic device, and a corresponding computer-readable storage medium provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. An access method of an intranet / Internet terminal, characterized by, The method involves an internal / external network access platform, wherein the internal / external network access platform is deployed with a software-defined boundary architecture, the software-defined boundary architecture including a zero-trust system, and the method includes: The zero-trust system receives communication connection requests from internal and external network terminals, and the communication connection includes a knock packet. In response to the communication connection request, access to the Internet port is granted to the internal and external network terminals based on the knock packet; Based on the access permissions, a communication connection is established with the internal and external network terminals to receive office business access requests from the internal and external network terminals; wherein, the internal and external network terminals include a personal space domain and a work space domain divided based on a zero-trust sandbox. Responding to the office business access request, the system obtains office data and returns the office data to the workspace domain of the internal and external network terminals; The TCP SPA capability is added on top of UDP SPA. The server closes all ports by default. Before normal users can access the device, the client needs to send a UDP SPA knock packet containing identity credentials. After successful verification, the local firewall rules are updated to temporarily allow access to the device's TCP port by the specified source IP for a very short time window. The subsequent connection establishment process follows the TCP SPA process to complete the TLS negotiation. The zero-trust client initiates the TLS Secure Sockets Protocol, sends a TLS client hello handshake packet, and carries an SPA knock packet in the extended field of the TLS client hello; The Zero Trust Service SPAD parses the SPA knock packet from the TLSclienthello extended field, decrypts and verifies the payload, including packet replay verification, packet forgery verification, and user security code verification. After successful verification, the TLS handshake negotiation is completed, an SSL encrypted transmission tunnel is established, and business data transmission begins. The access permissions granted to the internal and external network terminals to open Internet ports based on the knocking packet include: Verify that the data packet format of the knocking packet is correct; If the data packet format of the knocking packet is correct, verify the knocking packet information of the knocking packet; When the door knocking information is verified, access to the Internet port is granted to the internal and external network terminals; The door-knocking package information includes at least one or more of the following: user identity information, terminal device information, timestamp, network information, and location information; The user identity information includes at least one or more of the following: security code information and random number; the terminal device information includes at least one or more of the following: device physical address information and device name.
2. The method of claim 1, wherein, The method further includes: When the access duration of the Internet port reaches a preset time threshold, the access duration of the Internet port is closed to both internal and external network terminals.
3. The method of claim 1, wherein, The security code information is bound to internal and external network terminal users; The security code information has a valid usage period and / or a number of uses.
4. The method of claim 2, wherein, The verification of the knock package information includes: The knock packet information is subjected to at least one of the following verification processes: data packet replay verification, data packet forgery verification, and user security code verification.
5. The method of claim 1, wherein, The zero-trust system includes a zero-trust controller and a zero-trust gateway; The access permissions granted to the internal and external network terminals to open Internet ports based on the knocking packet include: The zero-trust controller grants access to the internet ports of the internal and external network terminals based on the knock packet; The step of responding to the office service access request, obtaining office data, and returning the office data to the workspace domain of the internal and external network terminals includes: The zero-trust gateway responds to the office service access request, obtains office data, and returns the office data to the workspace domain of the internal and external network terminals.
6. The method according to claim 5, characterized in that, The step of responding to the office service access request through the zero-trust gateway, obtaining office data, and returning the office data to the workspace domain of the internal and external network terminals includes: The zero-trust gateway forwards the office service access request to the office service server and obtains the office data returned by the office service server in response to the office service access request. The office data is forwarded to the zero-trust controller through the zero-trust gateway, and then returned to the workspace domain of the internal and external network terminals through the zero-trust controller.
7. The method according to any one of claims 1-6, characterized in that, The zero-trust system integrates multiple business systems, and the method further includes: Responding to user login requests from the internal and external network terminals to the multiple business systems; the login accounts in the user login requests of the multiple business systems are the same; With internet port access granted to the internal and external network terminals, the internal and external network terminals are allowed to log in to the multiple business systems based on the login account.
8. An access device for internal and external network terminals, characterized in that, The device relates to an internal / external network access platform, wherein the internal / external network access platform is deployed with a software-defined boundary architecture, the software-defined boundary architecture includes a zero-trust system, and the device includes: A communication connection request receiving module is used to receive communication connection requests from the internal and external network terminals, wherein the communication connection includes a knock packet; The access permission opening module is used to respond to the communication connection request and, based on the knock packet, open access permissions for the Internet port to the internal and external network terminals; The business access request receiving module is used to establish a communication connection with the internal and external network terminals based on the access permissions, and to receive office business access requests from the internal and external network terminals; wherein, the internal and external network terminals include a personal space domain and a work space domain divided based on a zero-trust sandbox. The office data return module is used to respond to the office business access request, obtain office data, and return the office data to the workspace domain of the internal and external network terminals; The device is also used to overlay TCP SPA capability on top of UDP SPA. The server closes all ports by default. Before normal users can access the device, the client needs to send a UDP SPA knock packet containing identity credentials. After successful verification, the local firewall rules are updated to temporarily allow access to the device's TCP port for a very short time window. In the subsequent connection establishment process, the TCP SPA process is followed to complete the TLS conference negotiation. The zero-trust client initiates the TLS Secure Sockets Protocol, sends a TLSclienthello handshake packet, and carries an SPA knock packet in the extended fields of TLSclienthello; The Zero Trust Service SPAD parses the SPA knock packet from the TLSclienthello extended field, decrypts and verifies the payload, including packet replay verification, packet forgery verification, and user security code verification. After successful verification, the TLS handshake negotiation is completed, an SSL encrypted transmission tunnel is established, and business data transmission begins.
9. An electronic device, characterized in that, include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the access method for internal and external network terminals as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when executed by a processor, the computer program implements the access method for internal and external network terminals as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Remote office access method and system based on zero trust
CN116032533A