Communication method and device, electronic equipment and readable storage medium
The terminal device receives and processes business access requests, adapts according to the access rights of the application and network type, and realizes the one-machine access function to the intranet and external network, solves the complex problems of the existing technology, and improves the security of data transmission.
Patent Information
- Application Number
- CN202411894720.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-05-06
AI Technical Summary
In the prior art, access to the intranet and external networks is performed separately through different devices, resulting in complex methods and it is difficult to realize the dual-use function of one machine.
Receive service access requests sent by the application through the terminal device, obtain application access permissions and destination communication address, and determine the network type based on the destination address. If the permissions and types are matched, the request will be sent to the gateway device for forwarding.
It realizes a dual-purpose function of the same terminal device that can access both the intranet and the external network, improving the security of data transmission and avoiding the access of services of applications without permissions.
Smart Images

Figure CN119945719A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a communication method, device, electronic device and readable storage medium. Background Art
[0002] In some application scenarios, the network is divided into an intranet and an extranet.
[0003] In the related art, external network access is performed through a device specifically used for accessing the external network, so as to ensure the security of business access.
[0004] However, this method of using different devices to access the intranet and the extranet respectively has a problem of being complicated. Summary of the invention
[0005] In view of the above problems, embodiments of the present application are proposed to provide a communication method, device, electronic device and readable storage medium that overcome the above problems or at least partially solve the above problems.
[0006] In a first aspect, an embodiment of the present application discloses a communication method, which is applied to a terminal device, and the method includes:
[0007] Receiving a service access request sent by an application, obtaining application access rights of the application, and a destination communication address of the service access request; the application access rights include: access rights to an intranet, or access rights to an extranet;
[0008] Determine the network type of the network accessed by the service access request according to the destination communication address; the network type includes an intranet or an extranet;
[0009] If the application access rights are compatible with the network type, the service access request is sent to a gateway device, so that the gateway device sends the service access request to a target network corresponding to the destination communication address, and the target network executes the service access request.
[0010] In a second aspect, this embodiment provides a communication method, which is applied to a gateway device, and the method includes:
[0011] receiving a service access request sent by a terminal device; the service access request is a service access request sent by an application, in which the terminal device obtains application access rights and a destination communication address of the service access request, determines a network type of a network accessed by the service access request according to the destination communication address, and sends the service access request to the gateway device when it is determined that the application access rights and the network type of the network accessed by the service access request are compatible;
[0012] Sending the service access request to a target network corresponding to the destination communication address, so that the target network executes the service access request;
[0013] The application access rights include: the right to access the intranet, or the right to access the extranet; the network type includes the intranet or the extranet.
[0014] In a third aspect, this embodiment provides a communication device, which is applied to a terminal device, and includes:
[0015] A first acquisition module is used to receive a service access request sent by an application, and obtain application access rights of the application and a destination communication address of the service access request; the application access rights include: access rights to an intranet or access rights to an extranet;
[0016] A first determination module, used to determine the network type of the network accessed by the service access request according to the destination communication address; the network type includes an intranet or an extranet;
[0017] The first sending module is used to send the service access request to the gateway device if the application access rights are compatible with the network type, so that the gateway device sends the service access request to the target network corresponding to the destination communication address, and the target network executes the service access request.
[0018] In a fourth aspect, this embodiment provides a communication device, the device is located in a gateway device, and the device includes:
[0019] A first receiving module is configured to receive a service access request sent by a terminal device; the service access request is a service access request sent by an application program, wherein the terminal device obtains application program access rights and a destination communication address of the service access request when receiving the service access request, determines a network type of a network accessed by the service access request according to the destination communication address, and sends the service access request to the gateway device when it is determined that the application program access rights and the network type of the network accessed by the service access request are compatible;
[0020] The second sending module is used to send the service access request to the target network corresponding to the destination communication address, and the target network executes the service access request; wherein the application access rights include: the right to access the intranet, or the right to access the extranet; the network type includes the intranet or the extranet.
[0021] In a fifth aspect, this embodiment provides an electronic device, including:
[0022] one or more processors; and
[0023] One or more machine-readable media having instructions stored thereon, when executed by the one or more processors, cause the processors to perform the communication method as described in the first aspect or the second aspect.
[0024] In a sixth aspect, this embodiment provides a computer-readable storage medium, which stores a computer program that enables a processor to execute the communication method as described in the first aspect or the second aspect.
[0025] The embodiment of the present invention includes the following advantages: when receiving a service access request sent by an application, the application access rights of the application and the destination communication address of the service access request are obtained; according to the destination communication address, the network type of the network accessed by the service access request is determined; if the application access rights and the network type are compatible, the service access request is sent to the gateway device. Based on this embodiment, it can be determined whether to forward and execute the service access request according to the access rights of the application and the network type of the network accessed by the service access request, thereby, through the same terminal device, access to the intranet and access to the extranet can be achieved. That is, based on this embodiment, the dual-purpose function of the same terminal device that can access both the intranet and the extranet is achieved. Only when the application access rights and the network type of the network accessed by the service access request are compatible, the service access request is sent to the gateway device for forwarding and processing, which can prevent applications without permission from accessing the service corresponding to the service access request, thereby improving the security of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 is a flow chart of steps of a communication method of the present application;
[0027] Figure 2 is a flowchart of the steps of another communication method of the present application;
[0028] Figure 3 is a flowchart of steps of another communication method of the present application;
[0029] Figure 4 It is a flow chart of the interaction steps of a communication method of the present application;
[0030] Figure 5 is a schematic diagram of a communication system of the present application;
[0031] Figure 6 is a flowchart of the steps of another communication method of the present application;
[0032] Figure 7 It is a structural block diagram of a communication device of the present application;
[0033] Figure 8 is a structural block diagram of another communication device of the present application;
[0034] Fig. 9 It is a structural block diagram of an electronic device of the present application. DETAILED DESCRIPTION
[0035] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, the present application is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.
[0036] Figure 1 A communication method is shown, referring to Figure 1 , the method may include the following steps:
[0037] Step 101: receiving a service access request sent by an application, obtaining the application access rights of the application, and a destination communication address of the service access request.
[0038] Application access permissions include: permission to access the intranet or permission to access the extranet.
[0039] For example, the method of this embodiment is applied to a terminal device. The terminal device may be a mobile computer, a desktop computer, or other terminal devices. Furthermore, a visual Internet protocol driver (VVoE) is installed in the terminal device, and the method of the embodiment of this application is implemented through the VVoE software.
[0040] For example, the destination communication address may be a destination Internet Protocol (IP) address.
[0041] For example, the terminal device sends the identity authentication information of the terminal device to the security management and control platform, and the security management and control platform performs identity authentication on the terminal device according to the identity authentication information. If the identity authentication is successful, the access rule for data transmission is sent to the terminal device, wherein the access rule includes application access rights of at least one application.
[0042] The terminal device receives and stores the access rules sent by the security management and control platform, and obtains the port information of the service access request when receiving the service access request sent by the application. Then, based on the port information of the service access request, the terminal device determines the application sending the service access request, and obtains the application access rights of the application sending the service access request from the stored application access rights.
[0043] Step 102: Determine the network type of the network accessed by the service access request according to the destination communication address.
[0044] The network type includes an intranet or an extranet.
[0045] For example, the intranet and the extranet have different communication address ranges, and the destination communication address is compared with the communication address range of the intranet and the communication address range of the extranet to obtain a comparison result of the communication address. If the destination communication address belongs to the intranet communication address range, the network type of the network accessed by the service access request is determined to be the intranet; if the destination communication address belongs to the extranet communication address range, the network type of the network accessed by the service access request is determined to be the extranet.
[0046] Step 103: If the application access rights and the network type are compatible, the service access request is sent to the gateway device, so that the gateway device sends the service access request to the target network corresponding to the destination communication address, and the target network executes the service access request.
[0047] Furthermore, if the application access rights and the network type of the network accessed by the service access request do not match, the service access request is rejected from being sent to the gateway device.
[0048] For example, if the application access permission of the application is the permission to access the intranet, and the network type of the network accessed by the business access request is the intranet, then it is determined that the application access permission and the network type of the network accessed by the business access request are compatible; if the application access permission of the application is the permission to access the extranet, and the network type of the network accessed by the business access request is the extranet, then it is determined that the application access permission and the network type of the network accessed by the business access request are compatible.
[0049] For example, if the application access permission of the application is the permission to access the intranet, and the network type of the network accessed by the business access request is the extranet, then it is determined that the application access permission and the network type of the network accessed by the business access request do not match; if the application access permission of the application is the permission to access the extranet, and the network type of the network accessed by the business access request is the intranet, then it is determined that the application access permission and the network type of the network accessed by the business access request do not match.
[0050] In this embodiment, if the application access rights are compatible with the network type of the network accessed by the service access request, the service access request is sent to the gateway device so that the gateway device can send the service access request to the target network corresponding to the destination communication address, and the target network will execute the service access request. Specifically, if the application has the right to access the intranet, and the service access request is a request to access the intranet, the service access request is sent to the gateway device, which is forwarded and executed by the gateway device; if the application has the right to access the extranet, and the service access request is a request to access the extranet, the service access request is sent to the gateway device. Based on this embodiment, it can be determined whether to forward and execute the service access request based on the application access rights and the network type of the network accessed by the service access request. Thus, the same terminal device can be used to access the intranet and the extranet. That is, based on this embodiment, the dual-purpose function of the same terminal device that can access both the intranet and the extranet is realized.
[0051] In addition, the service access request will only be sent to the gateway device for forwarding and processing when the application access rights and the network type of the network accessed by the service access request are compatible. This can prevent unauthorized applications from accessing the service corresponding to the service access request, thereby improving the security of data transmission.
[0052] For example, refer to Figure 2 The method of this embodiment can be applied to a terminal device. Specifically, the method may include the following steps:
[0053] Step 201, sending the identity authentication information of the terminal device to the security management and control platform, so that the security management and control platform can authenticate the terminal device according to the identity authentication information, and if the identity authentication is passed, feedback the routing information for sending the service access request to the terminal device and the gateway device.
[0054] Furthermore, the identity authentication information of the terminal device is sent to the security management and control platform so that the security management and control platform can authenticate the terminal device based on the identity authentication information. If the identity authentication fails, the routing information for sending the service access request is refused to be fed back to the terminal device and the gateway device.
[0055] For example, when a terminal device registers for network access, the security management and control platform stores the terminal device's identity authentication information and authenticates the terminal device's legal identity. When the terminal device sends the terminal device's identity authentication information to the security management and control platform, the security management and control platform compares the identity authentication information sent by the terminal device with the locally stored legal user's identity authentication information. If the comparison is successful, the identity authentication is determined to be successful; otherwise, the identity authentication is determined to be unsuccessful.
[0056] The terminal device obtains the routing information for forwarding the service access request, and then determines the forwarding path of the service access request, and then successfully sends the service access request to the gateway device that sends data to the intranet or the extranet. The gateway device obtains the routing information for forwarding the service access request, and then after receiving the service access request sent by the terminal device, it can determine the forwarding path of the service access request according to the routing information to forward the service access request.
[0057] Step 202: Receive a service access request sent by an application program, and obtain application program access rights of the application program and a destination communication address of the service access request.
[0058] The application access rights include: the permission to access the intranet or the permission to access the extranet.
[0059] The method of this step has been described in the aforementioned step 101 and will not be repeated here.
[0060] Step 203: Determine the network type of the network accessed by the service access request according to the destination communication address.
[0061] The network type includes an intranet or an extranet.
[0062] The method of this step has been described in the aforementioned step 102 and will not be repeated here.
[0063] Step 204: If the application access rights and the network type match, the service access request is sent to the gateway device according to the routing information, so that the gateway device can send the service access request to the target network corresponding to the destination communication address according to the routing information, and the target network can execute the service access request.
[0064] If the application access rights and the network type of the network accessed by the service access request are consistent, it means that the application has the access rights to the service corresponding to the application access request. In this case, the terminal device sends the service access request to the gateway device according to the routing information sent by the security management and control platform, which can ensure the security of data transmission.
[0065] Step 205: If the application access permission and the network type of the network accessed by the service access request do not match, the service access request is rejected from being sent to the gateway device.
[0066] If the application access rights and the network type of the network accessed by the service access request do not match, it means that the application does not have the authority to access the service corresponding to the service access request. In this case, the service access request is rejected and sent to the gateway device, thereby preventing the application without access rights from accessing the service. This improves data transmission security.
[0067] In this embodiment, only when the security management and control platform determines that the terminal device identity authentication is passed, will it send routing information for determining the forwarding path of the service access request to the terminal device and the gateway device. Only when the terminal device determines that the application access rights of the application are compatible with the network type of the network accessed by the service access request, will the service access request be forwarded to the gateway device. In other words, if the security management and control platform fails to authenticate the terminal device, the terminal device and the gateway device cannot obtain the routing information required for forwarding the service access request. If the terminal device recognizes that the application access rights of the application and the network type of the network accessed by the service access request are incompatible, the service access request will not be forwarded to the gateway device.
[0068] Therefore, based on the method of this embodiment, it is possible to avoid the situation where the service access request is still forwarded to the gateway device when the terminal device is illegal or the application does not have the authority to access the service requested by the service access request, and it is possible to avoid illegal devices and unauthorized applications from accessing the service requested by the service access request. Based on the method of this embodiment, the security of data forwarding is improved, and on the basis of ensuring the security of data forwarding, the service access to the intranet and the extranet can be realized through the same terminal device, realizing the dual-use function of a one-machine device that can access the intranet and the extranet.
[0069] For example, this embodiment can be applied to the field of visual networking. In this embodiment, the terminal device is installed with VVoE software, and the terminal device installed with VVoE software is the entrance for the user terminal to access the visual networking and the entrance for network access. Based on VVoE software, the sandbox technology used to implement the above-mentioned embodiment can be implemented, and the sandbox technology can be used to protect data security and realize the dual-use function of intranet and extranet service access.
[0070] Furthermore, a visual network transmission channel is established between the gateway device and the terminal device installed with the VVoE software, wherein the gateway device is used to provide data forwarding function for the terminal device installed with the VVoE software. Furthermore, the gateway device integrates the functions of the H03 router and the zero-trust gateway, and based on the functions of the H03 router, application proxy and data encrypted transmission can be realized.
[0071] Among them, the H03 router has high-performance routing and forwarding capabilities and rich interface options, and can support different network topologies and multiple protocols.
[0072] Furthermore, in order to achieve efficient communication with terminal devices installed with VVoE software, the H03 router is configured to support Virtual Local Area Network (VLAN) or Multi-Protocol Label Switching (MPLS) technology to ensure the isolation and security of data transmission.
[0073] For example, before step 202, the following steps are also included:
[0074] Step 206, sending the identity authentication information of the terminal device to the security management and control platform, so that the security management and control platform can perform identity authentication according to the identity authentication information, and if the identity authentication passes, sending the device access rights of the terminal device to the gateway device.
[0075] For example, a terminal device with VVoE software installed uses virtualization technology to register and authenticate on a security management and control platform to obtain device access rights.
[0076] For example, the device access permission may be a service level at which the terminal device can access a service; or may be permission to access a service, or non-permission to access a service.
[0077] After the security management and control platform determines the device access rights of the terminal device, it sends the device access rights to the gateway device so that the gateway device can authenticate the terminal device installed with the VVoE software after receiving the service access request sent by the terminal device, and perform access control on the service access request.
[0078] Specifically, after step 203, the following steps are also included:
[0079] Step 207, the service access request and the device identification of the terminal device are sent to the gateway device, so that the gateway device can obtain the device access rights of the terminal device from the multiple stored device access rights according to the device identification. When the device access rights match the service level of the service accessed by the service access request, the service access request is sent to the target network corresponding to the destination communication address, and the target network executes the service access request.
[0080] For example, the terminal device sends a service access request and a device identification of the terminal device to a gateway device, so that the gateway device obtains the device access rights of the terminal device from multiple stored device access rights based on the device identification. If the device access rights and the service level of the service accessed by the service access request do not match, the service access request is refused to be sent to the gateway device.
[0081] For example, the device access rights of the terminal device include the service level of the service that can be accessed. When the device access rights of the terminal device are higher than or equal to the service level of the service to be accessed by the service access request, it is determined that the device access rights and the service level of the service accessed by the service access request are compatible; when the device access rights of the terminal device are lower than the service level of the service to be accessed by the service access request, it is determined that the device access rights and the service level of the service accessed by the service access request are incompatible.
[0082] For example, if the terminal device has device access rights that allow access to confidential services, and the service level of the service to be accessed by the service access request is non-confidential services, then the terminal device's access rights are higher than the service level of the service to be accessed by the service access request.
[0083] For another example, the terminal device's device access rights are: can access non-confidential services, and the service level of the service to be accessed by the service access request is confidential services, then the terminal device's access rights are lower than the service level of the service to be accessed by the service access request.
[0084] For example, there may be multiple terminal devices in this embodiment, and each terminal device sends its own identity authentication information to the security management and control platform. The security management and control platform performs identity authentication on each terminal device. After the authentication is passed, the device access rights of each terminal device are sent to the gateway device.
[0085] The gateway device stores the device access rights corresponding to each terminal device, and upon receiving a service access request and a device identification sent by the terminal device, obtains the service access rights corresponding to the device identification from the stored multiple device access rights.
[0086] For example, after step 203, the method further includes:
[0087] Step 208: encrypt the service access request to obtain an encrypted service access request.
[0088] For example, a secure transmission channel is established between a terminal device installed with VVoE software and a gateway device through an Internet Protocol Security (IPSec) tunnel, a Secure Socket Layer (SSL), and a Transport Layer Security (TLS). The terminal device encrypts the service access request based on IPSec technology or the SSL / TLS protocol to obtain an encrypted service access request.
[0089] Step 209: Send the encrypted service access request to the gateway device through the encrypted transmission channel between the terminal device and the gateway device.
[0090] By transmitting business access requests through encrypted transmission channels, data can be transmitted securely.
[0091] The terminal device of this embodiment is installed with VVoE software. Among them, VVoE is a terminal software for visual networking to carry data services, which can support functions such as visual networking access and data transmission. It can be used as a security plug-in in the terminal device to support more terminal security-related functions. Based on the VVoE software and the method of this embodiment, the dual-use function of accessing the intranet and the extranet through the same terminal device can be realized.
[0092] In one embodiment, referring to Figure 3 , the method is applied to a gateway device, and the method may include the following steps:
[0093] Step 301: receiving a service access request sent by a terminal device.
[0094] Among them, the service access request is that when the terminal device receives the service access request sent by the application, it obtains the application access permission and the destination communication address of the service access request, determines the network type of the network accessed by the service access request according to the destination communication address, and sends the service access request to the gateway device when it is determined that the application access permission and the network type of the network accessed by the service access request are consistent.
[0095] The method of this step can refer to the description of the aforementioned steps 101 to 103, which will not be repeated here.
[0096] Step 302: Send the service access request to the target network corresponding to the destination communication address, and the target network executes the service access request.
[0097] The application access rights include: the permission to access the intranet, or the permission to access the extranet; the network type includes the intranet or the extranet.
[0098] The method of this step can refer to the description of the aforementioned step 103, which will not be repeated here.
[0099] Based on the method of this embodiment, it can be determined whether to forward and execute the service access request according to the access rights of the application and the network type of the network accessed by the service access request, so that the same terminal device can access both the intranet and the extranet. That is, based on this embodiment, the dual-purpose function of the same terminal device that can access both the intranet and the extranet is realized. Only when the access rights of the application and the network type of the network accessed by the service access request are compatible, the service access request is sent to the gateway device for forwarding and processing, which can prevent unauthorized applications from accessing the services corresponding to the service access request, thereby improving the security of data transmission.
[0100] For example, before step 301, the method may further include the following steps:
[0101] Step 303: Receive routing information sent by the security management and control platform.
[0102] Routing information is the routing information that the security management and control platform sends to the gateway device after authenticating the terminal device based on the terminal device's identity authentication information and passing the authentication.
[0103] The method of this step has been described in the aforementioned step 201 and will not be repeated here.
[0104] Step 302 may include the following sub-steps:
[0105] Sub-step 3021, sending the service access request to the target network corresponding to the destination communication address according to the routing information.
[0106] The method of this step has been described in the aforementioned step 204 and will not be repeated here.
[0107] For example, before step 301, the method further includes:
[0108] Step 304: Receive and store the device access rights of the terminal device sent by the security management and control platform.
[0109] Among them, device access rights are the device access rights that the security management and control platform authenticates the terminal device based on the identity authentication information of the terminal device, and sends to the gateway device when the identity authentication passes.
[0110] The corresponding step 302 may include the following sub-steps:
[0111] Sub-step 3022, obtaining a device identification of the terminal device, and obtaining the device access permission of the terminal device from a plurality of stored device access permissions according to the device identification.
[0112] The method of this step has been described in the aforementioned step 207 and will not be repeated here.
[0113] Sub-step 3023, obtaining the service level of the service accessed by the service access request, and sending the service access request to the target network corresponding to the destination communication address when the device access permission and the service level are compatible.
[0114] The method of this step has been described in the aforementioned step 207 and will not be repeated here.
[0115] In this embodiment, the terminal device installed with the VVoE software transmits data with the internal network through the proxy gateway device. The proxy gateway device filters, converts and encrypts the transmitted data according to the method of this embodiment, thereby improving the security of data transmission.
[0116] In one embodiment, voice processing and secure data transmission services are started on a terminal device with VVoE software installed, and the two services are monitored in real time through a security management and control platform, so that the terminal device with VVoE software installed can isolate the voice processing and secure data transmission services in different virtual environments to ensure that the same terminal device can process voice communications and serve as a node for secure data transmission.
[0117] For example, refer to Figure 4 , the method may include the following steps:
[0118] Step 401: The terminal device receives a service access request sent by an application program, and obtains the application program access rights of the application program and a destination communication address of the service access request.
[0119] The application access rights include: the right to access the intranet, or the right to access the extranet.
[0120] The method of this step has been described in the aforementioned step 101 and will not be repeated here.
[0121] Step 402: The terminal device determines the network type of the network accessed by the service access request according to the destination communication address.
[0122] The network type includes an intranet or an extranet.
[0123] The method of this step has been described in the aforementioned step 102 and will not be repeated here.
[0124] Step 403: If the terminal device determines that the application access permission is compatible with the network type, the terminal device sends the service access request to the gateway device.
[0125] The method of this step has been described in the aforementioned step 103 and will not be repeated here.
[0126] Step 404: The gateway device sends the service access request to a target network corresponding to the destination communication address, and the target network executes the service access request.
[0127] The method of this step has been described in the aforementioned step 302 and will not be repeated here.
[0128] In this embodiment, the terminal device determines whether to forward and execute the service access request based on the access rights of the application and the network type of the network accessed by the service access request. When it is determined that the access rights of the application and the network type of the network accessed by the service access request are compatible, the service access request is sent to the gateway device, and the gateway device sends the service access request to the target network corresponding to the destination communication address of the service access request and executes it. Thus, the same terminal device can access both the intranet and the extranet. That is, based on this embodiment, the dual-purpose function of the same terminal device that can access both the intranet and the extranet is realized.
[0129] Reference Figure 5 This embodiment also provides a communication system that can implement any of the above-mentioned embodiments. The communication system includes a terminal device 501 installed with VVoE software, a security management and control platform 502, a gateway device 503, multiple routing devices (routing devices 5041 to 5044), and a visual network core server 505. The gateway device 503 is a zero-trust gateway prototype, which integrates the functions of the H03 router.
[0130] The security management and control platform 502 is the control center of the entire communication system, and is used to perform user identity authentication on user terminals, access rule management, and data channel management.
[0131] Furthermore, the security management and control platform 502 is integrated with a zero-trust control system. Through the security management and control platform 502 integrated with the zero-trust control system, the user's terminal device 501, gateway device 503 and other devices can be managed, and identity authentication and dynamic authorization can be performed based on the identity authentication information of the terminal device 501.
[0132] Specifically, before sending a service access request, the terminal device 501 sends the identity authentication information to the security management and control platform 502. The security management and control platform 502 performs identity authentication on the terminal device 501. If the authentication is successful, the routing information is sent to the terminal device 501 and the gateway device 503 through the routing device 5041 and the visual network core server 505, and the device access rights of the terminal device 501 are sent to the gateway device 503.
[0133] After determining that the application access rights of the application sending the service access request are compatible with the network type of the network accessed by the service access request, the terminal device 501 determines the routing device 5042 between the gateway device 503 according to the routing information, and sends the service access request to the gateway device 503 through the determined routing device.
[0134] When the gateway device 503 determines that the device access rights of the terminal device 501 match the service level of the service accessed by the service access request, the service access request is sent to the target network corresponding to the destination communication address of the service access request, and the target network executes it. Each time the gateway device 503 receives a service access request, it verifies the device access rights of the terminal device 501 that sent the service access request, thereby realizing data transmission based on the zero trust model and improving data transmission security.
[0135] For example, if the network type of the network accessed by the service access request is an intranet, the gateway device 503 forwards the service access request to the routing device 5043 connected to the intranet, and the routing device 5043 forwards the service access request. If the network type of the network accessed by the service access request is an extranet, the gateway device 503 forwards the service access request to the routing device 5044 connected to the extranet, and the routing device 5044 forwards the service access request. For example, the extranet is the Internet.
[0136] Reference Figure 6 , the method may include the following steps:
[0137] Step S1, establish a communication connection between the terminal device installed with the VVoE software and the security management and control platform, and send the identity authentication information of the terminal device to the security management and control platform.
[0138] A secure transmission channel is established between the terminal device with VVoE software installed and the gateway device with H03 router function. The secure transmission channel can be a channel that uses IPSec protocol or SSL / TLS protocol for data encryption transmission.
[0139] Step S2: The security management and control platform performs identity authentication on the terminal device according to the identity authentication information. If the authentication fails, the system proceeds to step S3; otherwise, the system proceeds to step S4.
[0140] A communication connection is established between the terminal device with VVoE software installed and the security management and control platform. The terminal device with VVoE software installed registers and authenticates its identity through the security management and control platform to obtain legal access rights. The terminal device with VVoE software installed transmits data with the internal network through the proxy gateway device.
[0141] Step S3, stop processing.
[0142] If the identity authentication of the terminal device fails, the processing is stopped, thereby improving the security of data transmission.
[0143] Step S4, the security management and control platform obtains routing information, device access rights of the terminal device, and application access rights of the application software, and sends the routing information to the terminal device, and sends the routing information, device access rights, and application access rights to the gateway device.
[0144] When the identity authentication of the terminal device is passed, the security management and control platform sends routing information, device access rights of the terminal device, and application access rights of the application software, so that the terminal device and gateway device can send and process business access requests based on this information, thereby realizing data forwarding based on zero-trust technology and improving the security of data transmission.
[0145] Step S5: The terminal device encrypts the service access request and sends the encrypted service access request to the gateway device according to the routing information.
[0146] The business access request is transmitted in an encrypted manner, which improves the security of data transmission.
[0147] Step S6, the terminal device determines whether the network type of the network accessed by the application program access rights and the service access request is compatible, and then proceeds to step S7, otherwise returns to step S2.
[0148] If the application access rights and the network type of the network accessed by the service access request are compatible, it means that the application has the authority to access the service accessed by the service access request; otherwise, it means that the application does not have the authority to access the service accessed by the service access request.
[0149] Step S7, the terminal device determines whether the device access rights of the terminal device and the service level of the service access request are compatible, if yes, it goes to step S8, otherwise it returns to step S2.
[0150] If the device access permission matches the service type of the service accessed by the service access request, it means that the terminal device has the permission to access the service accessed by the service access request; otherwise, it means that the terminal device does not have the permission to access the service accessed by the service access request.
[0151] For example, the execution steps of step S6 and step S7 may be: first execute step S6, then execute step S7; or, first execute step S7, then execute step S6.
[0152] Step S8: The gateway device sends the service access request to the target network corresponding to the destination communication address according to the routing information, and the target network executes the service access request.
[0153] Based on this embodiment, it can be determined whether to forward and execute the service access request according to the access rights of the application and the network type of the network accessed by the service access request, so that the same terminal device can access both the intranet and the extranet. That is, based on this embodiment, the dual-purpose function of the same terminal device that can access both the intranet and the extranet is realized.
[0154] Figure 7 It is a communication device provided in an embodiment of the present application, and the device 60 is located in a terminal device. Figure 7 , the device 60 may include:
[0155] The first acquisition module 601 is used to receive a service access request sent by an application, and obtain application access rights of the application and a destination communication address of the service access request; the application access rights include: access rights to an intranet or access rights to an extranet;
[0156] A first determination module 602 is used to determine the network type of the network accessed by the service access request according to the destination communication address; the network type includes an intranet or an extranet;
[0157] The first sending module 603 is used to send the service access request to the gateway device if the application access rights and the network type are compatible, so that the gateway device sends the service access request to the target network corresponding to the destination communication address, and the target network executes the service access request.
[0158] Optionally, the device 60 further includes:
[0159] The third sending module is used to send the identity authentication information of the terminal device to the security management and control platform, so that the security management and control platform can authenticate the terminal device according to the identity authentication information, and feedback the routing information for sending the service access request to the terminal device and the gateway device if the identity authentication is passed;
[0160] The first sending module 603 includes:
[0161] The first sending submodule is used to send the service access request to the gateway device according to the routing information, so that the gateway device sends the service access request to the target network corresponding to the destination communication address according to the routing information, and the target network executes the service access request.
[0162] Optionally, the device 60 further includes:
[0163] The fourth sending module is used to send the identity authentication information of the terminal device to the security management and control platform, so that the security management and control platform can perform identity authentication according to the identity authentication information, and send the device access rights of the terminal device to the gateway device if the identity authentication passes;
[0164] The first sending module 603 may include:
[0165] The second sending submodule is used to send the service access request and the device identification of the terminal device to the gateway device, so that the gateway device can obtain the device access rights of the terminal device from the stored multiple device access rights according to the device identification, and when the device access rights are compatible with the service level of the service accessed by the service access request, the service access request is sent to the target network corresponding to the destination communication address, and the target network executes the service access request.
[0166] Optionally, the first sending module 603 may include:
[0167] An encryption module, used to encrypt the service access request to obtain an encrypted service access request;
[0168] The third sending submodule is used to send the encrypted service access request to the gateway device through the encrypted transmission channel between the terminal device and the gateway device.
[0169] Optionally, the device 60 further includes:
[0170] The determination module is used to, after determining the network type of the network accessed by the service access request according to the destination communication address, refuse to send the service access request to the gateway device if the application access rights and the network type of the network accessed by the service access request are inconsistent.
[0171] Based on this embodiment, the dual-purpose function of the same terminal device that can access both the intranet and the extranet is realized. When the application access rights and the network type of the network accessed by the service access request are compatible, the service access request is sent to the gateway device for forwarding and processing, which can prevent unauthorized applications from accessing the services corresponding to the service access request, thereby improving the security of data transmission.
[0172] Reference Figure 8 The embodiment of the present application further provides a communication device, wherein the device 70 is located in a gateway device, and the device 70 may include:
[0173] The first receiving module 701 is used to receive a service access request sent by a terminal device; the service access request is a service access request sent by an application program, wherein the terminal device obtains the application program access rights and the destination communication address of the service access request, determines the network type of the network accessed by the service access request according to the destination communication address, and sends the service access request to the gateway device when it is determined that the application program access rights and the network type of the network accessed by the service access request are consistent;
[0174] The second sending module 702 is used to send the service access request to the target network corresponding to the destination communication address, and the target network executes the service access request; wherein, the application access rights include: the right to access the intranet, or the right to access the extranet; the network type includes the intranet or the extranet.
[0175] Optionally, the device 70 further includes:
[0176] The second receiving module is used to receive routing information sent by the security management and control platform; the routing information is the routing information sent by the security management and control platform to the gateway device after the terminal device is authenticated according to the identity authentication information of the terminal device and after the identity authentication is passed;
[0177] The second sending module 702 may include:
[0178] The fourth sending submodule is used to send the service access request to a target network corresponding to the destination communication address according to the routing information.
[0179] Optionally, the device 70 further includes:
[0180] The third receiving module is used to receive and store the device access rights of the terminal device sent by the security management and control platform; the device access rights are the device access rights sent by the security management and control platform to the gateway device after the security management and control platform authenticates the terminal device according to the identity authentication information of the terminal device and passes the identity authentication;
[0181] The second sending module includes:
[0182] A first acquisition submodule is used to acquire a device identification of a terminal device, and acquire a device access permission of the terminal device from a plurality of stored device access permissions according to the device identification;
[0183] The second acquisition submodule is used to acquire the service level of the service accessed by the service access request, and send the service access request to the target network corresponding to the destination communication address when the device access authority and the service level are compatible.
[0184] Based on this embodiment, the dual-purpose function of the same terminal device that can access both the intranet and the extranet is realized. When the application access rights and the network type of the network accessed by the service access request are compatible, the service access request is sent to the gateway device for forwarding and processing, which can prevent unauthorized applications from accessing the services corresponding to the service access request, thereby improving the security of data transmission.
[0185] The embodiment of the present invention discloses an electronic device, such as Fig. 9 As shown, it includes: a processor 401 and a memory 402, the memory 402 stores programs or instructions that can be run on the processor 401, and when the programs or instructions are executed by the processor 401, any of the above communication methods is implemented.
[0186] An embodiment of the present invention discloses a computer-readable storage medium, wherein a computer program stored in the storage medium enables a processor to execute any one of the above methods.
[0187] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0188] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, devices, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0189] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0190] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0191] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable terminal device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0192] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present application.
[0193] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or terminal device including the elements.
[0194] The above is a detailed introduction to a communication method, device, equipment and storage medium provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for general technical personnel in this field, according to the idea of the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A communication method, characterized in that: Applied to a terminal device, the method comprises: Receiving a service access request sent by an application, obtaining application access rights of the application, and a destination communication address of the service access request; the application access rights include: access rights to an intranet, or access rights to an extranet; Determine the network type of the network accessed by the service access request according to the destination communication address; the network type includes an intranet or an extranet; If the application access rights are compatible with the network type, the service access request is sent to a gateway device, so that the gateway device sends the service access request to a target network corresponding to the destination communication address, and the target network executes the service access request.
2. The method according to claim 1, characterized in that The method further comprises: Sending the identity authentication information of the terminal device to the security management and control platform, so that the security management and control platform can authenticate the terminal device according to the identity authentication information, and if the identity authentication is passed, feeding back the routing information for sending the service access request to the terminal device and the gateway device; The sending the service access request to the gateway device includes: According to the routing information, the service access request is sent to a gateway device, so that the gateway device sends the service access request to a target network corresponding to the destination communication address according to the routing information, and the target network executes the service access request.
3. The method according to claim 1, characterized in that The method further comprises: Sending the identity authentication information of the terminal device to the security management and control platform, so that the security management and control platform can perform identity authentication according to the identity authentication information, and sending the device access rights of the terminal device to the gateway device if the identity authentication passes; The sending the service access request to the gateway device includes: The service access request and the device identification of the terminal device are sent to the gateway device, so that the gateway device obtains the device access rights of the terminal device from multiple stored device access rights according to the device identification. When the device access rights match the service level of the service accessed by the service access request, the service access request is sent to the target network corresponding to the destination communication address, and the target network executes the service access request.
4. A communication method, characterized in that: Applied to a gateway device, the method comprises: receiving a service access request sent by a terminal device; the service access request is a service access request sent by an application, in which the terminal device obtains application access rights and a destination communication address of the service access request, determines a network type of a network accessed by the service access request according to the destination communication address, and sends the service access request to the gateway device when it is determined that the application access rights and the network type of the network accessed by the service access request are compatible; Sending the service access request to a target network corresponding to the destination communication address, so that the target network executes the service access request; The application access rights include: the right to access the intranet, or the right to access the extranet; the network type includes the intranet or the extranet.
5. The method according to claim 4, characterized in that The method further comprises: Receive routing information sent by the security management and control platform; the routing information is the routing information sent to the gateway device by the security management and control platform after the terminal device is authenticated according to the identity authentication information of the terminal device and after the identity authentication is passed; Sending the service access request to a target network corresponding to the destination communication address includes: The service access request is sent to a target network corresponding to the destination communication address according to the routing information.
6. The method according to claim 4, characterized in that The method further comprises: Receive and store the device access rights of the terminal device sent by the security management and control platform; the device access rights are the device access rights sent by the security management and control platform to the gateway device after the security management and control platform authenticates the terminal device according to the identity authentication information of the terminal device and passes the identity authentication; Sending the service access request to a target network corresponding to the destination communication address includes: Obtaining a device identification of the terminal device, and obtaining a device access permission of the terminal device from a plurality of stored device access permissions according to the device identification; The service level of the service accessed by the service access request is obtained, and when the device access permission and the service level are compatible, the service access request is sent to a target network corresponding to the destination communication address.
7. A communication device, characterized in that: The device is located in a terminal device, and the device includes: A first acquisition module is used to receive a service access request sent by an application, and obtain application access rights of the application and a destination communication address of the service access request; the application access rights include: access rights to an intranet or access rights to an extranet; A first determination module, used to determine the network type of the network accessed by the service access request according to the destination communication address; the network type includes an intranet or an extranet; The first sending module is used to send the service access request to the gateway device if the application access rights are compatible with the network type, so that the gateway device sends the service access request to the target network corresponding to the destination communication address, and the target network executes the service access request.
8. A communication device, characterized in that: The device is located in a gateway device, and the device includes: A first receiving module is configured to receive a service access request sent by a terminal device; the service access request is a service access request sent by an application program, wherein the terminal device obtains application program access rights and a destination communication address of the service access request when receiving the service access request, determines a network type of a network accessed by the service access request according to the destination communication address, and sends the service access request to the gateway device when it is determined that the application program access rights and the network type of the network accessed by the service access request are compatible; The second sending module is used to send the service access request to the target network corresponding to the destination communication address, and the target network executes the service access request; wherein the application access rights include: the right to access the intranet, or the right to access the extranet; the network type includes the intranet or the extranet.
9. An electronic device, characterized in that: include: one or more processors; and One or more machine-readable media having instructions stored thereon, when executed by the one or more processors, cause the processors to perform the communication method according to any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that: The computer program stored therein enables the processor to execute the communication method according to any one of claims 1 to 6.