Network access control method and system
By introducing access credentials and digital signature verification mechanisms into the VPN system, the problem of not being able to access the intranet and the Internet at the same time after the VPN is turned on is solved, and flexible network access management and enhanced network security are achieved.
Patent Information
- Application Number
- CN202510157532.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-12
- Publication Date
- 2025-05-16
AI Technical Summary
After using a VPN, you cannot access intranet resources and Internet services at the same time, resulting in limited network access.
By sending a request message to the credential issuing system to apply for access credentials, the credentials include user ID, permission ID and digital signature, starting the VPN client and sending a network access request to the VPN server, the VPN server uses the public key of the credential issuing system to verify the digital signature and open the corresponding network access channel.
It realizes that when the VPN is turned on, users can access intranet resources and Internet services at the same time, meeting the flexible access needs of different users for internal and external network resources, and at the same time enhancing network security.
Smart Images

Figure CN120017360A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of network security, and in particular to a network access control method and system. Background Art
[0002] In the modern corporate office environment, network security and data protection are critical considerations. In order to achieve strict separation between the office intranet and the Internet and ensure the security of sensitive information, many organizations have adopted specific technical solutions to manage network access rights. This solution only allows employees to access Internet applications without opening a virtual private network (VPN), ensuring that external resources required for daily office work can be obtained; after opening a designated VPN, users are restricted to accessing only the company's internal network resources, thus forming an isolation mechanism that effectively prevents potential network security threats. Although this method improves security, it also brings inconveniences. For example, when it is necessary to use intranet resources and Internet services at the same time for communication, obstacles may be encountered because the relevant content of the office intranet system cannot be directly accessed under this setting.
[0003] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention
[0004] The present disclosure provides a network access control method and system, which at least to some extent overcomes the problem in the related art that after using VPN, intranet resources and Internet services cannot be used simultaneously.
[0005] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.
[0006] According to one aspect of the present disclosure, a network access control method is provided, which is applied to a terminal, and the method includes:
[0007] Sending a first request message to a credential issuing system, where the first request message is used to apply for an access credential and carries a user identifier;
[0008] Receiving an access credential issued by a credential issuing system for a user corresponding to the user ID, the access credential including the user ID, the authority ID, and the digital signature;
[0009] Start the VPN client and send a network access request to the VPN server. The network access request carries the access credential so that the VPN server can verify the digital signature using the public key of the credential issuance system and, if the verification is successful, open the network access channel corresponding to the permission identifier.
[0010] In one embodiment of the present disclosure, the access credential is one of an intranet credential, an extranet credential or a comprehensive credential. The intranet credential only has the authority to access the internal network, the extranet credential only has the authority to access the external network, and the intranet credential has the authority to access both the internal and external networks.
[0011] In one embodiment of the present disclosure, the access credential further includes a validity period, which records the time interval during which the user credential can be normally used.
[0012] In one embodiment of the present disclosure, the validity period is determined according to one or more of the contract period of the user corresponding to the user identification, the project cycle, or the security policy of the enterprise.
[0013] In one embodiment of the present disclosure, the digital signature is obtained by signing the target information in the access credential using the private key of the credential issuing system through a public key cryptographic algorithm, wherein the target information is the information in the access credential other than the digital signature.
[0014] According to another aspect of the present disclosure, a network access control method is provided, which is applied to a VPN server, and the method includes:
[0015] Receive and store the mapping relationship between the permission identifier and the permission, and the permission is associated with the network access channel;
[0016] Store the public key of the credential issuance system;
[0017] The receiving terminal sends a network access request after starting the VPN client. The network access request carries an access credential, which includes a user ID, an authority ID, and a digital signature.
[0018] Use the public key of the certificate issuing system to verify the digital signature;
[0019] If the verification is successful, the network access channel corresponding to the permission identifier is opened;
[0020] The access credential is issued by the credential issuing system to the user corresponding to the user ID.
[0021] In one embodiment of the present disclosure, the digital signature is verified using the public key of the certificate issuing system, including:
[0022] Decrypt the digital signature using the public key cryptographic algorithm and the public key of the certificate issuance system to obtain the decrypted information;
[0023] Compare the decrypted information with the information in the access credential except the digital signature to see if they are the same;
[0024] If they are the same, the verification passes.
[0025] According to another aspect of the present disclosure, a network access control method is provided, which is applied to a credential issuance system, and the method includes:
[0026] The mapping relationship between the permission identifier and the permission is sent to the VPN server, and the permission is associated with the network access channel;
[0027] Send the public key to the VPN server;
[0028] Receiving a first request message sent by a terminal, where the first request message is used to apply for an access credential and carries a user identifier;
[0029] Issue access credentials to the user corresponding to the user ID;
[0030] The access credential is sent to the terminal. The access credential contains the user ID, permission ID, and digital signature, so that the terminal can send a network access request to the VPN server after starting the VPN client. The network access request carries the access credential. The VPN server verifies the digital signature using the public key of the credential issuance system and opens the network access channel corresponding to the permission ID if the verification passes.
[0031] In one embodiment of the present disclosure, the access credential further includes a validity period, which records the time interval during which the user credential can be normally used.
[0032] In one embodiment of the present disclosure, issuing an access credential to a user corresponding to the user identification includes:
[0033] Based on the user ID, determine the permission ID and validity period;
[0034] Through the public key cryptographic algorithm, the private key of the credential issuance system is used to sign the user ID, authority ID and validity period to obtain a digital signature;
[0035] Based on the user ID, permission ID, validity period and digital signature, access credentials are obtained.
[0036] According to another aspect of the present disclosure, there is provided a network access control system, comprising:
[0037] The credential issuance system is used to send the mapping relationship between the permission identifier and the permission to the VPN server, associate the permission with the network access channel, and send the public key to the VPN server;
[0038] The terminal is used to send a first request message to the credential issuing system, where the first request message is used to apply for an access credential and carries a user identifier;
[0039] The credential issuance system is also used to issue access credentials to the user corresponding to the user ID, and send the access credentials to the terminal. The access credentials include the user ID, the authority ID, and the digital signature;
[0040] The terminal is also used to start the VPN client and send a network access request to the VPN server, and the network access request carries the access credential;
[0041] The VPN server also uses the public key of the certificate issuance system to verify the digital signature, and if the verification passes, it opens the network access channel corresponding to the permission identifier.
[0042] According to another aspect of the present disclosure, an electronic device is provided, including: a memory for storing instructions; and a processor for calling the instructions stored in the memory to implement the above-mentioned network access control method.
[0043] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which computer instructions are stored. When the computer instructions are executed by a processor, the above-mentioned network access control method is implemented.
[0044] According to another aspect of the present disclosure, a computer program product is provided. The computer program product stores instructions, and when the instructions are executed by a computer, the computer implements the above-mentioned network access control method.
[0045] According to yet another aspect of the present disclosure, there is provided a chip, comprising at least one processor and an interface;
[0046] An interface for providing program instructions or data to at least one processor;
[0047] At least one processor is used to execute program instructions to implement the above network access control method.
[0048] The network access control method and system provided by the embodiment of the present disclosure, when the terminal attempts to access the network through the VPN client, it will send a network access request to the VPN server with the access credential. Subsequently, the VPN server uses the public key of the credential issuance system to verify the digital signature. This method uses asymmetric encryption technology to ensure that only authorized credentials can pass the verification, further strengthening the security protection measures; once the digital signature verification is successful, the VPN server will open the corresponding network access channel according to the permission identifier in the access credential. This method allows enterprises to flexibly set the access rights of different users according to actual needs, which can not only protect sensitive resources from unauthorized access, but also meet the different access requirements of employees to internal and external network resources. For example, some employees can be allowed to access the internal network and the external network at the same time; the embodiment of the present disclosure not only improves information security and reduces potential risks, but also supports the differentiated network access requirements between different departments within the enterprise.
[0049] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.
[0051] Obviously, the drawings described below are only some embodiments of the present disclosure, and a person skilled in the art can obtain other drawings based on these drawings without any creative work.
[0052] Figure 1 A schematic diagram of a network architecture in related technology is shown;
[0053] Figure 2 A schematic diagram of the architecture of a network access control system in an embodiment of the present disclosure is shown;
[0054] Figure 3 A flow chart of a network access control method in an embodiment of the present disclosure is shown;
[0055] Figure 4 Another flow chart of a network access control method in an embodiment of the present disclosure is shown;
[0056] Figure 5 A flowchart of another network access control method in an embodiment of the present disclosure is shown;
[0057] Figure 6 A flow chart of another network access control method in an embodiment of the present disclosure is shown;
[0058] Figure 7Another flow chart of a network access control method in an embodiment of the present disclosure is shown;
[0059] Figure 8 A flowchart of another network access control method in an embodiment of the present disclosure is shown;
[0060] Fig. 9 A flow chart of another network access control method in an embodiment of the present disclosure is shown;
[0061] Fig.10 Another flow chart of a network access control method in an embodiment of the present disclosure is shown;
[0062] Fig.11 A schematic diagram of a terminal in an embodiment of the present disclosure is shown;
[0063] Fig.12 A schematic diagram of a VPN server in an embodiment of the present disclosure is shown;
[0064] Fig.13 A schematic diagram of a credential issuance system in an embodiment of the present disclosure is shown;
[0065] Fig.14 A structural block diagram of an electronic device in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0066] In order to make the purpose, technical scheme and advantages of the embodiments of the present disclosure clearer, the technical scheme in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, rather than all of the embodiments. The components of the embodiments of the present disclosure generally described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present disclosure provided in the drawings is not intended to limit the scope of the present disclosure for protection, but merely represents the selected embodiments of the present disclosure. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present disclosure.
[0067] Figure 1 A schematic diagram of a network architecture is shown, such as Figure 1 In the scenario shown, when VPN is not enabled, the terminal can only access Internet applications, but not internal applications; after VPN is enabled, it can only access internal applications, that is, access to designated intranet resources, but cannot access the Internet at the same time. Internal applications refer to office intranets, such as the network of internal company systems such as office OA; Internet applications refer to external networks, that is, networks of the public Internet.
[0068] Figure 2 A network access control system according to an embodiment of the present disclosure is shown. Figure 2 As shown, the network access control system includes a terminal, a certificate issuing system and a VPN server, wherein a VPN client is provided in the terminal. The certificate issuing system is used for certificate issuance and certificate management; the VPN server is used for certificate verification and authority allocation.
[0069] The credential issuance system is used to send the mapping relationship between the permission identifier and the permission to the VPN server, associate the permission with the network access channel, and send the public key to the VPN server;
[0070] The terminal is used to send a first request message to the credential issuing system, where the first request message is used to apply for an access credential and carries a user identifier;
[0071] The credential issuance system is also used to issue access credentials to the user corresponding to the user ID, and send the access credentials to the terminal. The access credentials include the user ID, the authority ID, and the digital signature;
[0072] The terminal is also used to start the VPN client and send a network access request to the VPN server, and the network access request carries the access credential;
[0073] The VPN server also uses the public key of the certificate issuance system to verify the digital signature, and if the verification passes, it opens the network access channel corresponding to the permission identifier.
[0074] In some embodiments, the access credential also includes a validity period, that is, the access credential consists of four parts: user identification, authority identification, validity period, and digital signature.
[0075] User ID: used to uniquely identify a user, such as an employee's email address, employee number, etc.
[0076] Permission ID: Specifies the scope of network access permissions corresponding to the user credentials.
[0077] Validity period: sets the time period during which user credentials can be used normally. It can be updated and adjusted regularly according to the employee's contract period, project cycle or corporate security policy.
[0078] A digital signature is a signature that uses the private key of the credential issuer to sign the other parts of the access credential (user ID || authority ID || validity period) through a public key cryptographic algorithm.
[0079] In some embodiments, the terminal may be an employee terminal, such as a computer, a smart tablet, a smart phone, or other terminal device that can be configured with the VPN client. Different employees have different permissions, and thus have different corresponding permission identifiers and can access different network applications.
[0080] Figure 3Shows a method based on Figure 2 The network access control method flow of the network access control system, such as Figure 3 The certificate issuing system shown sends the mapping relationship between the permission identifier and the permission to the VPN server, associates the permission with the network access channel, and sends the public key to the VPN server; after receiving a request message sent by the terminal, the certificate issuing system issues an access credential to the user corresponding to the user identifier, and sends the access credential to the terminal. The access credential includes the user identifier, the permission identifier, and the digital signature.
[0081] The terminal starts the VPN client and sends a network access request to the VPN server, which carries the access credential. The VPN server verifies the digital signature using the public key of the credential issuance system and, if the verification is successful, opens the network access channel corresponding to the permission identifier.
[0082] In some embodiments, different employees have different permissions for their access credentials. The access credentials may include intranet credentials, extranet credentials, and combined credentials. Intranet credentials only have permissions to access the internal network, extranet credentials only have permissions to access the external network, and intranet credentials have permissions to access both the internal and external networks.
[0083] The network access control system provided by the embodiment of the present disclosure introduces multiple access credentials based on the traditional VPN client and server architecture. Each credential corresponds to different network access rights: intranet credentials are limited to accessing corporate intranet resources, extranet credentials are limited to accessing the public Internet, and comprehensive credentials can access both intranet and extranet resources. Corresponding network access credentials are allocated according to employees' job requirements to ensure that they can only access necessary resources.
[0084] When logging in, employees select appropriate access credentials through the VPN client. The VPN server verifies the selected credentials and opens corresponding network access rights based on the verification results.
[0085] The access credential contains the user ID, permission ID, validity period and digital signature. The authenticity, integrity and validity of the access credential are guaranteed by digital signature technology. This solution not only enhances network security, but also simplifies the user's operation process and ensures the accuracy and flexibility of access control.
[0086] Figure 4 A flow chart of a network access control method in an embodiment of the present disclosure is shown as follows: Figure 4 As shown, the network access control method provided in the embodiment of the present disclosure includes S401-S405.
[0087] In S401, the terminal sends a first request message to the credential issuing system, where the first request message is used to apply for an access credential and carries a user identifier.
[0088] In S402, the credential issuing system issues an access credential to the user corresponding to the user identifier, and sends the access credential to the terminal.
[0089] In some embodiments, the access credential is one of an intranet credential, an extranet credential, or a combined credential. The intranet credential only has permission to access the internal network, the extranet credential only has permission to access the external network, and the intranet credential has permission to access both the internal and external networks.
[0090] In some embodiments, the access credentials include a user identification, an authority identification, and a digital signature.
[0091] In some embodiments, the access credential may further include a validity period, which records the time interval during which the user credential can be normally used.
[0092] In some embodiments, the validity period is determined based on one or more of a contract period, a project cycle, or a security policy of an enterprise of the user corresponding to the user identification.
[0093] In some embodiments, the digital signature is obtained by signing the target information in the access credential using the private key of the credential issuing system through a public key cryptographic algorithm, wherein the target information is the information in the access credential other than the digital signature.
[0094] In S403, the terminal starts the VPN client and sends a network access request to the VPN server, where the network access request carries the access credential.
[0095] In S404, the VPN server verifies the digital signature using the public key of the certificate issuing system.
[0096] In some embodiments, the digital signature is verified using the public key of the credential issuing system. The digital signature can be decrypted using a public key cryptographic algorithm and the public key of the credential issuing system to obtain decrypted information; the decrypted information is compared with the information in the access credential except the digital signature to see if they are the same; if they are the same, the verification is successful.
[0097] In some embodiments, when the access credential includes a user identifier, an authority identifier, and a digital signature, comparing the decrypted information with the information in the access credential other than the digital signature to see whether they are the same may be comparing the user identifier and the authority identifier in the decrypted information with the user identifier and the authority identifier in the access credential to see whether they are the same. When the access credential includes a user identifier, an authority identifier, a validity period, and a digital signature, comparing the decrypted information with the information in the access credential other than the digital signature to see whether they are the same may be comparing the user identifier, the authority identifier, the validity period in the decrypted information with the user identifier, the authority identifier, the validity period in the access credential to see whether they are the same.
[0098] In S405, when the verification is successful, the VPN server opens a network access channel corresponding to the authority identifier.
[0099] In some embodiments, different permission identifiers may correspond to different access credential types, such as intranet credentials, extranet credentials, or comprehensive credentials. In some embodiments, the permission identifiers of the same type of access credentials may also be different, for example, they are all intranet credentials, but different employees may have access to different intranet applications, and thus different permission identifiers.
[0100] Figure 5 A flow chart of a network access control method in an embodiment of the present disclosure is shown as follows: Figure 5 As shown, the network access control method provided in the embodiment of the present disclosure includes S501-S507, wherein S503-S507 are the same as S401-S405 and will not be described in detail here.
[0101] Applied to VPN servers, the methods include:
[0102] In S501, the credential issuing system sends the mapping relationship between the permission identifier and the permission to the VPN server, and the permission is associated with the network access channel;
[0103] In S502, the certificate issuing system sends the public key to the VPN server.
[0104] The VPN server can use the mapping relationship between the permission identifier and the permission to determine the permissions of different users, and then open the network access channel corresponding to the permission identifier.
[0105] The VPN server can use the above public key to verify the digital signature.
[0106] Figure 6 A flow chart of a network access control method in an embodiment of the present disclosure is shown as follows: Figure 6 As shown, the network access control method provided in the embodiment of the present disclosure includes S601-S608. Figure 5 In the embodiment, before the credential issuance system issues an access credential to the user corresponding to the user identifier and sends the access credential to the terminal at S605, the credential issuance system verifies the first request message at S604. S605 is to issue an access credential to the user corresponding to the user identifier and send the access credential to the terminal if the first request message is verified.
[0107] In some embodiments, the S604 credential issuance system verifies the first request message by verifying the authenticity and integrity of the first request message, and its principle is similar to the verification process of the digital signature of the network access credential in the previous embodiment. The first request message may include a user identifier and a second digital signature, and the second digital signature may be obtained by signing the user identifier using the private key of the terminal. The credential issuance system verifies the first request message by decrypting the second digital signature using the public key of the terminal, obtaining the second decrypted information, and then comparing whether the second decrypted information is the same as the user identifier.
[0108] In some embodiments, an access credential is issued to a user corresponding to a user identifier. The authority identifier and validity period can be determined based on the user identifier; the user identifier, authority identifier and validity period are signed using a public key cryptographic algorithm using a private key of the credential issuing system to obtain a digital signature; and the access credential is obtained based on the user identifier, authority identifier, validity period and digital signature.
[0109] Figure 7 A flow chart of a network access control method in an embodiment of the present disclosure is shown as follows: Figure 4 As shown, the network access control method provided in the embodiment of the present disclosure includes S701-S711. In this embodiment, the access credential also includes a validity period, which records the time interval during which the user credential can be used normally. Compared with the previous embodiment, in this embodiment, the credential system also executes S704-S707 after receiving the first request message.
[0110] In S704, the first request message is verified;
[0111] In S705, based on the user identifier, the authority identifier and validity period are determined;
[0112] In S706, the user identification, authority identification and validity period are signed using the private key of the certificate issuance system through a public key cryptographic algorithm to obtain a digital signature;
[0113] In S707, an access credential is obtained based on the user identification, authority identification, validity period and digital signature.
[0114] In the disclosed embodiment, the credential issuance system is responsible for defining and allocating permissions and notifying the VPN server of these permission rules. The credential issuance system can pre-import the identity information and permission range of employees.
[0115] Public key pre-setting: The VPN server is pre-configured with the public key of the identity credential issuance system for subsequent identity credential verification.
[0116] Request for credentials: Employees apply for specific access credentials through the identity credential issuance system. The system verifies the authenticity and completeness of the request and determines whether the request is reasonable based on the pre-imported employee identity and scope of authority. If the request meets the requirements, the system will issue the credential; otherwise, it will refuse to issue it.
[0117] Access network resources: When employees need to access network resources, they open the VPN client, select the corresponding identity credentials and initiate an access request.
[0118] Verification and authorization: After receiving the request, the VPN server uses the public key of the identity certificate issuance system to verify the certificate. After the verification is passed, the permission identifier in the certificate is extracted and the corresponding network access channel is opened according to the permission.
[0119] Most VPN-based network access solutions tend to use a relatively single form of authentication credentials, such as relying only on a username and password combination to verify the user's identity and decide whether to grant network access rights. Even if there are multiple authentication methods, they are basically enhanced authentication under the same permission scope, without subdividing the credential types for different network ranges (such as intranet and extranet) and corresponding to different permissions.
[0120] The existing VPN-based internal and external network switching solution adopts a unified identity authentication mechanism. Once the user logs in successfully, he can only obtain the preset network access rights. In the embodiment of the present disclosure, multiple identity credentials are introduced into the traditional VPN architecture, and each credential corresponds to different access rights. Employees obtain corresponding credentials according to job requirements to ensure that they can only access necessary resources.
[0121] Figure 8 A network access control method executed by a terminal in an embodiment of the present disclosure is shown. Figure 8 As shown, the network access control method provided in the embodiment of the present disclosure includes S801-S803.
[0122] In S801, a first request message is sent to a credential issuing system, the first request message is used to apply for an access credential, and the first request message carries a user identifier;
[0123] In S802, an access credential issued by a credential issuing system for a user corresponding to the user ID is received, where the access credential includes the user ID, the authority ID, and the digital signature;
[0124] In S803, the VPN client is started and a network access request is sent to the VPN server. The network access request carries the access credential so that the VPN server verifies the digital signature using the public key of the credential issuance system and opens the network access channel corresponding to the authority identifier if the verification passes.
[0125] Fig. 9 A network access control method performed by a VPN server in an embodiment of the present disclosure is shown. Fig. 9 As shown, the network access control method provided in the embodiment of the present disclosure includes S901-S905.
[0126] In S901, a mapping relationship between a permission identifier and a permission is received and stored, and the permission is associated with a network access channel;
[0127] In S902, the public key of the certificate issuing system is stored;
[0128] In S903, a network access request sent by a terminal after starting a VPN client is received, the network access request carries an access credential, and the access credential includes a user identifier, an authority identifier, and a digital signature;
[0129] In S904, the digital signature is verified using the public key of the certificate issuing system;
[0130] In S905, if the verification is successful, the network access channel corresponding to the authority identifier is opened;
[0131] The access credential is issued by the credential issuing system to the user corresponding to the user ID.
[0132] Fig.10 A network access control method performed by a credential issuance system in an embodiment of the present disclosure is shown. Fig.10 As shown, the network access control method provided in the embodiment of the present disclosure includes S1001-S1005.
[0133] In S1001, the mapping relationship between the permission identifier and the permission is sent to the VPN server, and the permission is associated with the network access channel;
[0134] In S1002, the public key is sent to the VPN server;
[0135] In S1003, a first request message sent by a terminal is received, where the first request message is used to apply for an access credential and carries a user identifier;
[0136] In S1004, an access credential is issued to the user corresponding to the user identifier;
[0137] In S1005, the access credential is sent to the terminal. The access credential includes a user ID, an authority ID, and a digital signature, so that the terminal starts the VPN client and sends a network access request to the VPN server. The network access request carries the access credential. The VPN server uses the public key of the credential issuance system to verify the digital signature and opens the network access channel corresponding to the authority ID if the verification passes.
[0138] In the embodiments of the present disclosure, the terms “first”, “second” and “third” are used for descriptive purposes only and should not be understood as indicating or implying relative importance.
[0139] The term "and / or" in this disclosure is only a description of the association relationship of associated objects, indicating that there may be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0140] Furthermore, although the steps of the method in the present disclosure are described in a particular order in the drawings, this does not require or imply that the steps must be performed in this particular order or that all the steps shown must be performed to achieve the desired results.
[0141] In some embodiments, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.
[0142] Based on the same inventive concept, the present disclosure also provides a terminal, such as Fig.11 As shown, the terminal includes a first request module 1101 , a credential receiving module 1102 and a second request module 1103 .
[0143] A first request module 1101 is used to send a first request message to a credential issuing system, where the first request message is used to apply for an access credential and carries a user identifier;
[0144] The credential receiving module 1102 is used to receive the access credential issued by the credential issuing system for the user corresponding to the user ID, and the access credential includes the user ID, the authority ID, and the digital signature;
[0145] The second request module 1103 is used to start the VPN client and send a network access request to the VPN server. The network access request carries the access credential so that the VPN server can verify the digital signature using the public key of the credential issuance system, and open the network access channel corresponding to the authority identifier if the verification passes.
[0146] Based on the same inventive concept, the present disclosure also provides a VPN server, such as Fig.12 As shown, the VPN server includes an authority receiving module 1201 , a public key receiving module 1202 , a first receiving module 1203 , a signature verification module 1204 and a channel control module 1205 .
[0147] The permission receiving module 1201 is used to receive and store the mapping relationship between the permission identifier and the permission, and the permission is associated with the network access channel;
[0148] The public key receiving module 1202 is used to store the public key of the certificate issuing system;
[0149] The first receiving module 1203 is used to receive a network access request sent by the terminal after starting the VPN client. The network access request carries an access credential, and the access credential includes a user identifier, an authority identifier, and a digital signature.
[0150] The signature verification module 1204 is used to verify the digital signature using the public key of the certificate issuance system;
[0151] The channel control module 1205 is used to open the network access channel corresponding to the authority identifier when the verification is passed.
[0152] The access credential is issued by the credential issuing system to the user corresponding to the user ID.
[0153] Based on the same inventive concept, the present disclosure also provides a credential issuance system, such as Fig.13 As shown, the certificate issuing system includes an authority sending module 1301 , a public key sending module 1302 , a second receiving module 1303 , a certificate issuing module 1304 and a certificate sending module 1305 .
[0154] The permission sending module 1301 is used to send the mapping relationship between the permission identifier and the permission to the VPN server, and the permission is associated with the network access channel;
[0155] A public key sending module 1302, used to send the public key to the VPN server;
[0156] The second receiving module 1303 is used to receive a first request message sent by the terminal, where the first request message is used to apply for an access credential and carries a user identifier;
[0157] The credential issuing module 1304 is used to issue an access credential to the user corresponding to the user identifier;
[0158] The credential sending module 1305 is used to send the access credential to the terminal. The access credential includes a user ID, an authority ID, and a digital signature, so that the terminal can send a network access request to the VPN server after starting the VPN client. The network access request carries the access credential. The VPN server uses the public key of the credential issuing system to verify the digital signature and, if the verification is successful, opens the network access channel corresponding to the authority ID.
[0159] The concepts of “first”, “second”, etc. mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0160] Regarding the terminal, VPN server and certificate issuing system in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments of the network access control method, and will not be elaborated here.
[0161] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, such division is not mandatory.
[0162] In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be embodied.
[0163] Some of the blocks shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0164] Refer to the following Fig.14 To describe the electronic device provided by the embodiment of the present disclosure. Fig.14 The electronic device 1400 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0165] Fig.14 FIG. 1 is a schematic diagram showing the architecture of an electronic device 1400 provided by an embodiment of the present disclosure. Fig.14 As shown, the electronic device 1400 includes but is not limited to: at least one processor 1410 and at least one memory 1420.
[0166] The memory 1420 is used to store instructions.
[0167] In some embodiments, the memory 1420 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 14201 and / or a cache memory unit 14202 , and may further include a read-only memory unit (ROM) 14203 .
[0168] In some embodiments, memory 1420 may also include a program / utility 14204 having a set (at least one) of program modules 14205, such program modules 14205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.
[0169] In some embodiments, the memory 1420 may store an operating system, which may be a real-time operating system (RTX), LINUX, UNIX, WINDOWS, or OS X.
[0170] In some embodiments, data may also be stored in the memory 1420 .
[0171] As an example, the processor 1410 may read data stored in the memory 1420 , where the data may be stored at the same storage address as the instruction, or the data may be stored at a different storage address than the instruction.
[0172] The processor 1410 is configured to call the instructions stored in the memory 1420 to implement the steps of various exemplary embodiments of the present disclosure described in the above “Exemplary Method” section of this specification. For example, the processor 1410 may execute the steps of the above network access control method embodiment.
[0173] It should be noted that the processor 1410 may be a general-purpose processor or a special-purpose processor. The processor 1410 may include one or more processing cores, and the processor 1410 executes various functional applications and data processing by running instructions.
[0174] In some embodiments, processor 1410 may include a central processing unit (CPU) and / or a baseband processor.
[0175] In some embodiments, the processor 1410 may determine an instruction according to the priority identification and / or function category information carried in each control instruction.
[0176] In the present disclosure, the processor 1410 and the memory 1420 may be provided separately or integrated together.
[0177] As an example, the processor 1410 and the memory 1420 may be integrated on a single board or a system on chip (SOC).
[0178] like Fig.14 As shown, the electronic device 1400 is in the form of a general-purpose computing device. The electronic device 1400 may further include a bus 1430 .
[0179] The bus 1430 may be a bus representing one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor, or a local bus using any of a variety of bus architectures.
[0180] The electronic device 1400 may also communicate with one or more external devices 1440 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), one or more devices that enable a user to interact with the electronic device 1400, and / or any device that enables the electronic device 1400 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed through an input / output (I / O) interface 1450.
[0181] Furthermore, the electronic device 1400 can also communicate with one or more networks (eg, a local area network (LAN), a wide area network (WAN) and / or a public network, such as the Internet) through the network adapter 1460 .
[0182] like Fig.14 As shown, the network adapter 1460 communicates with other modules of the electronic device 1400 via the bus 1430 .
[0183] It should be understood that although not shown in the figures, other hardware and / or software modules may be used in conjunction with the electronic device 1400, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0184] It is to be understood that the structure shown in the embodiment of the present disclosure does not constitute a specific limitation on the electronic device 1400. In other embodiments of the present disclosure, the electronic device 1400 may include: Fig.14 More or fewer components may be shown, or some components may be combined or separated, or the components may be arranged differently. Fig.14 The components shown may be implemented in hardware, software or a combination of software and hardware.
[0185] The present disclosure also provides a computer-readable storage medium on which computer instructions are stored. When the computer instructions are executed by a processor, the network access control method described in the above method embodiment is implemented.
[0186] The computer-readable storage medium in the embodiments of the present disclosure is a computer instruction that can be sent, propagated or transmitted for use by or in conjunction with an instruction execution system, apparatus or device.
[0187] As one example, computer readable storage media are non-volatile storage media.
[0188] In some embodiments, more specific examples of computer-readable storage media in the present disclosure may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, a USB flash drive, a mobile hard disk, or any suitable combination of the foregoing.
[0189] In the embodiments of the present disclosure, the computer-readable storage medium may include a data signal propagated in a baseband or as a part of a carrier wave, in which computer instructions (readable program codes) are carried.
[0190] Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing.
[0191] In some examples, computing instructions contained on a computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0192] The embodiment of the present disclosure also provides a computer program product, which stores instructions. When the instructions are executed by a computer, the computer implements the network access control method described in the above method embodiment.
[0193] The above instructions may be program codes. In specific implementation, the program codes may be written in any combination of one or more programming languages.
[0194] The programming language includes object-oriented programming languages, such as Java, C++, etc., and also includes conventional procedural programming languages, such as "C" language or similar programming languages.
[0195] The program code may execute entirely on the user's computing device, partly on the user's computing device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device or entirely on the remote computing device or server.
[0196] Where a remote computing device is involved, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).
[0197] The embodiment of the present disclosure also provides a chip, including at least one processor and an interface;
[0198] An interface for providing program instructions or data to at least one processor;
[0199] At least one processor is used to execute program instructions to implement the network access control method described in the above method embodiment.
[0200] In some embodiments, the chip may further include a memory, which is used to store program instructions and data, and the memory is located inside or outside the processor.
[0201] Those skilled in the art will appreciate that all or part of the steps for implementing the above embodiments may be implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, which may be collectively referred to herein as "circuits", "modules" or "systems".
[0202] Other embodiments of the disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the invention disclosed herein.
[0203] The present disclosure is intended to cover any variation, use or adaptation of the present disclosure, which follows the general principles of the present disclosure and includes common knowledge or customary technical means in the technical field not disclosed in the present disclosure. The description and examples are to be regarded as exemplary only, and the true scope and spirit of the present disclosure are indicated by the appended claims.
Claims
1. A network access control method, characterized in that: Applied to a terminal, the method comprises: Sending a first request message to a credential issuing system, where the first request message is used to apply for an access credential, and the first request message carries a user identifier; Receiving an access credential issued by a credential issuing system for a user corresponding to the user identifier, the access credential comprising a user identifier, an authority identifier, and a digital signature; The VPN client is started and a network access request is sent to the VPN server. The network access request carries the access credential, so that the VPN server verifies the digital signature using the public key of the credential issuance system and opens a network access channel corresponding to the authority identifier if the verification passes.
2. The method according to claim 1, characterized in that The access credential is one of an intranet credential, an extranet credential or a comprehensive credential. The intranet credential only has the authority to access the internal network, the extranet credential only has the authority to access the external network, and the intranet credential has the authority to access both the internal network and the external network.
3. The method according to claim 1, characterized in that The access credential also includes a validity period, which records the time interval during which the user credential can be normally used.
4. The method according to claim 3, characterized in that The validity period is determined according to one or more of a contract period, a project cycle, or a security policy of an enterprise of a user corresponding to the user identifier.
5. The method according to any one of claims 1 to 4, characterized in that: The digital signature is obtained by signing the target information in the access credential using the private key of the credential issuing system through a public key cryptographic algorithm, wherein the target information is the information in the access credential other than the digital signature.
6. A network access control method, characterized in that: Applied to a VPN server, the method comprises: Receiving and storing a mapping relationship between a permission identifier and a permission, wherein the permission is associated with a network access channel; Store the public key of the credential issuance system; Receiving a network access request sent by a terminal after starting a VPN client, the network access request carries an access credential, and the access credential includes a user identifier, an authority identifier, and a digital signature; Verifying the digital signature using the public key of the credential issuing system; If the verification is successful, the network access channel corresponding to the permission identifier is opened; The access credential is issued by the credential issuing system to the user corresponding to the user identifier.
7. The method according to claim 6, characterized in that The verifying the digital signature using the public key of the certificate issuing system includes: Decrypt the digital signature using a public key cryptographic algorithm and the public key of the certificate issuing system to obtain decrypted information; comparing the decrypted information with the information in the access credential except the digital signature to determine whether they are identical; If they are the same, the verification passes.
8. A network access control method, characterized in that: Applied to a credential issuance system, the method comprises: Sending a mapping relationship between the permission identifier and the permission to the VPN server, wherein the permission is associated with a network access channel; Sending the public key to the VPN server; Receiving a first request message sent by a terminal, where the first request message is used to apply for an access credential and the first request message carries a user identifier; issuing an access credential to a user corresponding to the user identifier; The access credential is sent to the terminal, and the access credential includes a user identifier, an authority identifier, and a digital signature, so that the terminal starts the VPN client and sends a network access request to the VPN server, and the network access request carries the access credential. The VPN server verifies the digital signature using the public key of the credential issuance system, and opens a network access channel corresponding to the authority identifier if the verification passes.
9. The method according to claim 8, characterized in that The access credential also includes a validity period, which records the time interval during which the user credential can be normally used.
10. The method according to claim 9, characterized in that The issuing of an access credential for the user corresponding to the user identifier includes: Based on the user identifier, determine the authority identifier and validity period; The user identification, the authority identification and the validity period are signed using the private key of the credential issuing system through a public key cryptographic algorithm to obtain the digital signature; The access credential is obtained based on the user identifier, the authority identifier, the validity period and the digital signature.
11. A network access control system, characterized in that: include: A certificate issuance system, used to send a mapping relationship between a permission identifier and a permission to a VPN server, the permission being associated with a network access channel, and a public key to the VPN server; The terminal is used to send a first request message to the credential issuing system, where the first request message is used to apply for an access credential, and the first request message carries a user identifier; The credential issuance system is further used to issue an access credential to the user corresponding to the user identifier, and send the access credential to the terminal, wherein the access credential includes a user identifier, an authority identifier, and a digital signature; The terminal is further used to start the VPN client and send a network access request to the VPN server, wherein the network access request carries the access credential; The VPN server also verifies the digital signature using the public key of the certificate issuing system, and opens a network access channel corresponding to the authority identifier if the verification passes.
Citation Information
Patent Citations
Security authentication method and device, electronic equipment and storage medium
CN114697063A
Method, device and system for accessing server
CN115277168A
Intranet resource access method and device, electronic equipment and readable medium
CN116980214A
Decentralized excitation hybrid network
CN117242473A
Data exfiltration control
US10764294B1
Cited By
Access control method, device and system, electronic equipment and storage medium
CN121864503A