Network communication method and device based on zero trust system, equipment and medium
By enhancing the HTTP/HTTPS request message header in the zero-trust system and inserting user-related information for dynamic authentication and permission control, the problem that traditional network security architecture cannot cope with diverse attacks is solved, achieving higher security and flexibility.
Patent Information
- Application Number
- CN202411732678.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-28
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-11-28
AI Technical Summary
Traditional perimeter-based network security architecture cannot meet the security requirements of diverse attack methods. It relies on fixed network boundaries and static authentication mechanisms, resulting in insufficient network security.
A network communication method based on a zero-trust system is adopted. Dynamic authentication and permission control are performed by inserting user-related information into the HTTP/HTTPS request message header enhancement information, and each access request is strictly authenticated and authorized using the zero-trust model.
It improves network security and flexibility, simplifies management processes, optimizes resource utilization, reduces unnecessary network traffic and computing resource consumption, and improves user experience and the accuracy of identity authentication.
Smart Images

Figure CN119814355B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular to a network communication method, apparatus, device, and medium based on a zero-trust system. Background Art
[0002] With the rapid development of Internet technology, network security issues are becoming increasingly serious, causing great losses to users' personal information, property, etc.
[0003] In existing technologies, a boundary-based network security architecture is usually adopted, which often relies on fixed network boundaries and static authentication mechanisms. However, as attack methods become more and more diverse, the traditional boundary-based network security architecture can no longer meet security needs. Summary of the Invention
[0004] In view of the above problems, a network communication method, apparatus, device and medium based on a zero-trust system are proposed to overcome the above problems or at least partially solve the above problems, including:
[0005] A network communication method based on a zero-trust system, the method comprising:
[0006] receiving a request message sent by a user device;
[0007] generating header enhancement information for the request message according to relevant information of the user equipment, and performing header enhancement processing on the request message using the header enhancement information;
[0008] The request message after header enhancement processing is sent to the zero-trust system network element to verify the authority of the user device through the header enhancement information.
[0009] Optionally, the using the header enhancement information to perform header enhancement processing on the request message includes:
[0010] The header enhancement information is inserted into the header of the request message.
[0011] Optionally, the request message is a request message for user authentication, the zero-trust system network element is a zero-trust controller, and the sending of the request message after header enhancement processing to the zero-trust system network element to perform permission verification on the user device through the header enhancement information includes:
[0012] The request message after header enhancement processing is sent to the zero trust controller to perform user identity authentication on the user device through the header enhancement information.
[0013] Optionally, after sending the request message after the header enhancement processing to the zero trust controller to perform user identity authentication on the user device through the header enhancement information, the method further includes:
[0014] A response message returned in response to the enhanced request message is received, and the response message is sent to the user equipment so that the message content is displayed on the user equipment.
[0015] Optionally, the request message is a request message for user resource access, the zero-trust system network element is a zero-trust gateway, and the request message after header enhancement processing is sent to the zero-trust system network element to perform permission verification on the user device through the header enhancement information, including:
[0016] The request message after header enhancement processing is sent to the zero-trust gateway to authenticate the resource access permission of the user device through the header enhancement information, and access the resource server if the resource access permission authentication is passed.
[0017] Optionally, the relevant information of the user equipment includes any one or more of the following: user identity information, accessed network information, and geographic location information.
[0018] Optionally, the request message is a message based on Hypertext Transfer Protocol or Hypertext Transfer Protocol Secure.
[0019] A network communication device based on a zero-trust system, the device comprising:
[0020] A request message receiving module, configured to receive a request message sent by a user device;
[0021] a header enhancement module, configured to generate header enhancement information for the request message based on relevant information of the user equipment, and perform header enhancement processing on the request message using the header enhancement information;
[0022] The authority verification module is used to send the request message after header enhancement processing to the zero-trust system network element, so as to verify the authority of the user device through the header enhancement information.
[0023] An electronic device includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program implements the method described above when executed by the processor.
[0024] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described above is implemented.
[0025] The embodiments of the present invention have the following advantages:
[0026] In an embodiment of the present invention, by receiving a request message sent by a user device, header enhancement information for the request message is generated based on relevant information of the user device, and the header enhancement information is used to perform header enhancement processing on the request message. The request message after the header enhancement processing is sent to a zero-trust system network element to perform authority verification on the user device through the header enhancement information, thereby realizing authority verification based on the header enhancement information of the message in the zero-trust system, improving the security of the network, and thus meeting security requirements. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solution of the present invention, the following briefly introduces the drawings required for use in the description of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0028] Figure 1 is a flowchart of the steps of a network communication method based on a zero-trust system provided by some embodiments of the present invention;
[0029] Figure 2a is a schematic diagram of a system architecture provided by some embodiments of the present invention;
[0030] Figure 2b is a flowchart of another network communication method based on a zero-trust system provided by some embodiments of the present invention;
[0031] Figure 2c is a flowchart of another network communication method based on a zero-trust system provided by some embodiments of the present invention;
[0032] Figure 3 is a flowchart of another network communication method based on a zero-trust system provided by some embodiments of the present invention;
[0033] Figure 4 is a flowchart of another network communication method based on a zero-trust system provided by some embodiments of the present invention;
[0034] Figure 5 This is a structural block diagram of a network communication device based on a zero-trust system provided by some embodiments of the present invention. DETAILED DESCRIPTION
[0035] To make the above-mentioned objects, features, and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments described are only a portion of the embodiments of the present invention, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without inventive effort are also within the scope of protection of the present invention.
[0036] Currently, the Hypertext Transfer Protocol (HTTP), as one of the basic protocols of the Internet, was not originally designed with security issues in mind. The data transmitted by the HTTP protocol is in plain text and is easily eavesdropped and tampered with, posing a security risk to network applications.
[0037] To address HTTP security issues, the Hypertext Transfer Protocol Secure (HTTPS) was developed. HTTPS adds the SSL (Secure Socket Layer) / TLS (Transport Layer Security) protocols to HTTP to encrypt data transmission, improving confidentiality and integrity. However, HTTPS itself does not include a mechanism for transmitting user identity information.
[0038] In related technologies, strict identity authentication and access control of visitors are achieved by binding the user's MSISDN (Mobile Station International Subscriber Directory Number, international standard telephone number) information with campus information, combining the header enhancement function of the UPF (User Plane Function) device, the secondary authentication of the security gateway module, the session authentication list management, and the anomaly detection mechanism for multi-device access.
[0039] In this embodiment, dynamic network access authorization is achieved through identity verification based on HTTP / HTTPS header enhancement within a zero-trust system. By applying a zero-trust model and header enhancement, the system no longer relies on network location to determine visitor trustworthiness, but instead performs strict authentication and authorization on each access request. This model minimizes the scope of trust, granting only necessary permissions, significantly reducing security risks.
[0040] The embodiments of the present invention can easily adapt to a variety of network environments, business scenarios, and user authentication requirements, supporting a wider range of application scenarios. Furthermore, through HTTP / HTTPS header enhancement technology, the new technology can utilize richer user information for identity recognition, thereby providing more refined access control policies to meet the security needs of different business scenarios. Furthermore, the introduction of a zero-trust architecture stealth mechanism further enhances access security between users and protected resources, optimizes resource utilization, and reduces unnecessary network traffic and computing resource consumption.
[0041] In the embodiments of the present invention, the core purpose is to provide a more secure, flexible and easy-to-manage network access control solution, which specifically includes the following aspects:
[0042] Enhanced security: Through the Zero Trust model and header enhancement, the system no longer relies on network location to determine the trustworthiness of visitors. Instead, it strictly authenticates and authorizes each access request. This model minimizes the scope of trust and grants only necessary permissions, significantly reducing security risks.
[0043] Improved flexibility: The system does not require users to install any software or plug-ins. Users can access network resources through standard HTTP / HTTPS protocols. This design not only simplifies the deployment and management process, but also enables the system to easily adapt to various complex network environments, including cross-platform, cross-device and cross-network situations.
[0044] Optimized user experience: Users no longer need to worry about the underlying authentication and authorization mechanisms, allowing them to focus on the business itself. The system automatically handles complex authentication and authorization processes, reducing user wait time and operational complexity, thereby improving the user experience.
[0045] Simplified Management: Through centralized zero-trust configuration and management, administrators can easily manage the entire network access control system. The system provides a wealth of configuration options and monitoring tools, allowing administrators to monitor network access in real time, adjust access policies, and respond to potential security threats.
[0046] Support for dynamic authorization: The system can make dynamic authorization decisions based on HTTP / HTTPS header information and other contextual information (such as device status, network environment, etc.). This authorization mechanism based on real-time information enables the system to more accurately assess the credibility of visitors and grant appropriate permissions.
[0047] The present invention will be further described below with reference to the accompanying drawings:
[0048] Reference Figure 1, showing a step flow chart of a network communication method based on a zero-trust system provided by some embodiments of the present invention. As an emerging security architecture, the Zero Trust system assumes that no one inside or outside the network should be automatically trusted. Regardless of where the user is located, strict identity authentication and authorization are required to access network resources. It emphasizes continuous verification and dynamic authorization of all access subjects, and no longer relies on fixed network boundaries.
[0049] In some examples, the zero-trust system includes three modules: a zero-trust policy controller, a zero-trust gateway, and a header enhancement module. The main functions of the modules are as follows:
[0050] ① Zero Trust Policy Controller: The head enhances the information control and collection function, collects user identity information, access network information, geographic location, etc., and sends the collected information to the zero trust gateway.
[0051] ②Zero Trust Gateway: Responsible for the Zero Trust Policy Controller to collect HTTP / HTTPS request headers for enhanced information verification, and allow access to the target business system (such as resource server) after verification.
[0052] ③ Header enhancement: Insert one or more relevant information of the user device (such as user number, accessed operator network, accessed geographic location, etc.) into the HTTP / HTTPS request message header and pass it to the zero trust gateway so that zero trust can identify user information.
[0053] like Figure 2a 、 Figure 2b 、 Figure 2c , a network based on a zero-trust system includes the following network elements:
[0054] SDP-GATEWAY: A Software Defined Perimeter (SDP) gateway is a key component in the SDP architecture. The SDP gateway serves as the access control enforcement point, establishing a secure connection between clients and protected resources and ensuring that only authenticated and authorized users can access those resources.
[0055] SDP-CONTROLER: The software-defined border controller is a core component of the SDP architecture, responsible for managing all authentication and access processes. Often referred to as the "brain" of the solution, it defines and evaluates access policies and serves as the decision point for zero-trust policies.
[0056] SC (Service Classifier): Located at the edge of the SRV6 SFC service chain network, it is the source node of the service chain path. SCs can use various traffic diversion methods to direct service data into SRV6 TE Policy tunnels for forwarding.
[0057] UE (User Equipment): Devices used by end users, such as smartphones and tablets.
[0058] AMF (Access and Mobility Management Function): Responsible for performing registration, connection, reachability, mobility management and other functions, and providing a session management message transmission channel for UE and SMF.
[0059] SMF (Session Management Function): Responsible for user session management, including tunnel maintenance, IP address allocation and management, UP function selection, policy implementation, and QoS control.
[0060] PCRF / PCF (Policy and Charging Rules Function / Policy Control Function): Responsible for managing and controlling network policies and charging.
[0061] (R)AN (Radio Access Network): Responsible for the transmission and reception of wireless signals and serves as a bridge between user devices and the core network.
[0062] PDN (Public Data Network / Packet Data Network): A wide area network established by telecom operators that provides packet switching or circuit switching services.
[0063] eNB (Evolved Node B): An eNB is a base station device in a 5G network, responsible for communicating with UEs and forwarding user traffic to the core network. In some cases, an eNB can work with a gNB (next-generation base station), but currently only supports scenarios with a single eNB and a single UE.
[0064] UPF (User Plane Function): UPF is responsible for processing user plane data packets and ensuring that the data is correctly routed to the destination.
[0065] ISP (Internet Service Provider): An ISP provides internet access, ensuring that user devices can connect to the internet and access the resources they need. While the evidence does not directly mention the specific role of an ISP, it plays a crucial role in the overall network architecture, ensuring that data can be transmitted between different networks.
[0066] In some examples, embodiments of the present invention require cooperation between GW and PCRF.
[0067] Among them, the main functions of PCRF / PCF and SDP-CONTROLER are: PCRF and SDP-CONTROLER merge to issue predetermined rules, and execute services that match the predetermined rules to trigger the header enhancement function. The main function of UPF / GW-U is: to perform content enhancement processing on the HTTP / HTTPS message header, add one or more information in the user information (such as APN, IMEI, etc.) to the HTTP / HTTPS message header and pass it to the zero-trust gateway. The main function of SDP-GATEWAY is: to identify the user identity information in the HTTP / HTTPS message header, and establish a zero-trust secure connection between users and resources based on dynamic identity access control
[0068] Specifically, the following steps may be included:
[0069] Step 101: Receive a request message sent by a user equipment.
[0070] In some examples, the request message may be a message based on the Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPs). HTTP is a protocol for transmitting hypertext from a website server to a local browser. It allows users to access web pages and other resources over the Internet. HTTPS is a secure version of HTTP that adds an SSL / TLS encryption layer to HTTP to ensure the security and integrity of data during transmission.
[0071] In actual applications, the user equipment (UE) can send a request message to the UPF. The request message can be a request message for user authentication, a request message for user resource access, or other types of request messages.
[0072] In some examples, before the user device sends a request message to the UPF, a TCP connection can be established between the user device and the UPF, and communication can be carried out through the TCP connection.
[0073] Step 102: Generate header enhancement information for the request message based on the relevant information of the user equipment, and perform header enhancement processing on the request message using the header enhancement information.
[0074] Since messages based on the Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPs) do not carry information about user devices, it is possible to obtain information about user devices and then generate header enhancement information for the request message using the information. After obtaining the header enhancement information, the header enhancement information can be used to perform header enhancement processing on the request message, thereby allowing the request message to carry information about the user device.
[0075] In some examples, UPF identifies the protocol type of the message, parses the message after successful protocol identification, and performs policy matching based on the parsed message feature information (such as the message feature information may be the address port corresponding to the service requested to be accessed). When the request message matches the header enhancement processing, the local predefined configuration and user-related information can be extracted, and the header enhancement information can be inserted into the request message header to implement header enhancement processing of the request message.
[0076] In some examples, since the UPF adds header enhancement information to the message, it is also necessary to adjust certain field values of the TCP layer and IP layer according to the protocol specifications, such as the length and check fields.
[0077] In some embodiments of the present invention, the relevant information of the user equipment includes any one or more of the following: user identity information, accessed network information, and geographic location information.
[0078] In some examples, the HTTP / HTTPS header enhancement information can include information of the following types: IMSI / SUPI (IMSI is a unique number used to identify a mobile user in a 2G / 3G / 4G network, and SUPI is a unique number used to identify a mobile user in a 5G network), MSISDN / GPSI (Mobile Station International ISDN Number / Generic Public Subscription Identifier), RATTYPE (Radio Access Technology Type), APN (Access Point Name, for 4G access, the APN is issued by GW-C to GW-U, which can be an APN requested by a user, an APN actually used by a user, or a specified APN), IMEI / PEI (International Mobile Equipment Identity / Permanent Equipment Identifier), SGWADDR (SGSN / SGW IP address), USRADDR (User IP address), RATTYPES (Radio Access Technology Type (string)), ULI (User Location Information), PGWADDR (GGSN / PGW IP address), TIMESTAMP (UTC time), USERDEF (User Defined Fields), etc.
[0079] In some examples, each header enhancement field name can be defined by a user.
[0080] In some embodiments of the application, the header enhancement information is inserted into the header of the request message.
[0081] In actual application, after the header enhancement information is generated, the header enhancement information is encoded into an Extension field and inserted into the tail of the header of the request message.
[0082] Table 1 below shows the original request message, and Table 2 shows the request message after header enhancement processing.
[0083] IP header TCP header Client Hello message header Original Extension
[0084] Table 1
[0085] IP header TCP header Client Hello message header Original Extension Insert Extension
[0086] Table 2
[0087] In some examples, the inserted Extension field can also be protected against fraud. When the request message before header enhancement processing contains the same bytes as the Extension field to be inserted, the request message is considered to be a fraudulent message, and an anti-fraud strategy can be implemented on the fraudulent message.
[0088] Step 103: Send the request message after header enhancement processing to the zero-trust system network element to verify the authority of the user device through the header enhancement information.
[0089] After the header enhancement processing, the request message after the header enhancement processing can be sent to the zero-trust system network element. The zero-trust system network element can then obtain the header enhancement information from the request message after the header enhancement processing, and then perform authority verification on the user device based on the relevant information of the user device carried in the header enhancement information to complete the user verification process.
[0090] In some embodiments of the present invention, the request message is a request message for user authentication, the zero-trust system network element is a zero-trust controller, and the request message after header enhancement processing is sent to the zero-trust system network element to perform permission verification on the user device through the header enhancement information, including: sending the request message after header enhancement processing to the zero-trust controller to perform user identity authentication on the user device through the header enhancement information.
[0091] In some embodiments of the present invention, after sending the request message after header enhancement processing to the zero trust controller to perform user authentication on the user device through the header enhancement information, it also includes: receiving a response message returned for the request message after enhancement processing, and sending the response message to the user device to display the message content on the user device.
[0092] For request messages used for user authentication, after obtaining the request after header enhancement processing, the zero-trust controller can perform user identity authentication based on the header enhancement information itself, or forward it to a third-party authentication system for user identity authentication based on the header enhancement information.
[0093] After authentication is passed, the user authorization policy can be queried, the zero-trust gateway can be notified to release user access control, and a response message can be returned to the UPF. After parsing the message and adjusting the serial number, the UPF forwards it to the UE. The UE receives and displays the message content to the user.
[0094] In some embodiments of the present invention, the request message is a request message for user resource access, the zero-trust system network element is a zero-trust gateway, and the request message after header enhancement processing is sent to the zero-trust system network element to perform permission verification on the user device through the header enhancement information, including: sending the request message after header enhancement processing to the zero-trust gateway to perform resource access permission authentication on the user device through the header enhancement information, and accessing the resource server if the resource access permission authentication is passed.
[0095] For request messages for user resource access, the zero-trust gateway can allow or reject the user's resource access request based on the controller's policy and the matched header enhancement information after receiving the request message after header enhancement processing, and forward the legitimate user request that matches the policy to the corresponding resource server for processing.
[0096] In an embodiment of the present invention, by receiving a request message sent by a user device, header enhancement information for the request message is generated based on relevant information of the user device, and the header enhancement information is used to perform header enhancement processing on the request message. The request message after the header enhancement processing is sent to a zero-trust system network element to perform authority verification on the user device through the header enhancement information, thereby realizing authority verification based on the header enhancement information of the message in the zero-trust system, improving the security of the network, and thus meeting security requirements.
[0097] Under the Zero Trust system architecture, the use of header enhancement to implement identity recognition and dynamic network access authorization has demonstrated many significant advantages and positive effects, as follows:
[0098] First, it significantly improves the accuracy of identity authentication. By adding additional user information to the HTTP / HTTPS request header, such as the user's phone number, the carrier network being accessed, and the geographic location being accessed, the system can gain a more comprehensive understanding of the user's identity and perform more accurate authentication based on this information. This fine-grained identity recognition method effectively reduces the security risks associated with identity fraud or forgery.
[0099] Secondly, HTTP / HTTPS header enhancements significantly enhance the flexibility of dynamic access control. Traditional access control policies are often based on static permission allocations, while this approach dynamically adjusts access permissions based on real-time user information and behavior. This means the system can more intelligently determine user access intent and grant appropriate permissions accordingly, ensuring both security and improving the user experience.
[0100] Furthermore, the clientless design greatly simplifies client deployment and management. Users can access network resources through standard HTTP / HTTPS protocols without installing additional software or plug-ins. This not only reduces system complexity but also mitigates security risks caused by client software vulnerabilities or user errors.
[0101] Furthermore, HTTP / HTTPS header enhancements help improve the user experience. Without the need to install additional software or plug-ins, users can access network resources more conveniently, reducing wait times and operational complexity. Furthermore, because the system can more accurately identify users and provide personalized services accordingly, users can enjoy a more attentive and satisfying experience.
[0102] Finally, from a business continuity perspective, HTTP / HTTPS header enhancements also help maintain stable service operations. Through precise identity verification and dynamic network access authorization, the system ensures that only verified entities can access network resources, thereby preventing service interruptions or data leaks caused by unauthorized access.
[0103] The following combination Figure 2b and Figure 2c The present invention is illustrated by way of example:
[0104] like Figure 2b The network includes UE, eNB, SMF, UPF, and ISP, and specifically includes the following processes:
[0105] 1. The UE establishes a TCP connection with the ISP;
[0106] 2. The UE sends an HTTPS Client Hello Request (seq_0, len_0) (i.e., a request message for user authentication) to the UPF. After receiving the message, the UPF performs header enhancement by len_1.
[0107] 3. UPF sends an HTTPS Client Hello Request (seq_0, len_0+len_1) to the ISP (i.e., the request message after header enhancement).
[0108] 4. The ISP returns HTTPS Response (seq_0, len_0 + len1) (i.e., the response message) to the UPF, and the UPF adjusts the sequence number by len_1;
[0109] 5. UPF sends HTTPS Response (seq_0, len_0) (i.e., response message) to UE.
[0110] like Figure 2c The network includes UE, UPF, SDP CONTREOLER, SDP GATEWAY, PCRF, and PCF. Specifically, it includes two processes: user authentication and user resource access:
[0111] The user authentication process is as follows:
[0112] 1. The user goes online and establishes a TCP connection. When the TCP connection establishment message reaches the UPF, the UPF allows it to pass.
[0113] 2. The UE initiates an HTTP / HTTPS service, and the HTTP / HTTPS Client Hello Request message (i.e., the request message for user authentication) sent by the UE arrives at the UPF. The UPF identifies the protocol type of the message, and after successful protocol identification, it parses and processes the message, performs policy matching based on the parsed message feature information, and performs billing or execution based on the matching results. When it is determined that the message matches the HTTP / HTTPS header enhancement action and HTTP / HTTPS header enhancement processing is required, the local predefined configuration and user-related information are extracted, and the header enhancement information is inserted into the HTTP / HTTPS Client Hello Request message header. Since the UPF adds data information to the message, it is also necessary to adjust certain field values of the TCP layer and IP layer in accordance with the protocol regulations, such as the length and check field.
[0114] 3. The UPF sends the HTTP / HTTPS Client Hello Request message with the header enhancement information added to the zero trust controller.
[0115] 4. After receiving the HTTP / HTTPS Client Hello Request message, the zero-trust controller obtains the current user's information (i.e., the relevant information of the user device carried in the header enhancement information) to identify the user's identity (or forwards it to a third-party authentication system to identify the user's identity), constructs and returns a personalized response message to the UPF user.
[0116] 5. Authentication succeeds, the user authorization policy is queried, and the gateway is notified to release user access control. The UPF parses the received HTTP / HTTPS Response message (i.e., the response message), adjusts the sequence number, and forwards it to the UE. The UE receives and displays the HTTP / HTTPS Response message content to the user. The UE is unaware of the UPF's HTTP / HTTPS header enhancement processing of the service message.
[0117] The process of user resource access is as follows:
[0118] 6. The user initiates a resource access request. After the message reaches UPF, UPF allows it to pass.
[0119] 7. When UPF determines that the message matches the HTTP / HTTPS header enhancement action and HTTP / HTTPS header enhancement processing is required, it extracts the local predefined configuration and user-related information, and inserts the header enhancement information into the HTTP / HTTPS Client Hello Request message (that is, the request message used for user resource access) header.
[0120] 8. UPF routes the user request to the Zero Trust Gateway.
[0121] 9. The zero-trust gateway allows or rejects the user's resource access request based on the controller's policy and the matched user header enhanced identity information.
[0122] 10. Forward legitimate user requests that match the policy to the corresponding resource server for processing.
[0123] Reference Figure 3 , shows a flowchart of another network communication method based on a zero-trust system provided by some embodiments of the present invention, which may specifically include the following steps:
[0124] Step 301: Receive a request message sent by a user device; wherein the request message is a request message for user authentication.
[0125] Step 302: Generate header enhancement information for the request message based on the relevant information of the user equipment, and perform header enhancement processing on the request message using the header enhancement information.
[0126] Step 303: Send the request message after header enhancement processing to the zero trust controller to perform user identity authentication on the user device through the header enhancement information.
[0127] Step 304: Receive a response message returned to the request message after the enhanced processing, and send the response message to the user equipment so that the message content is displayed on the user equipment.
[0128] Reference Figure 4 , shows a flowchart of another network communication method based on a zero-trust system provided by some embodiments of the present invention, which may specifically include the following steps:
[0129] Step 401: Receive a request message sent by a user device; wherein the request message is a request message for user resource access.
[0130] Step 402: Generate header enhancement information for the request message based on the relevant information of the user equipment, and perform header enhancement processing on the request message using the header enhancement information.
[0131] In step 403, the request message after header enhancement processing is sent to the zero-trust gateway to authenticate the resource access permission of the user device through the header enhancement information, and access the resource server if the resource access permission authentication is passed.
[0132] It should be noted that for the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.
[0133] Reference Figure 5 , shows a schematic structural diagram of a network communication device based on a zero-trust system provided by some embodiments of the present invention, which may specifically include the following modules:
[0134] The request message receiving module 501 is used to receive a request message sent by a user equipment;
[0135] a header enhancement module 502, configured to generate header enhancement information for the request message based on relevant information of the user equipment, and perform header enhancement processing on the request message using the header enhancement information;
[0136] The authority verification module 503 is used to send the request message after the header enhancement processing to the zero-trust system network element, so as to verify the authority of the user equipment through the header enhancement information.
[0137] In some embodiments of the present invention, the step of using the header enhancement information to perform header enhancement processing on the request message includes:
[0138] The header enhancement information is inserted into the header of the request message.
[0139] In some embodiments of the present invention, the request message is a request message for user authentication, the zero-trust system network element is a zero-trust controller, and the request message after header enhancement processing is sent to the zero-trust system network element to perform permission verification on the user device through the header enhancement information, including:
[0140] The request message after header enhancement processing is sent to the zero trust controller to perform user identity authentication on the user device through the header enhancement information.
[0141] In some embodiments of the present invention, after sending the request message after header enhancement to the zero trust controller to perform user identity authentication on the user device based on the header enhancement information, the method further includes:
[0142] A response message returned in response to the enhanced request message is received, and the response message is sent to the user equipment so that the message content is displayed on the user equipment.
[0143] In some embodiments of the present invention, the request message is a request message for user resource access, the zero-trust system network element is a zero-trust gateway, and the request message after header enhancement processing is sent to the zero-trust system network element to perform permission verification on the user device through the header enhancement information, including:
[0144] The request message after header enhancement processing is sent to the zero-trust gateway to authenticate the resource access permission of the user device through the header enhancement information, and access the resource server if the resource access permission authentication is passed.
[0145] In some embodiments of the present invention, the relevant information of the user equipment includes any one or more of the following: user identity information, accessed network information, and geographic location information.
[0146] In some embodiments of the present invention, the request message is a message based on Hypertext Transfer Protocol or Hypertext Transfer Protocol Secure.
[0147] Some embodiments of the present invention further provide an electronic device, comprising a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program implements the above method when executed by the processor.
[0148] Some embodiments of the present invention further provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the above method is implemented.
[0149] Some embodiments of the present invention further provide a computer program product, including a computer program, which implements the above method when executed by a processor.
[0150] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0151] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0152] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0153] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, apparatus, or computer program products. Thus, embodiments of the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0154] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the process in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0155] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0156] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0157] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.
[0158] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the above elements.
[0159] The above is a detailed introduction to the network communication method, device, equipment and medium based on the zero-trust system. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for general technical personnel in this field, according to the ideas of the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.
Claims
1. A network communication method based on a zero-trust system, characterized in that: The method comprises: receiving a request message sent by a user device; generating header enhancement information for the request message according to relevant information of the user equipment, and performing header enhancement processing on the request message using the header enhancement information; The request message after header enhancement processing is sent to the zero-trust system network element to verify the authority of the user device through the header enhancement information.
2. The method according to claim 1, characterized in that The step of using the header enhancement information to perform header enhancement processing on the request message includes: The header enhancement information is inserted into the header of the request message.
3. The method according to claim 1 or 2, characterized in that The request message is a request message for user authentication, the zero-trust system network element is a zero-trust controller, and the request message after header enhancement processing is sent to the zero-trust system network element to perform permission verification on the user device through the header enhancement information, including: The request message after header enhancement processing is sent to the zero trust controller to perform user identity authentication on the user device through the header enhancement information.
4. The method according to claim 3, characterized in that After sending the request message after the header enhancement processing to the zero trust controller to perform user identity authentication on the user device through the header enhancement information, the method further includes: A response message returned in response to the enhanced request message is received, and the response message is sent to the user equipment so that the message content is displayed on the user equipment.
5. The method according to claim 1 or 2, characterized in that The request message is a request message for user resource access, the zero-trust system network element is a zero-trust gateway, and the request message after header enhancement processing is sent to the zero-trust system network element to perform permission verification on the user device through the header enhancement information, including: The request message after header enhancement processing is sent to the zero-trust gateway to authenticate the resource access permission of the user device through the header enhancement information, and access the resource server if the resource access permission authentication is passed.
6. The method according to claim 1, characterized in that The relevant information of the user equipment includes any one or more of the following: user identity information, accessed network information, and geographic location information.
7. The method according to claim 1, characterized in that The request message is a message based on the Hypertext Transfer Protocol or Hypertext Transfer Protocol Secure.
8. A network communication device based on a zero-trust system, characterized in that: The device comprises: A request message receiving module, configured to receive a request message sent by a user device; a header enhancement module, configured to generate header enhancement information for the request message based on relevant information of the user equipment, and perform header enhancement processing on the request message using the header enhancement information; The authority verification module is used to send the request message after header enhancement processing to the zero-trust system network element, so as to verify the authority of the user device through the header enhancement information.
9. An electronic device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program implements the method according to any one of claims 1 to 7 when executed by the processor.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Licensing authority controlled modification of HTTP headers in a proxy-based system
US20200169536A1
Monetization and data rights enablement in a data management ecosystem
US20230289409A1