Hierarchical multi-granularity access control method and system for park network
By developing a multi-grained flow authorization tag access control system in the upper layer of the SDN controller, and dynamically issuing access control communication flow tables, the problem of insufficient traffic isolation between secure areas in the park network in the existing technology is solved, efficient and economical security authorization access is achieved, and the security and stability of the park network is improved.
Patent Information
- Application Number
- CN202510138571.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-08
- Publication Date
- 2025-05-09
AI Technical Summary
The prior art has problems such as high configuration complexity, insufficient dynamics and flexibility, high professional capabilities of administrators, and difficult to achieve refined access control and maintenance management costs in the park network, resulting in insufficient efficiency, flexibility and security.
By developing a park network-level multi-grained flow authorization tag access control system on the upper layer of the SDN controller, the OpenFlow protocol is used to dynamically issue a hierarchical multi-grained access control communication flow table to the access switch, so as to control users' access to specific resources, and divide security areas according to resource levels, and use different granularity flow authorization tags for security protection.
It realizes efficient, economical, automated and intelligent secure authorized access to the park network resources, reduces manual intervention, improves management efficiency, and improves the security and stability of the park network.
Smart Images

Figure CN119966726A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security, and in particular relates to a campus network hierarchical multi-granularity access control method and system. Background Art
[0002] Campus network usually refers to the campus network of colleges and universities or the internal network of enterprises (intranet). In this kind of network, in order to ensure security, the network is usually divided into multiple security areas according to protection needs. Different security areas correspond to different levels of network resources. To ensure security, the traffic interaction between these security areas needs to be strictly controlled, and only authorized traffic is allowed to access the corresponding security area, thereby effectively preventing malicious traffic attacks and ensuring the stability and security of the campus network.
[0003] There are many problems with existing technologies when implementing traffic isolation between campus network security areas, which are mainly reflected in the following aspects: high configuration complexity. Administrators need to manually write a large number of access control rules. As the network scale expands, the number and complexity of rules increase exponentially, which can easily lead to configuration errors; insufficient dynamism and flexibility. Traditional solutions are mostly based on static rules, which are difficult to cope with dynamic changes such as user device replacement, IP reallocation or new users joining, and lack the ability to quickly adjust policies; high requirements on administrators' professional capabilities, who need to have deep network knowledge and configuration skills. Configuration errors or rule conflicts may cause legitimate traffic to be blocked or malicious traffic to pass; it is difficult to achieve refined access control. Static rules cannot be flexibly adjusted according to the real-time status of traffic, and it is difficult to meet fine-grained control requirements based on user identity, device type or access time; high maintenance and management costs. The rule base becomes large and complicated over time, and there is a lack of automated tools to assist in optimization and cleaning; in addition, the ability to respond to security threats lags behind. Traditional solutions are mostly based on known threat patterns, and it is difficult to adjust rules in a timely manner when facing unknown attacks. These problems have led to obvious deficiencies in the efficiency, flexibility and security of existing solutions. An automated, intelligent and dynamic technical solution is urgently needed to reduce manual intervention, improve management efficiency, and enhance the security and stability of the campus network.
[0004] Therefore, it is an urgent problem to be solved in the security of the campus network to divide the network resources in the campus network into different levels of security areas, and to use different granularity flow authorization tags (FAT) communication flow tables to provide corresponding levels of security protection for different levels of areas, thereby establishing a multi-level host authentication and access control mechanism. For this reason, the present invention is proposed. Summary of the invention
[0005] In view of the deficiencies in the prior art, the present invention provides a hierarchical multi-granularity access control method and system for a campus network, which provides a cost-effective solution for secure authorized access to campus network resources. For service resources with different security protection level requirements, the resources in the campus network are divided into security areas of different levels based on the importance of the resources. According to the list of resources allowed to be accessed by users and the attributes of the importance of the resources entered in advance by the administrator, a hierarchical multi-granularity access control communication flow table is dynamically issued to the access switch through the OpenFlow protocol in the Software-Defined Networks (SDN), so as to realize the control function for user access to specific resources, and based on this, a hierarchical multi-granularity flow authorization label access control system of a multi-function module is established.
[0006] Specifically, a campus network hierarchical multi-granularity flow authorization label access control system application is developed at the upper layer of the SDN controller. By collecting campus network user information and device information, an associated database is established, and the resources in the campus network are divided into areas with different security levels. The SDN controller automatically detects the network user information after sensing user access, and interacts with the upper-layer application system through the API to improve the database user information and formulate communication flow table access rules, and sends a communication flow table based on hierarchical multi-granularity access control to the access switch. The access switch performs access control on the user's communication behavior in the designated security area in real time according to the flow table, which provides reliability for preventing users from illegally crossing security areas to access campus network resources in the campus network.
[0007] Terminology explanation:
[0008] Mode: The core component used to define the database structure, mapping the database table and its fields in the form of Python classes; the model not only defines how the data is stored, but also supports the definition of relationships with other models (such as one-to-many, one-to-one, many-to-many).
[0009] ORM: Object-relational mapping is a tool provided by Django for directly manipulating the database through model classes; it abstracts table records into Python objects, allowing developers to use Python code to add, delete, modify, and query the database without writing native SQL.
[0010] The technical solution of the present invention is as follows:
[0011] A first aspect of the present invention provides a campus network hierarchical multi-granularity access control method, comprising:
[0012] Step 1: Create a Model model in the upper-layer application of the SDN controller and establish a related database through ORM relationship model mapping;
[0013] Step 2: The administrator classifies the resources of the campus network and issues access control, classifying the resources into basic resources, important resources, and key resources according to their importance.
[0014] Step 3: Initialize the network topology data structure in the SDN controller, including switches and hosts, monitor the change events in the network, update and record the network topology data, send the detected campus network topology data to the upper-layer background application in real time through asynchronous multi-threading, and realize the storage of key data;
[0015] Step 4: After the administrator issues access control or the SDN controller senses user access, the background application scans the resource level to which the access control belongs in the database record table and creates access flow table rules based on the resource level;
[0016] Step 5: Send the access rules to the SDN controller. The SDN controller creates a communication flow table and sends two flow tables to the access switch. The access switch performs data packet forwarding operations according to the received flow table rules to complete network access control.
[0017] Preferably, in step 1, a Model model is created in the upper layer application of the SDN controller, and an associated database is established through ORM relationship model mapping; including:
[0018] The Model model includes the user host model and the network device model;
[0019] The user host model includes user ID, host IPv4 address, host IPv6 address, host MAC address, user name, user unit, user network device, user allowed access resource list, network resource security level and user access port number; network device model includes device ID, device connection topology, device type and device location;
[0020] Establish an associated database through ORM relational model mapping, and run the migration command through the Django background to automatically create a database table based on the model. The fields of the model correspond one-to-one with the fields of the database table.
[0021] Preferably, in step 2, the administrator divides the resource levels of the campus network and issues access control, and divides the resources into basic resources, important resources and key resources according to their importance; including:
[0022] Administrators divide the resource levels of the campus network into basic resources, which mainly include network devices with general data, storage and computing capabilities within the campus network;
[0023] Critical resources, including network equipment with significant data, storage, and computing capabilities;
[0024] Critical resources, including network equipment with critical data, resources that have a significant impact on core business and security, storage and computing capabilities;
[0025] Then, access control is issued according to different resource levels. For basic resources, which are not very important, by specifying the source address and destination address (SD) in the flow table issued from the resource end to the access switch, end-to-end access can be restricted, blocking access to resources by users not allowed by the system, thus forming the most basic security area protection and traffic isolation function.
[0026] For important resources, in order to further protect the important resource area, VLAN is introduced on the basis of specifying the source address and destination address (SD) in the flow table to customize and assign a unique VLAN ID to each data packet, that is, basic resources and important resources are divided into independent logical networks VLAN 1 and VLAN 2, respectively, and the source address (S), destination address (D) and virtual LAN identifier (VLAN ID) are specified in the flow table sent to the access switch at the important resource end;
[0027] For key resources, the source address (S), destination address (D) and vxlan network identifier (VNID, which is also the unique identifier of the user in the campus network) are specified in the flow table sent from the resource end to the access switch. Through the matching results of the data flow and the table items, end-to-end access can be restricted, blocking the behavior of users who want to access resources without authorization. In addition, through the VNID field in the data flow, the access behavior can be located to a specific user, forming a more advanced security area protection and traffic isolation function;
[0028] Preferably, in step 3, the network topology data structure is initialized in the SDN controller, including switches and hosts, monitoring change events in the network, updating and recording network topology data, and sending the detected campus network topology data to the upper-layer background application in real time through asynchronous multi-threading and realizing the storage of key data; including:
[0029] The network topology data structure initialized in the SDN controller is a dictionary, which contains the switch data structure and the host data structure;
[0030] Switches: Stores information about switches, including their data path identifiers (dpid), port lists (ports), and link lists (links);
[0031] Hosts: stores information about the host, including the host's MAC address, IPv4 / IPv6 address, connected switch (dpid), and port number;
[0032] The SDN controller dynamically updates switch and link information and learns host information through ARP and ICMPv6 messages through event processing to monitor changes in the network;
[0033] The SDN controller monitors the status change events of switches, hosts, and links in the network;
[0034] Switch events include: online, offline, port addition / removal, port status change; link events include: link establishment, disconnection, bandwidth change, delay change, error rate change; host events include: host online, host offline; install default flow table rules for the switch, and the default flow table rules upload the first packet of unknown data packets to the controller for processing;
[0035] The SDN controller monitors switch topology change events, including switch entry, exit, and link addition and deletion, detects basic switch information, including data plane identifier dpid and port number, traverses switches and links in the current network, and updates the ports, plane identifier dpid, and link information of switches dictionary data in the network topology data;
[0036] The switches in the controller is a dictionary-type data structure. After the data is obtained, it is stored in the dictionary and then sent to the upper-layer APP application of the controller through the API interface. After receiving the data, the APP application obtains the data and stores the data in the switches table of the database through ORM. The link information includes the source dpid, the destination dpid, the source port number, and the destination port number.
[0037] The SDN controller monitors user access topology change events, including capturing and processing ARP request messages (for IPv4) and ND (Neighbor Discovery) messages (for IPv6) in the network;
[0038] For the ARP request message, process the Sender Mac Address field in it to extract the MAC address of the communication initiating host, and process the Sender IP address field in the ARP request message to extract the IPv4 address and inbound port information of the communication initiating host;
[0039] For ND packets, extract the source IPv6 address, source MAC address, and inbound port information of the packet;
[0040] Scan the campus network topology data structure and update the IPv4 address, IPv6 address, data plane identifier dpid and port number in the hosts table of the database.
[0041] Preferably, according to the present invention, the background application scans the resource level to which the access control belongs in the database record table item, and creates an access flow table rule according to the resource level; including:
[0042] For basic resources, the administrator configures a list of user resources accessible to the host device of the access switch, matches the area accessible list as the basic resource, and creates two user communication flow table entry and exit rules for the basic resources;
[0043] Among them, the inbound rule communication flow table uses the host MAC address and inbound port of the table item recorded by the SDN controller to monitor and detect, fill in the source host MAC address, destination MAC address, and inbound port number of the matching item in the table item, and the action item uses the inbound port of the basic resource that the user flow authorization can access to the table item recorded by the SDN controller to monitor and detect as the traffic egress port;
[0044] The outgoing rule communication flow table is filled with the source MAC address, destination MAC address, and inbound port number of the matching item in the table. The action item uses the inbound port number of the authorized access user of the table item recorded by the SDN controller monitoring and detection as the traffic outbound port;
[0045] For important resources, the administrator configures a user resource list accessible to the host device of the access switch, matches the zone accessible list as important resources, and creates two user communication flow table entry and exit rules for important resources;
[0046] Among them, the inbound rule communication flow table uses the host MAC address and inbound port number of the table item recorded by the SDN controller to monitor and detect, fills in the source host MAC address, destination MAC address, inbound port number, and VLAN ID of the matching item in the table item, and the action item removes the VLAN tag and uses the SDN controller to monitor and detect the inbound port number of the important resource that the user flow authorization can access to the recorded table item as the traffic egress port;
[0047] The outgoing rule communication flow table is filled with the source MAC address, destination MAC address, and inbound port number of the matching item in the table entry. The action item adds an 802.1Q VLAN tag and uses the SDN controller to monitor and detect the inbound port of the authorized access user recorded in the table entry as the traffic outbound port;
[0048] For key resources, the administrator configures a list of user resources accessible to the host device of the access switch, matches the list of resources accessible to the area as key resources, and creates two user communication flow table entry and exit rules for key resources;
[0049] Among them, the inbound rule communication flow table uses the host MAC address and inbound port number of the table item recorded by the SDN controller for monitoring and detection, fills in the source host MAC address, destination MAC address, inbound port number, VLAN ID, and VNID of the matching item in the table item, and the action item removes the VLAN tag and uses the SDN controller to monitor and detect the inbound port number of the key resource that the user flow authorization can access to the recorded table item as the traffic egress port;
[0050] The outgoing rule communication flow table is filled with the source MAC address, destination MAC address, and inbound port number of the matching item in the table entry. The action item adds an 802.1Q VLAN tag, sets the VNID, and uses the SDN controller to monitor and detect the access port number of the authorized access user of the recorded table entry as the traffic outbound port.
[0051] A computer device includes a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of a campus network hierarchical multi-granularity access control method when executing the computer program.
[0052] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of a campus network hierarchical multi-granularity access control method.
[0053] A second aspect of the present invention provides a campus network hierarchical multi-granularity access control system, comprising:
[0054] The model creation module is configured to: create a Model model in the upper layer application of the SDN controller and establish a related database through ORM relationship model mapping;
[0055] The level classification module is configured as follows: the administrator classifies the resource levels of the campus network and issues access control, and classifies the resources into basic resources, important resources, and key resources according to their importance;
[0056] The monitoring module is configured to: initialize the network topology data structure in the SDN controller, monitor the change events in the network, update and record the network topology data, send the detected campus network topology data to the upper-layer background application in real time through asynchronous multi-threading, and realize the storage of key data;
[0057] The access flow table rule creation module is configured as follows: after the administrator issues access control or the SDN controller senses user access, the background application scans the resource level to which the access control belongs in the database record table item, and creates the access flow table rule according to the resource level;
[0058] The execution module is configured to: send the access rule to the SDN controller, the SDN controller creates a communication flow table and sends two flow tables to the access switch, and the access switch performs a data packet forwarding operation according to the received flow table rules.
[0059] The beneficial effects of the present invention are:
[0060] 1. Real-time network status perception: By monitoring the status changes of switches and links and user access topology events, the network topology can be updated in real time to ensure that the controller can quickly adapt to the dynamic network environment.
[0061] 2. Efficient resource management: Through the accurate recording and management of user host and network device information, including device topology, port information and user access rights, efficient resource allocation and management can be achieved.
[0062] 3. Compatible with multiple protocols: Supports the processing of ARP and ND messages, can adapt to both IPv4 and IPv6 network environments, and improves the compatibility and expansion capabilities of the network.
[0063] 4. Accurate traffic control: Utilizing topology information and user information collected in real time, combined with the ability to dynamically issue flow rules, more accurate traffic path selection and load balancing can be achieved, thereby improving network performance.
[0064] 5. Enhanced security: By extracting user access rights and network resource security levels and combining them with dynamically updated user access information, illegal access and malicious traffic can be identified and blocked in a timely manner. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] Figure 1 A schematic diagram of a three-layer model of a campus network system architecture based on SDN in the present invention;
[0066] Figure 2 This is the user information representation of the campus network of the present invention;
[0067] Figure 3 This is a schematic diagram of the network equipment information of the campus network of the present invention;
[0068] Figure 4(a) is a schematic diagram showing the multi-granularity communication flow of basic resources;
[0069] Figure 4(b) is a schematic representation of the multi-granularity communication flow of important resources;
[0070] Figure 4(c) is a schematic representation of the multi-granularity communication flow of key resources;
[0071] Figure 5 The present invention is a flow chart of a campus network hierarchical multi-granularity access control method. DETAILED DESCRIPTION
[0072] The present invention will be further described below by way of embodiments in conjunction with the accompanying drawings, but is not limited thereto.
[0073] Example 1
[0074] A hierarchical multi-granularity access control method for a campus network, such as Figure 5 As shown, including:
[0075] Step 1: Create a Model model in the upper-layer application of the SDN controller and establish a related database through ORM relationship model mapping;
[0076] Step 2: The administrator classifies the resources of the campus network and issues access control, classifying the resources into basic resources, important resources, and key resources according to their importance.
[0077] Step 3: Initialize the network topology data structure in the SDN controller, including switches and hosts, monitor the change events in the network, update and record the network topology data, send the detected campus network topology data to the upper-layer background application in real time through asynchronous multi-threading, and realize the storage of key data;
[0078] Step 4: After the administrator issues access control or the SDN controller senses user access, the background application scans the resource level to which the access control belongs in the database record table and creates access flow table rules based on the resource level;
[0079] Step 5: Send the access rules to the SDN controller. The SDN controller creates a communication flow table and sends two flow tables to the access switch. The access switch performs data packet forwarding operations according to the received flow table rules to complete network access control.
[0080] Example 2
[0081] The difference between the campus network hierarchical multi-granularity access control method described in Example 1 is that:
[0082] In step 1, a Model model is created in the upper-layer application of the SDN controller, and an associated database is established through ORM relationship model mapping; including:
[0083] The Model model includes the user host model and the network device model;
[0084] The user host model includes user ID, host IPv4 address, host IPv6 address, host MAC address, user name, user unit, user network device, user allowed access resource list, network resource security level and user access port number; network device model includes device ID, device connection topology, device type and device location;
[0085] Establish an associated database through ORM relational model mapping, and run the migration command through the Django background to automatically create a database table based on the model. The fields of the model correspond one-to-one with the fields of the database table.
[0086] In step 2, the administrator classifies the resources of the campus network and issues access control, classifying the resources into basic resources, important resources, and key resources according to their importance; including:
[0087] Administrators divide the resource levels of the campus network into basic resources, which mainly include network devices with general data, storage and computing capabilities within the campus network;
[0088] Critical resources, including network equipment with significant data, storage, and computing capabilities;
[0089] Critical resources, including network equipment with critical data, resources that have a significant impact on core business and security, storage and computing capabilities;
[0090] Then, access control is issued according to different resource levels. For basic resources, which are not very important, by specifying the source address and destination address (SD) in the flow table issued from the resource end to the access switch, end-to-end access can be restricted, blocking access to resources by users not allowed by the system, thus forming the most basic security area protection and traffic isolation function.
[0091] For important resources, in order to further protect the important resource area, VLAN is introduced on the basis of specifying the source address and destination address (SD) in the flow table to customize and assign a unique VLAN ID to each data packet, that is, basic resources and important resources are divided into independent logical networks VLAN 1 and VLAN 2, respectively, and the source address (S), destination address (D) and virtual LAN identifier (VLAN ID) are specified in the flow table sent to the access switch at the important resource end;
[0092] For key resources, the source address (S), destination address (D) and vxlan network identifier (VNID, which is also the unique identifier of the user in the campus network) are specified in the flow table sent from the resource end to the access switch. Through the matching results of the data flow and the table items, end-to-end access can be restricted, blocking the behavior of users who want to access resources without authorization. In addition, through the VNID field in the data flow, the access behavior can be located to a specific user, forming a more advanced security area protection and traffic isolation function;
[0093] In step 3, the SDN controller initializes the network topology data structure, including switches and hosts, monitors the change events in the network, updates and records the network topology data, sends the detected campus network topology data to the upper-layer background application in real time through asynchronous multi-threading, and realizes the storage of key data; including:
[0094] The network topology data structure initialized in the SDN controller is a dictionary, which contains the switch data structure and the host data structure;
[0095] Switches: Stores information about switches, including their data path identifiers (dpid), port lists (ports), and link lists (links);
[0096] Hosts: stores information about the host, including the host's MAC address, IPv4 / IPv6 address, connected switch (dpid), and port number;
[0097] The SDN controller dynamically updates switch and link information and learns host information through ARP and ICMPv6 messages through event processing to monitor changes in the network;
[0098] The SDN controller monitors the status change events of switches, hosts, and links in the network;
[0099] Switch events include: online, offline, port addition / removal, port status change; link events include: link establishment, disconnection, bandwidth change, delay change, error rate change; host events include: host online, host offline; install default flow table rules for the switch, and the default flow table rules upload the first packet of unknown data packets to the controller for processing;
[0100] The SDN controller monitors switch topology change events, including switch entry, exit, and link addition and deletion, detects basic switch information, including data plane identifier dpid and port number, traverses switches and links in the current network, and updates the ports, plane identifier dpid, and link information of switches dictionary data in the network topology data;
[0101] The switches in the controller is a dictionary-type data structure. After the data is obtained, it is stored in the dictionary and then sent to the upper-layer APP application of the controller through the API interface. After receiving the data, the APP application obtains the data and stores the data in the switches table of the database through ORM. The link information includes the source dpid, the destination dpid, the source port number, and the destination port number.
[0102] The SDN controller monitors user access topology change events, including capturing and processing ARP request messages (for IPv4) and ND (Neighbor Discovery) messages (for IPv6) in the network;
[0103] For the ARP request message, process the Sender Mac Address field in it to extract the MAC address of the communication initiating host, and process the Sender IP address field in the ARP request message to extract the IPv4 address and inbound port information of the communication initiating host;
[0104] For ND packets, extract the source IPv6 address, source MAC address, and inbound port information of the packet;
[0105] Scan the campus network topology data structure and update the IPv4 address, IPv6 address, data plane identifier dpid and port number in the hosts table of the database.
[0106] The background application scans the resource level to which the access control belongs in the database record table entry, and creates access flow table rules according to the resource level; including:
[0107] For basic resources, the administrator configures a list of user resources accessible to the host device of the access switch, matches the area accessible list as the basic resource, and creates two user communication flow table entry and exit rules for the basic resources;
[0108] Among them, the inbound rule communication flow table uses the host MAC address and inbound port of the table item recorded by the SDN controller to monitor and detect, fill in the source host MAC address, destination MAC address, and inbound port number of the matching item in the table item, and the action item uses the inbound port of the basic resource that the user flow authorization can access to the table item recorded by the SDN controller to monitor and detect as the traffic egress port;
[0109] The outgoing rule communication flow table is filled with the source MAC address, destination MAC address, and inbound port number of the matching item in the table. The action item uses the inbound port number of the authorized access user of the table item recorded by the SDN controller monitoring and detection as the traffic outbound port;
[0110] For important resources, the administrator configures a user resource list accessible to the host device of the access switch, matches the zone accessible list as important resources, and creates two user communication flow table entry and exit rules for important resources;
[0111] Among them, the inbound rule communication flow table uses the host MAC address and inbound port number of the table item recorded by the SDN controller to monitor and detect, fills in the source host MAC address, destination MAC address, inbound port number, and VLAN ID of the matching item in the table item, and the action item removes the VLAN tag and uses the SDN controller to monitor and detect the inbound port number of the important resource that the user flow authorization can access to the recorded table item as the traffic egress port;
[0112] The outgoing rule communication flow table is filled with the source MAC address, destination MAC address, and inbound port number of the matching item in the table entry. The action item adds an 802.1Q VLAN tag and uses the SDN controller to monitor and detect the inbound port of the authorized access user recorded in the table entry as the traffic outbound port;
[0113] For key resources, the administrator configures a list of user resources accessible to the host device of the access switch, matches the list of resources accessible to the area as key resources, and creates two user communication flow table entry and exit rules for key resources;
[0114] Among them, the inbound rule communication flow table uses the host MAC address and inbound port number of the table item recorded by the SDN controller for monitoring and detection, fills in the source host MAC address, destination MAC address, inbound port number, VLAN ID, and VNID of the matching item in the table item, and the action item removes the VLAN tag and uses the SDN controller to monitor and detect the inbound port number of the key resource that the user flow authorization can access to the recorded table item as the traffic egress port;
[0115] The outgoing rule communication flow table is filled with the source MAC address, destination MAC address, and inbound port number of the matching item in the table entry. The action item adds an 802.1Q VLAN tag, sets the VNID, and uses the SDN controller to monitor and detect the access port number of the authorized access user of the recorded table entry as the traffic outbound port.
[0116] Example 3
[0117] The difference between the campus network hierarchical multi-granularity access control method described in Example 1 is that:
[0118] The three-layer model diagram of the campus network system architecture based on SDN is shown in Figure 1The present invention divides the network resources in the campus network into different levels of security areas, and uses flow authorization tags (FAT) of different granularities to provide corresponding levels of security protection for different levels of areas, thereby establishing a multi-level host authentication and access control mechanism. The first level is the basic protection area, which introduces the source-destination address (SD) and controls access to basic resources in the park through the SD mapping relationship; the second level is the important protection layer, which introduces the virtual local area network identifier (Vlan ID) and uses the coarse-grained communication isolation of the virtual local area network (vlan) to access and control important resources in the park, which can solve the problem of forged source address protection that may appear in the first level of protection; the third level is the key protection area, which introduces the virtual eXtensible Local Area Network network identifier (VNID) verification and uses the finer-grained network isolation and FAT mechanism of the virtual eXtensible Local Area Network (vxlan) to block access users other than unauthorized signatures, thereby protecting key resources in the park network and solving the problem of forged identity access in the first two levels of protection. By designing a three-level protection mechanism that progresses layer by layer, it aims to achieve more secure authorized access to park network resources.
[0119] Campus Network User Information View Figure 2 As shown, they are user ID, user name, host IPv4 address, host IPv6 address, host MAC address, user access port number, user department, user class, student number, user allowed access resource list, and user VNI.
[0120] Campus network equipment information diagram Figure 3 As shown, they are device ID, device DPID, connection information, device type, Vxlan port list, and device location.
[0121] 4(a), 4(b) and 4(c) are schematic diagrams of user communication flow tables, which are respectively the basic resource communication flow table, where the matching items are the ingress port, source MAC address and destination MAC address, and the action item is the egress port of the traffic; the important resource communication flow table, where the matching items are the ingress port, source MAC address and destination MAC address, and VLAN ID, and the action item is setting the VLAN tag and the egress port of the traffic; and the key resource communication flow table, where the matching items are the ingress port, source MAC address and destination MAC address, VLAN ID and VNID, and the action item is setting the VLAN tag, setting the VNID, and the egress port of the traffic.
[0122] A flow chart of a hierarchical multi-granularity access control method for a campus network is shown in Figure 5 , the steps are as follows:
[0123] S100: Create a Model model in the upper-layer application of the SDN controller and establish a related database through ORM relationship model mapping;
[0124] S200: The administrator can classify the resources of the campus network and issue access control policies. These policies will be issued to the controller system as the basis for network access management.
[0125] S300: Initialize the network topology data structure in the SDN controller, monitor the state change events of the switches and host links in the network, and dynamically update the network information;
[0126] S400: The SDN controller system establishes network topology data based on the network detection performed by S300 and sends it to the campus network hierarchical multi-granularity access system through the API to update the table information of the database to realize the storage of key data;
[0127] S500: The administrator issues access control or the SDN controller senses the user access and triggers the creation of access flow table rules through interaction with the upper layer application;
[0128] S600: Determine the resource level of authorized access according to the interactive information of S500. Basic resources execute S601, important resources execute S602, and key resources execute S603;
[0129] S601: For basic resources, two basic SD ingress and egress flow table rules are created, which are applicable to low-sensitivity data access;
[0130] S602: For important resources, two SD ingress and egress flow table rules with dynamically generated VLAN IDs are created to ensure resource isolation;
[0131] S603: For key resources, two SD ingress and egress flow table rules are created that combine dynamic VLAN ID and VNI ID to form a more advanced security zone protection and traffic isolation function;
[0132] S700: The campus network hierarchical multi-granularity access system sends the communication flow table rules of S601, S602, or S603 to the SDN controller through the API;
[0133] S800: The SDN controller creates a communication flow table and sends two flow tables to the access switch;
[0134] S900: The access switch performs a data packet forwarding operation according to the received flow table rule to complete network access control;
[0135] Example 4
[0136] A computer device includes a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps of the campus network hierarchical multi-granularity access control method described in any one of Examples 1-3 are implemented.
[0137] Example 5
[0138] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the campus network hierarchical multi-granularity access control method described in any one of Examples 1-3.
[0139] Example 6
[0140] A campus network hierarchical multi-granularity access control system, comprising:
[0141] The model creation module is configured to: create a Model model in the upper layer application of the SDN controller and establish a related database through ORM relationship model mapping;
[0142] The level classification module is configured as follows: the administrator classifies the resource levels of the campus network and issues access control, and classifies the resources into basic resources, important resources, and key resources according to their importance;
[0143] The monitoring module is configured to: initialize the network topology data structure in the SDN controller, monitor the change events in the network, update and record the network topology data, send the detected campus network topology data to the upper-layer background application in real time through asynchronous multi-threading, and realize the storage of key data;
[0144] The access flow table rule creation module is configured as follows: after the administrator issues access control or the SDN controller senses user access, the background application scans the resource level to which the access control belongs in the database record table item, and creates the access flow table rule according to the resource level;
[0145] The execution module is configured to: send the access rule to the SDN controller, the SDN controller creates a communication flow table and sends two flow tables to the access switch, and the access switch performs a data packet forwarding operation according to the received flow table rules.
Claims
1. A campus network hierarchical multi-granularity access control method, characterized in that: include: Step 1: Create a Model model in the upper-layer application of the SDN controller and establish a related database through ORM relationship model mapping; Step 2: The administrator classifies the resources of the campus network and issues access control, classifying the resources into basic resources, important resources, and key resources according to their importance. Step 3: Initialize the network topology data structure in the SDN controller, monitor the change events in the network, update and record the network topology data, send the detected campus network topology data to the upper-layer background application in real time through asynchronous multi-threading, and realize the storage of key data; Step 4: After the administrator issues access control or the SDN controller senses user access, the background application scans the resource level to which the access control belongs in the database record table and creates access flow table rules based on the resource level; Step 5: Send the access rules to the SDN controller. The SDN controller creates a communication flow table and sends two flow tables to the access switch. The access switch performs data packet forwarding operations according to the received flow table rules.
2. A campus network hierarchical multi-granularity access control method according to claim 1, characterized in that: In step 1, a Model model is created in the upper-layer application of the SDN controller, and an associated database is established through ORM relationship model mapping; including: The Model model includes the user host model and the network device model; The user host model includes user ID, host IPv4 address, host IPv6 address, host MAC address, user name, user unit, user network device, user allowed access resource list, network resource security level and user access port number; network device model includes device ID, device connection topology, device type and device location; Establish an associated database through ORM relational model mapping, and run the migration command through the Django background to automatically create a database table based on the model. The fields of the model correspond one-to-one with the fields of the database table.
3. A campus network hierarchical multi-granularity access control method according to claim 1, characterized in that: In step 2, the administrator classifies the resources of the campus network and issues access control, classifying the resources into basic resources, important resources, and key resources according to their importance. include: Administrators divide the resource levels of the campus network into basic resources, which mainly include network devices with general data, storage and computing capabilities within the campus network; Critical resources, including network equipment with significant data, storage, and computing capabilities; Critical resources, including network equipment with critical data, resources that have a significant impact on core business and security, storage and computing capabilities; Then, access control is issued according to different resource levels. For basic resources, the source address and destination address are specified in the flow table issued by the resource end to the access switch; For important resources, VLAN is introduced on the basis of specifying the source address and destination address in the flow table to customize the unique VLAN ID for each data packet, that is, basic resources and important resources are divided into independent logical networks VLAN 1 and VLAN 2, and the source address, destination address and virtual LAN ID are specified in the flow table sent to the access switch at the important resource end; For key resources, specify the source address, destination address, and vxlan network identifier in the flow table sent to the access switch from the resource end.
4. A campus network hierarchical multi-granularity access control method according to claim 2, characterized in that: In step 3, the SDN controller initializes the network topology data structure, monitors the change events in the network, updates and records the network topology data, sends the detected campus network topology data to the upper-layer background application in real time through asynchronous multi-threading, and realizes the storage of key data; including: The network topology data structure initialized in the SDN controller is a dictionary, which contains the switch data structure and the host data structure; Switch: Stores information about the switch, including its data path identifier, port list, and link list; Host: stores information about the host, including the host's MAC address, IPv4 / IPv6 address, connected switch, and port number; The SDN controller dynamically updates switch and link information and learns host information through ARP and ICMPv6 messages through event processing to monitor changes in the network; The SDN controller monitors the status change events of switches, hosts, and links in the network; Switch events include: online, offline, port addition / removal, port status change; link events include: link establishment, disconnection, bandwidth change, delay change, error rate change; host events include: host online, host offline; install default flow table rules for the switch, and the default flow table rules upload the first packet of unknown data packets to the controller for processing; The SDN controller monitors switch topology change events, including switch entry, exit, and link addition and deletion, detects basic switch information, including data plane identifier dpid and port number, traverses switches and links in the current network, and updates the ports, plane identifier dpid, and link information of switches dictionary data in the network topology data; The switches in the controller is a dictionary-type data structure. After the data is obtained, it is stored in the dictionary and then sent to the upper-layer APP application of the controller through the API interface. After receiving the data, the APP application obtains the data and stores the data in the switches table of the database through ORM. The link information includes the source dpid, the destination dpid, the source port number, and the destination port number. The SDN controller monitors user access topology change events, including capturing and processing ARP request packets and ND packets in the network; For the ARP request message, process the Sender Mac Address field in it to extract the MAC address of the communication initiating host, and process the Sender IP address field in the ARP request message to extract the IPv4 address and inbound port information of the communication initiating host; For ND packets, extract the source IPv6 address, source MAC address, and inbound port information of the packet; Scan the campus network topology data structure and update the IPv4 address, IPv6 address, data plane identifier dpid and port number in the hosts table of the database.
5. A campus network hierarchical multi-granularity access control method according to claim 4, characterized in that: The background application scans the resource level to which the access control belongs in the database record table entry, and creates access flow table rules according to the resource level; including: For basic resources, the administrator configures a list of user resources accessible to the host device of the access switch, matches the area accessible list as the basic resource, and creates two user communication flow table entry and exit rules for the basic resources; Among them, the inbound rule communication flow table uses the host MAC address and inbound port of the table item recorded by the SDN controller to monitor and detect, fill in the source host MAC address, destination MAC address, and inbound port number of the matching item in the table item, and the action item uses the inbound port of the basic resource that the user flow authorization can access to the table item recorded by the SDN controller to monitor and detect as the traffic egress port; The outgoing rule communication flow table is filled with the source MAC address, destination MAC address, and inbound port number of the matching item in the table. The action item uses the inbound port number of the authorized access user of the table item recorded by the SDN controller monitoring and detection as the traffic outbound port; For important resources, the administrator configures a user resource list accessible to the host device of the access switch, matches the zone accessible list as important resources, and creates two user communication flow table entry and exit rules for important resources; Among them, the inbound rule communication flow table uses the host MAC address and inbound port number of the table item recorded by the SDN controller to monitor and detect, fills in the source host MAC address, destination MAC address, inbound port number, and VLAN ID of the matching item in the table item, and the action item removes the VLAN tag and uses the SDN controller to monitor and detect the inbound port number of the important resource that the user flow authorization can access to the recorded table item as the traffic egress port; The outgoing rule communication flow table is filled with the source MAC address, destination MAC address, and inbound port number of the matching item in the table entry. The action item adds an 802.1Q VLAN tag and uses the SDN controller to monitor and detect the inbound port of the authorized access user recorded in the table entry as the traffic outbound port; For key resources, the administrator configures a list of user resources accessible to the host device of the access switch, matches the list of resources accessible to the area as key resources, and creates two user communication flow table entry and exit rules for key resources; Among them, the inbound rule communication flow table uses the host MAC address and inbound port number of the table item recorded by the SDN controller for monitoring and detection, fills in the source host MAC address, destination MAC address, inbound port number, VLAN ID, and VNID of the matching item in the table item, and the action item removes the VLAN tag and uses the SDN controller to monitor and detect the inbound port number of the key resource that the user flow authorization can access to the recorded table item as the traffic egress port; The outgoing rule communication flow table is filled with the source MAC address, destination MAC address, and inbound port number of the matching item in the table entry. The action item adds an 802.1Q VLAN tag, sets the VNID, and uses the SDN controller to monitor and detect the access port number of the authorized access user of the recorded table entry as the traffic outbound port.
6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the campus network hierarchical multi-granularity access control method described in any one of claims 1-5 are implemented.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the campus network hierarchical multi-granularity access control method described in any one of claims 1-5 are implemented.
8. A campus network hierarchical multi-granularity access control system, characterized in that: include: The model creation module is configured to: create a Model model in the upper layer application of the SDN controller and establish a related database through ORM relationship model mapping; The level classification module is configured as follows: the administrator classifies the resource levels of the campus network and issues access control, and classifies the resources into basic resources, important resources, and key resources according to their importance; The monitoring module is configured to: initialize the network topology data structure in the SDN controller, monitor the change events in the network, update and record the network topology data, send the detected campus network topology data to the upper-layer background application in real time through asynchronous multi-threading, and realize the storage of key data; The access flow table rule creation module is configured as follows: after the administrator issues access control or the SDN controller senses user access, the background application scans the resource level to which the access control belongs in the database record table item, and creates the access flow table rule according to the resource level; The execution module is configured to: send the access rule to the SDN controller, the SDN controller creates a communication flow table and sends two flow tables to the access switch, and the access switch performs a data packet forwarding operation according to the received flow table rules.