User cross-network security access method based on IP control

Through the IP-controlled cross-network security access method, the data security problem caused by the collaborative work of R&D network and office network under network logic isolation is solved, and data security guarantees for non-R&D terminals are realized, ensuring the security and coordination efficiency of the business system.

CN120050089APending Publication Date: 2025-05-27JIANGSU XCMG STATE KEY LAB TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510194579.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In the environment of network logic isolation, the coordinated interaction between R&D network and office network leads to challenges in terminal data security management, especially the risk of data leakage from non-R&D terminals.

Method used

The user's cross-network security access method is adopted based on IP control. By pre-dividing fixed IP network segments, configuring office network IP whitelists, assigning IPs to user hosts, and filtering user logins based on account network attributes and IP whitelists, restricting technical network accounts from accessing R&D business systems from office network terminals.

Benefits of technology

It effectively guarantees the data security of the business system in non-R&D terminals, ensures the security of important documents and information, and enables personnel from different organizations and functional areas to work together safely.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050089A_ABST
    Figure CN120050089A_ABST
Patent Text Reader

Abstract

The invention provides a user cross-network security access method based on IP control, and the method comprises the steps: dividing a fixed IP network segment for an office network user using a service system in advance, selecting an account network attribute as a technical network or an office network for an office network account applied by the user, and distributing an IP to a user host from the fixed IP network segment; when a user logs in, a user client IP and a system configuration office network IP white list are obtained, if the account network attribute is a technical network, whether the office network IP list contains the client IP is judged, if yes, login fails, and the system refuses to access; if not, the login succeeds. And if the account network attribute is an office network, the system responds normally. According to the invention, the security of the business data in the non-research and non-development terminal is ensured, so that personnel of different organizations and different functional domains can smoothly carry out actual businesses depending on the business system, and a solid foundation is provided for enterprises to subsequently use digital technologies to optimize own processes and organizations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital research and development of engineering machinery, and in particular to a user cross-network secure access method based on IP control. Background Art

[0002] In order to ensure network security and prevent data leakage, the internal network of the enterprise will be logically isolated, divided into R&D network and office network, so as to meet the needs of user security R&D and conveniently obtain Internet resources to assist office work. The R&D data of engineering machinery enterprises usually contains core sensitive information. Once leaked or attacked, it will bring huge economic losses to the enterprise. Therefore, the enterprise puts the confidential business system into the R&D network for protection, and creates a safe and reliable R&D environment by disabling the U port, printing, and Internet access rights of the R&D terminal. In the digital age, cross-organizational and cross-domain collaborative sharing is becoming an important source of enterprise efficiency. The collaborative interaction of business activities between the R&D network and the office network is becoming more and more frequent. In order to support the needs of collaborative office, the business system needs to be open to users of the R&D network and the office network at the same time. At this time, terminal data security management has been challenged. If the business system does not restrict user access rights, a R&D domain user (R&D network) with file download rights can download R&D domain files to non-R&D terminals through non-R&D terminals (office network) across networks, resulting in the leakage of important files and information. Summary of the invention

[0003] In order to achieve the goal of balancing efficiency and security, the present invention proposes a user cross-network secure access method based on IP control to solve the data security problems caused by the collaboration of R&D network and office network under network logical isolation, and to ensure the data security of business systems in non-R&D terminals.

[0004] To achieve the above object, the technical solution adopted by the present invention is as follows: The present invention provides a user cross-network secure access method based on IP control, comprising: Pre-allocate fixed IP network segments for office network users who use R&D business systems; Configure office network IP whitelist information; Assign R&D business system accounts to users, and assign IP addresses to user hosts based on account network attributes and the divided fixed IP segments; Based on the user system account network attributes and the office network IP whitelist, the technical network account login IP address is filtered to restrict users from using the technical network account to access the R&D business system from the office network terminal.

[0005] Preferably, the step of pre-dividing a fixed IP network segment for office network users using the R&D business system includes: Pre-allocate a fixed IP network segment for office network users using the R & D business system, and allow the fixed IP network segment to access the R & D business system server by configuring the firewall access policy.

[0006] Preferably, the configuration of the office network IP white list information includes: Enter the information of the divided fixed IP network segment in the R & D business system.

[0007] Preferably, the configuration of the office network IP white list information further includes: Save the entered fixed IP network segment information to the IP configuration table in the R & D business system database.

[0008] Preferably, the entry of the divided fixed IP network segment information in the R & D business system supports single IP entry and IP address segment entry.

[0009] Preferably, the allocation of R & D business system accounts to users and the assignment of IPs to user hosts based on the account network attributes and the divided fixed IP network segment include: Users apply for R & D business system accounts and fill in application information, which needs to include account network attributes; the account network attributes are one of the technology network and the office network; After being approved, for office network accounts, assign IPs to user hosts from the fixed IP network segment.

[0010] Preferably, after the assignment of IPs to user hosts, it further includes: Add user account information in the R & D business system; the user account information includes: user account and account network attribute information.

[0011] Preferably, the filtering of the login IP address of technology network accounts based on the user system account network attributes and the office network IP white list includes: When a user logs in to the R & D business system, obtain the real IP of the user client, the user account network attributes, and the office network IP white list; If the account network attribute is the technology network, compare the real IP of the user client with the office network IP white list to determine whether to allow login; If the account network attribute is the office network, allow login.

[0012] Preferably, the office network IP white list is obtained from the IP configuration table in the R & D business system database.

[0013] Preferably, the step of if the account network attribute is the technology network, then compare the real IP of the user client with the office network IP white list to determine whether to allow login includes: Determine whether the real IP address of the client is included in the white list of the office network IP. If it is included, it means that the user is accessing the R & D business system from an office network terminal using a technology network account, and login is not allowed. If it is not included, the user can normally access the R & D business system from the technology network and the login is successful.

[0014] By adopting the above technical solution, the beneficial effects of the present invention are as follows: The present invention proposes a method for cross-network secure access of users based on IP control, which solves the problem of terminal data security generated by the collaborative work of R & D network and office network business personnel relying on a unified business system under network logical isolation. By filtering the login IP address of the technology network account, it restricts users from accessing from office network terminals using the technology network account, ensuring the security of business data on non-R & D terminals, enabling personnel in different organizations and different functional domains to smoothly carry out actual business relying on the business system, and enabling business data to be generated and transferred truly, completely and smoothly between multiple organizations and multiple processes, providing a solid foundation for the enterprise to optimize its own processes and organizations by applying digital technology in the future. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 It is a schematic flowchart of Step 1 of the method for cross-network secure access of users based on IP control provided by the present invention; Figure 2 It is a schematic flowchart of Step 2 of the method for cross-network secure access of users based on IP control provided by the present invention; Figure 3 It is a schematic flowchart of Step 3 of the method for cross-network secure access of users based on IP control provided by the present invention; Figure 4 It is a schematic flowchart of Step 4 of the method for cross-network secure access of users based on IP control provided by the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0016] To make the purpose, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below in conjunction with the embodiments and the drawings. Here, the illustrative embodiments and descriptions thereof of the present invention are used to explain the present invention, but not to limit the present invention.

[0017] Here, it should also be noted that in order to avoid obscuring the present invention due to unnecessary details, only the structures and / or processing steps closely related to the solution of the present invention are shown in the drawings, while other details less related to the present invention are omitted.

[0018] It should be emphasized that the term "including / comprising" when used herein refers to the presence of features, elements, steps or components, but does not exclude the presence or addition of one or more other features, elements, steps or components.

[0019] It should be emphasized here that the step marks mentioned hereinafter do not limit the sequence of each step. Instead, it should be understood that the steps can be executed in the sequence mentioned in the embodiments, or different from the sequence in the embodiments, or several steps can be executed simultaneously.

[0020] An embodiment of the present invention provides a method for cross-network secure access of users based on IP control to solve the data security problems generated by the work collaboration between the R & D network and the office network under network logical isolation and ensure the data security of the business system on non-R & D terminals. See Figures 1 to 4 , including the following steps: Step 1, see Figure 1 , pre-divide a fixed IP network segment for office network users using the R & D business system. By configuring the firewall access policy, allow this office fixed IP network segment to access the R & D business system server.

[0021] Step 2, configure the office network IP whitelist information. The specific implementation process is as follows Figure 2 , including: S21. In the "IP Configuration Management" module of the R & D business system, fill in the fixed IP network segment information divided in Step 1, supporting single IP entry and IP address segment entry; S22. Save the filled fixed IP network segment information to the "IP Configuration Table" in the database.

[0022] Step 3, assign R & D business system accounts to users. The specific implementation process is as follows Figure 3 , including: S31. Through the enterprise internal process management platform, apply for an R & D business system account and fill in the application information, which needs to include the account network attribute ("technology network" or "office network"); S32. After being approved, for office network accounts, assign an IP from the office fixed IP network segment that is allowed to access the R & D business system service to the user host; S33. The system administrator adds user information in the R & D business system, assigns an account to the user, and configures the account network attribute information.

[0023] Step 4, when the user logs in to the R & D business system, filter the login IP address of the technology network account to restrict the user from accessing the R & D business system from the office network terminal using the technology network account. The specific implementation process is as follows Figure 4 , including: S41. When the user logs in to the R & D business system, obtain the real IP of the user client; S42. Obtain the office network IP whitelist information configured in the R & D business system from the "IP Configuration Table"; S43. Obtain the user account network attribute, If the network property of the account is the technology network, compare the real IP of the user client with the obtained white list of office network IPs to determine whether the white list of office network IPs contains the client IP. If it contains, it means that the user is currently using a technology network account to access the R & D system from an office network terminal, and the login fails, and the system refuses access; if it does not contain, it means that the technology network account is accessing the R & D business system from the technology network normally, and the login is successful, and the system responds normally; If the network property of the account is the office network, the system responds normally and the login is directly successful.

[0024] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and deformations can be made, and these improvements and deformations should also be regarded as the protection scope of the present invention.

Claims

1. A user cross-network secure access method based on IP control, characterized in that: include: Pre-allocate fixed IP network segments for office network users who use R&D business systems; Configure office network IP whitelist information; Assign R&D business system accounts to users, and assign IP addresses to user hosts based on account network attributes and the divided fixed IP segments; Based on the user system account network attributes and the office network IP whitelist, the technical network account login IP address is filtered to restrict users from using the technical network account to access the R&D business system from the office network terminal.

2. According to the method for secure user cross-network access based on IP control according to claim 1, it is characterized in that: The method of pre-dividing a fixed IP network segment for office network users using the R&D business system includes: Pre-allocate a fixed IP network segment for office network users who use the R&D business system, and configure the firewall access policy to allow the fixed IP network segment to access the R&D business system server.

3. According to claim 2, a user cross-network secure access method based on IP control is characterized in that: The configuration of office network IP whitelist information includes: Enter the divided fixed IP network segment information into the R&D business system.

4. According to claim 3, a user cross-network secure access method based on IP control is characterized in that: The configuration of office network IP whitelist information also includes: Save the entered fixed IP network segment information to the IP configuration table of the R&D business system database.

5. According to the method of claim 3, the method is characterized in that: The fixed IP network segment information divided and entered into the R&D business system supports single IP entry and IP address segment entry.

6. According to the method of claim 4, the method is characterized in that: The method of allocating a research and development business system account to a user and allocating an IP address to a user host based on the account network attributes and the divided fixed IP network segments includes: The user applies for a research and development business system account and fills in the application information, which must include the account network attribute; the account network attribute is one of the technical network and the office network; After approval, for the office network account, an IP is allocated to the user host from the fixed IP segment.

7. A user cross-network secure access method based on IP control according to claim 6, characterized in that: After allocating the IP to the user host, the process also includes: Add user account information in the R&D business system; the user account information includes: user account and account network attribute information.

8. A user cross-network secure access method based on IP control according to claim 7, characterized in that: The filtering of the technical network account login IP address based on the user system account network attribute and the office network IP whitelist includes: When a user logs into the R&D business system, the user's real client IP, user account network attributes, and office network IP whitelist are obtained; If the account network attribute is a technical network, the user client's real IP is compared with the office network IP whitelist to determine whether login is allowed; If the account network attribute is office network, login is allowed.

9. A user cross-network secure access method based on IP control according to claim 8, characterized in that: The office network IP whitelist is obtained from the IP configuration table of the R&D business system database.

10. The method for secure cross-network access based on IP control according to claim 8, characterized in that: If the account network attribute is a technical network, the real IP address of the user client is compared with the office network IP whitelist to determine whether to allow login, including: Determine whether the real IP of the client is included in the office network IP whitelist. If it is included, the user is using the technical network account to access the R&D business system from the office network terminal and is not allowed to log in. If it is not included, the user accesses the R&D business system normally from the technical network and logs in successfully.

Citation Information

Cited By

  • Intention-driven cross-network access control strategy dynamic arrangement method

    CN121984736A