Access control method and device of terminal equipment and computer program product
By conducting connectivity detection on the client software to detect the terminal equipment and sending corresponding access management policies or emergency response instructions, the problem of low accuracy in site identification of terminal equipment is solved, and the accuracy of site judgment and business continuity are improved.
Patent Information
- Application Number
- CN202510427693.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-06-13
AI Technical Summary
In the prior art, there is a problem of low recognition accuracy when identifying the detection terminal equipment in the site, and the site judgment mechanism is prone to failure due to system failure or network attacks, affecting business continuity.
By obtaining the client software of the terminal device to be detected and performing connectivity detection on it, it is determined whether the terminal device is in the target place. If the detection result indicates that the terminal device is in the target site, send an access management policy to indicate its network access rights; if the detection result is unknown, send an emergency processing instruction to initiate the emergency processing mechanism.
It improves the accuracy and flexibility of terminal equipment site judgment, optimizes the site judgment and emergency access process, enhances user experience and business continuity, and solves the problem of low accuracy in terminal equipment site recognition.
Smart Images

Figure CN120151073A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of fintech, and in particular, to an access control method, device, and computer program product for a terminal device. Background Art
[0002] In recent years, with the continuous expansion of the cyber space and the rapid development of information technology, external information security threats have shown an increasingly severe situation. Especially in the financial industry, due to its high dependence on data and networks, and the huge value of the assets involved, the systems of financial institutions have become the main targets of cyber attacks, and important internal data has been leaked, affecting the normal office work and business development within the institution. To address these challenges, financial institutions have taken a number of network security measures internally. For example, various security protection means such as firewalls, security gateways, and deployment of terminal security products are adopted to achieve the purpose of not allowing terminals to access the Internet, and at the same time, an internal network boundary is established to implement strict isolation measures to prevent unauthorized Internet access, reduce the risk of external attacks, and ensure the security of the internal network and effectively prevent attack risks.
[0003] In actual scenarios, since the network of financial institutions includes an internal network site and a remote access site, verified trusted terminals can enter the internal network scenario through the network. At this time, the network firewall can be relaxed for such trusted terminals without excessive restrictions; for terminals in the remote usage scenario of Internet access, the access scope needs to be strictly controlled locally at the terminal, and only the remote access destination address and the corresponding port can be opened to avoid intrusion to the greatest extent. However, the above measures have some limitations in actual applications.
[0004] First of all, the current site judgment mechanism is too strict, and it only judges the location of the terminal based on whether it establishes a connection with specific resources in the internal network, which is prone to misjudgment. Once a misjudged compliant internal network terminal is wrongly regarded as a remote access terminal, it will not be able to access internal resources normally, affecting business efficiency. In addition, the judgment of the site where the terminal is located is usually combined with the connectivity test of other internal systems. If these systems go offline or fail, the entire site judgment mechanism may fail, and the terminal cannot access the internal network, resulting in business interruption. Further, the current site judgment mechanism often uses the Ping command to test the connectivity with internal network resources. Although the network load of a single Ping operation is small, in a large-scale terminal network, frequent Ping operations may have a cumulative effect, causing the target server to bear a large amount of useless network traffic, affecting the normal operation of services, and posing a potential threat to the network security and business continuity of financial institutions.
[0005] Regarding the problem of low recognition accuracy in identifying the location of the terminal device to be detected in the related art, no effective solution has been proposed yet. Summary of the Invention
[0006] The main objective of the present application is to provide an access control method, apparatus, and computer program product for a terminal device, so as to solve the problem of low recognition accuracy in identifying the location of a terminal device to be detected in the related art.
[0007] To achieve the above objective, according to one aspect of the present application, an access control method for a terminal device is provided. The method includes: obtaining a terminal device to be detected, and obtaining the client software installed on the terminal device to be detected; performing a connectivity detection on the client software to obtain a first detection result, where the connectivity detection is used to determine whether the terminal device to be detected is in a target location; in the case where the first detection result indicates that the terminal device to be detected is in the target location, sending an access management policy to the terminal device to be detected, where the access management policy is used to indicate the network access permission of the terminal device to be detected in the target location; in the case where the first detection result indicates that the location of the terminal device to be detected is unknown, sending an emergency handling instruction to the terminal device to be detected, where the emergency handling instruction is used to indicate the terminal device to be detected to activate an emergency handling mechanism.
[0008] Further, performing a connectivity detection on the client software to obtain a first detection result includes: obtaining preset parameters of a preset server, where the preset parameters include at least one of the following: address information of the preset server, port number, and domain name information; generating a detection instruction according to the preset parameters and sending the detection instruction to the client software; in the case of receiving a detection response fed back by the client software, sending a preset command to the client software and monitoring the client software, where the detection response is used to indicate that the client software has received the detection instruction, and the preset command is used to indicate the client software to establish a connection with the preset server; in the case of receiving a first connection response fed back by the client software, generating a determination result that the terminal device to be detected is in the target location, where the first connection response indicates that the client software has received a response fed back by the preset server within a preset time period; in the case of receiving a second connection response fed back by the client software, generating a determination result that the location of the terminal device to be detected is unknown, where the second connection response indicates that the client software has not received a response fed back by the preset server within a preset time period, or the preset server refuses to establish a connection with the client software.
[0009] Further, sending an access management policy to the terminal device to be detected includes: identifying the venue type of the target venue, where the venue type includes an intranet venue and a remote access venue; in the case where the target venue is an intranet venue, obtaining a first access management policy according to the intranet venue and authenticating the terminal device to be detected; in the case where the terminal device to be detected passes the authentication, pushing the first access management policy to the terminal device to be detected; in the case where the target venue is a remote access venue, obtaining a second access management policy according to the remote access venue and, in the case where the terminal device to be detected is verified without error, pushing the second access management policy to the terminal device to be detected.
[0010] Further, after sending the access management policy to the terminal device to be detected, the method further includes: receiving a policy execution result fed back by the terminal device to be detected, where the policy execution result is used to characterize the execution situation of the access management policy by the terminal device to be detected; identifying the policy execution result, and in the case where the policy execution result characterizes that there is an abnormality when the terminal device to be detected executes the access management policy, sending an emergency handling instruction to the terminal device to be detected.
[0011] Further, after sending the emergency handling instruction to the terminal device to be detected, the method further includes: receiving an authentication request initiated by the terminal device to be detected, where the authentication request includes the identification information of the terminal device to be detected and an emergency handling key; authenticating the terminal device to be detected according to the identification information and the emergency handling key; in the case where the identification information passes the authentication, determining the terminal device to be detected as a device of the target venue and sending an emergency handling policy to the terminal device to be detected, where, in the case where the terminal device to be detected receives the emergency handling policy, adjusting the firewall rules and network access permissions of the terminal device to be detected according to the emergency handling policy.
[0012] Further, after sending the emergency handling policy to the terminal device to be detected, the method further includes: re-performing a connectivity detection on the client software to obtain a second detection result; in the case where the second detection result characterizes that the terminal device to be detected is in the target venue, restoring the firewall rules and network access permissions of the terminal device to be detected; in the case where the second detection result characterizes that the venue of the terminal device to be detected is unknown, migrating the terminal device to be detected to an isolation area and restricting the terminal device to be detected from accessing the network.
[0013] Further, obtaining the terminal device to be detected includes: obtaining M financial management systems in the financial operation cluster to which the client management system belongs, where M is a positive integer; decoupling the M financial management systems from the client management system and performing the step of obtaining the terminal device to be detected.
[0014] To achieve the above object, according to another aspect of the present application, there is provided an access control device for a terminal device. The device includes: an acquisition unit configured to acquire a terminal device to be detected and acquire client software installed on the terminal device to be detected; a first detection unit configured to perform connectivity detection on the client software to obtain a first detection result, wherein the connectivity detection is used to determine whether the terminal device to be detected is in a target location; a first sending unit configured to send an access management policy to the terminal device to be detected when the first detection result indicates that the terminal device to be detected is in the target location, wherein the access management policy is used to indicate the network access permission of the terminal device to be detected in the target location; a second sending unit configured to send an emergency handling instruction to the terminal device to be detected when the first detection result indicates that the location of the terminal device to be detected is unknown, wherein the emergency handling instruction is used to instruct the terminal device to be detected to start an emergency handling mechanism.
[0015] According to another aspect of the embodiments of the present invention, there is also provided a computer-readable storage medium. The computer-readable storage medium includes a stored executable program, wherein when the executable program runs, it controls the device where the computer-readable storage medium is located to execute any one of the above access control methods for a terminal device.
[0016] According to another aspect of the embodiments of the present invention, there is also provided an electronic device, including one or more processors and a memory. The memory stores an executable program, and the processors are configured to run the program. Wherein, when one or more programs are executed by one or more processors, one or more processors are caused to implement any one of the above access control methods for a terminal device.
[0017] According to another aspect of the embodiments of the present invention, there is also provided a computer program product. The computer program product includes a computer program, wherein when the computer program is executed by a processor, it implements any one of the above access control methods for a terminal device.
[0018] In an embodiment of the present application, an access control method for a terminal device is adopted. By obtaining the terminal device to be detected and the client software installed on the terminal device to be detected, and performing connectivity detection on the client software to obtain a first detection result. The connectivity detection is used to determine whether the terminal device to be detected is in a target location. When the first detection result indicates that the terminal device to be detected is in the target location, an access management policy is sent to the terminal device to be detected. The access management policy is used to indicate the network access permission of the terminal device to be detected in the target location. When the first detection result indicates that the location of the terminal device to be detected is unknown, an emergency handling instruction is sent to the terminal device to be detected. The emergency handling instruction is used to indicate the terminal device to be detected to start an emergency handling mechanism, achieving the purpose of enhancing the accuracy and flexibility of location judgment and realizing the emergency access of the terminal device to be detected. Thus, the technical effect of optimizing the location judgment and emergency access process, enhancing the user experience and business continuity is achieved, and further solves the problem of low recognition accuracy when identifying the location of the terminal device to be detected. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The accompanying drawings, which form a part of this application, are used to provide a further understanding of this application. The schematic embodiments and descriptions thereof of this application are used to explain this application and do not constitute an improper limitation of this application. In the drawings:
[0020] Figure 1 is a hardware structure block diagram of a computer terminal (or mobile device) for implementing an access control method for a terminal device;
[0021] Figure 2 is a flowchart of an access control method for a terminal device according to an embodiment of this application;
[0022] Figure 3 is a flowchart of an alternative access control method for a terminal device according to an embodiment of this application;
[0023] Figure 4 is a schematic diagram of an access control device for a terminal device according to an embodiment of this application;
[0024] Figure 5 is a structure block diagram of an electronic device according to an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0025] To enable those skilled in the art to better understand the solution of this application, the following will clearly and completely describe the technical solution in the embodiments of this application in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application.
[0026] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data used can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order different from those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0027] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set up between this system and relevant users or institutions. Before obtaining relevant information, a request for acquisition needs to be sent to the aforementioned users or institutions through the interface, and after receiving the consent information feedback from the aforementioned users or institutions, the relevant information can be obtained.
[0028] It should be noted that the information collected in this application is information and data authorized by the user or fully authorized by all parties, and the processing of relevant data such as collection, storage, use, processing, transmission, provision, disclosure, and application complies with the relevant laws, regulations, and standards in the relevant regions, takes necessary confidentiality measures, does not violate public order and good customs, and provides a corresponding operation entry for users to choose to authorize or refuse to use.
[0029] Embodiment 1
[0030] According to the embodiments of this application, an embodiment of a method for access control of a terminal device is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.
[0031] The method embodiment provided in the first embodiment of this application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 It is a hardware block diagram of a computer terminal (or mobile device) for implementing an access control method for a terminal device. As Figure 1 shown, the computer terminal 10 (or mobile device) may include one or more ( Figure 1 illustrated as 102a, 102b,..., 102n in Figure 1 the figure) processors 102 (the processors 102 may include, but are not limited to, processing devices such as a microprocessor MCU (Microcontroller Unit) or a field-programmable gate array FPGA (Field-Programmable Gate Array)), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a keyboard, a cursor control device, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown in Figure 1 the figure is only illustrative and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than
[0032] shown in
[0033] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the access control method of the terminal device in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned access control method of the terminal device. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof.
[0034] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of the computer terminal 10. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, NIC) and a network interface, which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0035] The display can be, for example, a touch-screen liquid crystal display (Liquid Crystal Display, LCD), and the liquid crystal display enables a user to interact with the user interface of the computer terminal 10 (or mobile device).
[0036] Under the above operating environment, the present application provides an access control method for a terminal device as Figure 2 shown. Figure 2 is a flowchart of the access control method for a terminal device provided according to an embodiment of the present application, as Figure 2 shown, and the method includes the following steps:
[0037] Step S201, obtain the terminal device to be detected, and obtain the client software installed on the terminal device to be detected.
[0038] Specifically, the terminal device to be detected refers to the device used by the staff of a financial institution. To determine the network environment where the terminal device to be detected is located, first, the above-mentioned terminal device to be detected and the client software installed in the device can be obtained. Among them, the client software can receive and execute the security policies and network access control rules from the client management system, and can also start an emergency handling mechanism when the terminal device to be detected encounters network access obstacles or the judgment mechanism fails. The client software can be a desktop management client.
[0039] Step S202: Perform a connectivity test on the client software to obtain a first test result. Among them, the connectivity test is used to determine whether the terminal device to be detected is in the target location.
[0040] Specifically, the connectivity judgment is used to detect whether the network connection between the terminal device and specific internal network resources is smooth. To determine whether the current network environment of the terminal is an internal network location, a remote access location, or an unknown location, the optimized Telnet command or NC (Netcat) command can be used to perform a connectivity judgment on the client software installed on the terminal device to be detected. Among them, the Telnet / NC command is used to test network connections and data transmissions. When performing a network connectivity test, there is no need to parse the TTL (Time-to-Live) value of the ICMP (Internet Control Message Protocol), and the judgment of network connectivity can be more direct, without bringing additional traffic pressure to the network, and at the same time avoiding the potential security risks caused by the widespread use of the Ping command. By using the Telnet command or NC command, the network status of the terminal device to be detected can be judged more accurately without affecting the normal operation of the internal network.
[0041] Step S203: When the first test result indicates that the terminal device to be detected is in the target location, send an access management policy to the terminal device to be detected. Among them, the access management policy is used to indicate the network access permissions of the terminal device to be detected in the target location.
[0042] It should be noted that the target location can include an internal network location and a remote access location. The access control policy can define the security boundaries and accessible network resources of the terminal device to be detected in different locations, such as a list of allowed network resources, a prohibited address range, open ports of network services, specific servers, databases, applications, or external network services, as well as specific firewall rules, which helps to protect private data and ensure that it is only accessed in a secure network environment.
[0043] Specifically, when the first detection result indicates that the to-be-detected terminal device can be connected, that is, it is in the target location, the client management system can first verify the identity of the to-be-detected terminal device, and then send the access management policy for the corresponding location to the to-be-detected terminal device. At this time, the to-be-detected terminal device can update the local network access control list and firewall rules according to the content of the policy, and then access network resources according to the updated rules to ensure network security and compliance.
[0044] Step S204, when the first detection result indicates that the location of the to-be-detected terminal device is unknown, send an emergency handling instruction to the to-be-detected terminal device, where the emergency handling instruction is used to instruct the to-be-detected terminal device to start an emergency handling mechanism.
[0045] Specifically, when the first detection result indicates that the location of the to-be-detected terminal device is unknown, that is, the to-be-detected terminal device is not in the intranet location and the remote access location, at this time, in order to cope with possible network failures or system anomalies, emergency handling is required, that is, send an emergency handling instruction to the above-mentioned to-be-detected terminal device, where the emergency handling instruction may include reconfiguring network settings, temporarily adjusting firewall rules, starting an emergency handling mechanism, etc., to help the to-be-detected terminal device restore basic network access functions while minimizing the impact on network security.
[0046] After the to-be-detected terminal device receives the above emergency handling instruction, it can first guide the client software to perform network diagnosis, check the network configuration, connection status and firewall rules of the to-be-detected terminal device, and try to identify the reason for the unknown detection result. If the diagnosis finds that it is caused by a simple network configuration error or a temporary connection problem, it can try to automatically repair, such as adjusting network settings, restarting network services or temporarily closing the firewall; if the network diagnosis fails to solve the problem, or the detection result is unknown due to more complex reasons, such as network isolation, system failure or security incident, the to-be-detected terminal device triggers a preset emergency handling mechanism.
[0047] It should be noted that once the to-be-detected terminal device restores basic network functions through the emergency handling mechanism, the system can re-perform the connectivity detection to determine its current actual location. If the new detection result can clarify the location of the to-be-detected terminal device, the corresponding access management policy can be executed according to the new detection result at this time; if the problem remains unresolved, network isolation measures need to be taken for the to-be-detected terminal device.
[0048] The access control method for a terminal device provided by an embodiment of the present application includes obtaining a terminal device to be detected and obtaining the client software installed on the terminal device to be detected; performing a connectivity detection on the client software to obtain a first detection result, where the connectivity detection is used to determine whether the terminal device to be detected is in a target location; in the case where the first detection result indicates that the terminal device to be detected is in the target location, sending an access management policy to the terminal device to be detected, where the access management policy is used to indicate the network access permission of the terminal device to be detected in the target location; in the case where the first detection result indicates that the location of the terminal device to be detected is unknown, sending an emergency handling instruction to the terminal device to be detected, where the emergency handling instruction is used to instruct the terminal device to be detected to start an emergency handling mechanism, which solves the problem of low recognition accuracy in identifying the location of the terminal device to be detected in the related art. By performing a connectivity detection on the client software of the terminal device to be detected, in the case where the detection result indicates that the terminal device to be detected is in the target location, sending an access management policy to the terminal device to be detected; in the case where the detection result indicates that the location of the terminal device to be detected is unknown, sending an emergency handling instruction to the terminal device to be detected, thereby achieving the technical effects of optimizing the location judgment and emergency access process and enhancing the user experience and service continuity.
[0049] Optionally, in order to determine whether the terminal device to be detected can currently successfully communicate with a preset network resource, in the access control method for a terminal device provided by an embodiment of the present application, performing a connectivity detection on the client software to obtain a first detection result includes: obtaining preset parameters of a preset server, where the preset parameters include at least one of the following: address information of the preset server, port number, and domain name information; generating a detection instruction according to the preset parameters and sending the detection instruction to the client software; in the case of receiving a detection response feedback by the client software, sending a preset command to the client software and monitoring the client software, where the detection response is used to indicate that the client software has received the detection instruction, and the preset command is used to instruct the client software to establish a connection with the preset server; in the case of receiving a first connection response feedback by the client software, generating a judgment result that the terminal device to be detected is in the target location, where the first connection response indicates that the client software has received a response feedback by the preset server within a preset time period; in the case of receiving a second connection response feedback by the client software, generating a judgment result that the location of the terminal device to be detected is unknown, where the second connection response indicates that the client software has not received a response feedback by the preset server within a preset time period, or the preset server refuses to establish a connection with the client software.
[0050] Specifically, when performing connectivity detection on the terminal device to be detected, it is first necessary to determine the parameter information of the preset server for venue judgment, such as the IP address, port number, domain name information, etc. of the server. Then, based on the obtained preset server parameters, a detection instruction is generated and sent to indicate that the client software attempts to establish a connection with the preset server.
[0051] After receiving the detection instruction, the client software attempts to establish a connection with the specified target server using the Telnet or NC command, and then sends a detection response to the client management system, indicating that it has received and started to execute the detection instruction. Among them, the format of the above command can be: telnet [preset server IP or domain name] [port number] or nc - zv [preset server IP or domain name] [port number].
[0052] To avoid the situation of waiting for a long time without response, it is also necessary to determine the detection timeout time. After receiving the detection response, the client management system enters the monitoring state and waits for the client software to further feedback the connection result. If the client software successfully receives the response feedback from the preset server within the preset time, it indicates that the connection is successfully established, that is, the connectivity detection is successful. At this time, a judgment result that the terminal device to be detected is in the intranet venue or a predefined remote access venue can be generated.
[0053] On the contrary, if within the preset time period, the client management system does not receive the response feedback from the preset server or the above preset server refuses to establish a connection, that is, the connection times out or is refused, it indicates that the terminal device to be detected is located in an unauthorized network environment, or encounters a network failure or security problem, and further diagnosis and processing are required. At this time, the connectivity detection fails, and a judgment result that the venue of the terminal device to be detected is unknown can be generated. For the terminal determined to be located in the target venue, the system will issue an access management policy to allow it to access specific network resources; for the terminal with an unknown venue, an emergency handling instruction will be issued, or it will enter the isolation area according to the system configuration to restrict its network access until the problem is solved or its location is reconfirmed. Through judging the network environment of the terminal device to be detected, this embodiment determines the venue where the terminal device to be detected is located, enhances the timeliness and response speed, and can also quickly identify network problems and potential security threats.
[0054] Access management policies can include multiple types. Optionally, in the access control method for a terminal device provided in the embodiments of the present application, sending an access management policy to the terminal device to be detected includes: identifying the type of the target location, where the location type includes an intranet location and a remote access location; in the case where the target location is an intranet location, obtaining a first access management policy according to the intranet location and authenticating the terminal device to be detected; in the case where the terminal device to be detected passes the authentication, pushing the first access management policy to the terminal device to be detected; in the case where the target location is a remote access location, obtaining a second access management policy according to the remote access location and, in the case where the terminal device to be detected is verified correctly, pushing the second access management policy to the terminal device to be detected.
[0055] After performing a connectivity detection on the terminal device to be detected, the network access permissions that the terminal device to be detected can obtain can be determined based on the detection result, and then different access management policies can be sent to the terminal device to be detected. Specifically, the intranet location can be a network environment within a financial institution that is not open to the Internet and does not require passing through a firewall or additional network controls; the remote access location, however, requires access control through additional security measures. When the detection result indicates that the terminal device to be detected is in the target location, it is first necessary to determine the specific type of the target location. After the target location is an intranet location, it is first necessary to authenticate the terminal device to be detected, and after the authentication passes, obtain the first access management policy applicable to the intranet location from the policy library. This policy details the network access permissions of the terminal device to be detected in the intranet location, including the list of internal servers allowed to be accessed, open ports and protocols, firewall rules, etc.
[0056] For the remote access location, the client management system needs to perform secondary verification while authenticating the terminal device to be detected. After the verification is successful, obtain the second access management policy applicable to the remote access location from the policy library and, through a secure communication channel, push the access management policy applicable to the above location type to the client software of the terminal device to be detected, ensuring that the terminal device to be detected can only access authorized internal resources and at the same time restricting its access to other networks to protect the financial institution from external threats. After receiving the policy, the client software can update the local firewall rules and network access control list according to the policy.
[0057] This embodiment can effectively isolate the intranet and remote access environments through location type identification, reduce the potential risks of external threats to the intranet. At the same time, through correct location judgment and access policy pushing, it helps with the reasonable allocation and management of resources, reduces network congestion, and improves the overall network performance, thus supporting the business continuity and network security of financial institutions.
[0058] Optionally, in the access control method of the terminal device provided in the embodiments of the present application, after sending the access management policy to the terminal device to be detected, the method further includes: receiving the policy execution result fed back by the terminal device to be detected, where the policy execution result is used to characterize the execution situation of the access management policy by the terminal device to be detected; identifying the policy execution result, and when the policy execution result indicates that there is an abnormality in the execution of the access management policy by the terminal device to be detected, sending an emergency handling instruction to the terminal device to be detected.
[0059] To ensure that the access management policy can be correctly executed on the terminal device to be detected, the execution status of the policy can be determined through the policy execution result fed back by the terminal device to be detected, and the execution abnormality can be identified and responded to in a timely manner, so as to take necessary emergency measures. Specifically, after the terminal device to be detected receives the access management policy, it executes the network access control instructions in the policy, such as updating firewall rules, adjusting network settings, etc., and then generates a policy execution result according to the execution situation and sends it to the client management system. Among them, the policy execution result can include the status of policy execution (success or failure), specific execution operations, error or warning information encountered during the execution process, and the network access record after execution. These information can help the client management system comprehensively understand the actual effect of the policy on the terminal device to be detected and possible execution problems.
[0060] After receiving the above policy execution result, the client management system identifies and analyzes the abnormal situations therein, such as whether it involves situations such as policy execution failure, network access exceeding the policy permitted range, network connection interruption during the execution process, firewall rule update failure, etc. When the policy execution result indicates that there is an abnormality in the execution of the access management policy by the terminal device to be detected, an emergency handling instruction can be generated at this time and sent to the terminal device to be detected through a secure communication channel.
[0061] It should be noted that after sending the emergency handling instruction, the client management system can continuously monitor the status of the terminal device to be detected to ensure that the emergency handling instruction is correctly executed. Through real-time receiving the policy execution result and identifying the abnormality, this embodiment can quickly respond to the changes in the network environment, correct the errors in the policy execution in a timely manner, improve the security and stability, and also improve the response speed and processing efficiency of the overall system.
[0062] Optionally, in the access control method of the terminal device provided in the embodiments of the present application, after sending an emergency processing instruction to the terminal device to be detected, the method further includes: receiving an authentication request initiated by the terminal device to be detected, where the authentication request includes the identification information of the terminal device to be detected and an emergency processing key; performing identity authentication on the terminal device to be detected according to the identification information and the emergency processing key; in the case where the identification information is verified, determining the terminal device to be detected as a device of the target location, and sending an emergency processing strategy to the terminal device to be detected, where, in the case where the terminal device to be detected receives the emergency processing strategy, adjusting the firewall rules and network access permissions of the terminal device to be detected according to the emergency processing strategy.
[0063] Specifically, when the terminal device to be detected is in an unknown location, in order to safely restore network access permissions, the client management system can receive the authentication request initiated by the terminal device to be detected, and parse the identification information and the emergency processing key in the request to confirm the source of the request and the legality of the request, where the request includes the unique identification information of the terminal device to be detected (such as MAC address, serial number or device name) and a pre-configured emergency processing key.
[0064] The client management system ensures that the request comes from a device authorized within the financial institution by verifying the correctness of the identification information of the terminal device to be detected and the emergency processing key, and after the identification information and the emergency processing key are verified, generates a corresponding emergency processing strategy according to the abnormal network environment where the terminal device to be detected is located, and sends the emergency processing strategy to the terminal device to be detected through a secure communication channel, where the above strategy may include temporary network access permissions, relaxed firewall rules, a specific list of emergency servers, etc., and performs necessary function recovery and security maintenance to help the terminal device to be detected restore basic network functions in a restricted network environment.
[0065] After receiving the emergency processing strategy, the terminal device to be detected can adjust its firewall rules and network access permissions according to the emergency processing strategy, and then ensure the restoration of network functions according to access control. This embodiment reduces the business suspension caused by network problems by using the emergency processing strategy to process the terminal device to be detected, simplifies the process of network fault recovery, and can maintain business continuity and user work efficiency.
[0066] Optionally, in the access control method for a terminal device provided in an embodiment of the present application, after sending an emergency handling policy to the terminal device to be detected, the method further includes: re-performing a connectivity detection on the client software to obtain a second detection result; when the second detection result indicates that the terminal device to be detected is in a target location, restoring the firewall rules and network access permissions of the terminal device to be detected; when the second detection result indicates that the location of the terminal device to be detected is unknown, migrating the terminal device to be detected to an isolation area and restricting the terminal device to be detected from accessing the network.
[0067] Specifically, to verify whether the terminal device to be detected has returned to a normal state or is still in an abnormal network environment, a connectivity detection can be performed on the above-mentioned terminal device to be detected again, and a second detection result is generated. When the second detection result indicates that the terminal device to be detected is already in a target location (intranet location or remote access location), at this time, a first access management policy or a second access management policy can be sent to the terminal device to be detected according to the location type of the target location, so as to restore its firewall rules and network access permissions. After receiving the access management policy, the terminal device to be detected executes the content in the access management policy and updates the firewall configuration to ensure that network access complies with the security requirements of the target location.
[0068] If the second detection result indicates that the location of the terminal device to be detected is still unknown, then the device is migrated to an isolation area, and the network access permission of the device is restricted, and only access to specific emergency servers is allowed, and security checks and troubleshooting are performed. At the same time, the network activities of the terminal device to be detected can also be detected. Once any abnormal behaviors are found, such as attempts to access unauthorized network resources, signs of network attacks, etc., measures such as disconnecting the network connection and starting in-depth security checks are taken to prevent the spread of potential security threats. This embodiment verifies the effectiveness of the emergency handling policy through re-detection of connectivity, and whether the terminal device to be detected has returned to a secure network environment. When the terminal device to be detected returns to the state of the target location, the timely restoration of the access control policy enables users to quickly resume normal work processes, reduces the impact of network failures on services, and improves service continuity and efficiency.
[0069] To avoid the problem of the failure of the location judgment mechanism, optionally, in the access control method for a terminal device provided in an embodiment of the present application, obtaining the terminal device to be detected includes: obtaining M financial management systems in the financial operation cluster to which the client management system belongs, where M is a positive integer; decoupling the M financial management systems from the client management system, and then performing the step of obtaining the terminal device to be detected.
[0070] Specifically, to enhance the comprehensive handling ability of the venue judgment system, multiple financial management systems in the financial operation cluster to which the client management system belongs are first identified and obtained. These systems are usually responsible for different business functions, such as account management, transaction processing, risk control, etc., but all have potential dependencies on the venue judgment control system. Then, the direct communication and dependencies between the client management system and the above-mentioned financial management systems are removed, and decoupling is achieved by modifying the venue judgment logic, adjusting the emergency handling strategy, and updating the firewall rules and network access control lists. Furthermore, the client management system can perform comprehensive judgment of the venue using a more independent and robust judgment logic. In this embodiment, by decoupling the financial management system from the client management system, the venue judgment logic and connectivity detection mechanism no longer depend on the financial management system or service, enhancing the independence of the client management system, making the emergency handling strategy more flexible, improving the efficiency of emergency handling. At the same time, the independent venue judgment logic can more accurately identify the network location of the terminal device to be detected, preventing potential security risks caused by misjudgment.
[0071] The embodiment of the present application also provides an access control method for a terminal device. Figure 3 It is a flowchart of an optional access control method for a terminal device provided according to the embodiment of the present application, as Figure 3 shown. The method includes:
[0072] When the terminal device to be detected within a financial institution attempts to enter the intranet venue, in order to determine the network environment where the terminal device to be detected is located and how to effectively restore network access permissions, first, when the terminal device to be detected within the financial institution starts up, the desktop management client attempts to establish a connection with the client management system. The client management system performs connectivity detection on the desktop management client software of the terminal device to be detected.
[0073] In the case where the connection result indicates that the terminal device to be detected can be connected, the client management system issues an access management policy associated with the intranet venue to the terminal device to be detected. At this time, the terminal device to be detected can send the policy execution status to the client management system according to the execution situation. At the same time, since the terminal device to be detected is in the intranet venue, after the terminal device to be detected enters the intranet venue, the firewall does not perform corresponding control, and it can access basic office applications.
[0074] When the connection result indicates that the terminal device to be detected cannot be connected, it is determined whether it is possible to enter the remote access location. If the conditions for remote access are met, the client management system sends the access management policy associated with the remote location to the terminal device to be detected. After receiving the access management policy for the remote access location, the terminal device to be detected enters the remote access location. At this time, the firewall of this location does not perform corresponding control, but the terminal device to be detected can only access the applications required for remote connection. If the terminal can neither be judged through the internal network location nor directly enter the remote access location, it indicates that the terminal may be in an unknown or abnormal state.
[0075] When the connection result indicates that the location of the terminal device to be detected is unknown, the client management system sends an emergency handling instruction to the terminal device to be detected, that is, to instruct the terminal device to be detected to start the emergency handling mechanism. After receiving the above instruction, the terminal device to be detected communicates with the client management system through a preset port for special communication, and at this time, an emergency handling request can be sent to the client management system. After receiving the emergency handling request, the client management system re-authenticates the terminal. If the authentication is passed, the legitimacy of the above terminal device is confirmed. At this time, the terminal device to be detected can return to the internal network location and restore normal access rights; if the authentication fails, the terminal device to be detected enters the isolation area, and the network access rights of the terminal device to be detected are strictly restricted and it cannot access any applications or services.
[0076] It should be noted that the terminal device to be detected that enters the isolation area will be further inspected to determine its status and security risks. If the terminal device to be detected is a secure terminal device, the location judgment process can be restarted to attempt normal access. If the terminal device to be detected has security problems, repairs or other security measures need to be taken until the problem is solved before it can be reconnected to the internal network or the remote access location.
[0077] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0078] Embodiment 2
[0079] The embodiment of the present application also provides an access control device for a terminal device. It should be noted that the access control device for the terminal device in the embodiment of the present application can be used to execute the access control method for the terminal device provided in the embodiment of the present application. The access control device for the terminal device provided in the embodiment of the present application is introduced below.
[0080] According to the embodiment of the present application, there is also provided a device for implementing the above-mentioned access control method for a terminal device.Figure 4 It is a schematic diagram of an access control device for a terminal device provided by an embodiment of the present application. As Figure 4 shown, the device includes: an acquisition unit 40, a first detection unit 41, a first transmission unit 42, and a second transmission unit 43.
[0081] The acquisition unit 40 is configured to acquire a terminal device to be detected and acquire the client software installed on the terminal device to be detected;
[0082] The first detection unit 41 is configured to perform a connectivity detection on the client software to obtain a first detection result, where the connectivity detection is used to determine whether the terminal device to be detected is in a target location;
[0083] The first transmission unit 42 is configured to send an access management policy to the terminal device to be detected when the first detection result indicates that the terminal device to be detected is in the target location, where the access management policy is used to indicate the network access permission of the terminal device to be detected in the target location;
[0084] The second transmission unit 43 is configured to send an emergency handling instruction to the terminal device to be detected when the first detection result indicates that the location of the terminal device to be detected is unknown, where the emergency handling instruction is used to instruct the terminal device to be detected to start an emergency handling mechanism.
[0085] The access control device for a terminal device provided by an embodiment of the present application acquires a terminal device to be detected through the acquisition unit 40 and acquires the client software installed on the terminal device to be detected; the first detection unit 41 performs a connectivity detection on the client software to obtain a first detection result, where the connectivity detection is used to determine whether the terminal device to be detected is in a target location; the first transmission unit 42 sends an access management policy to the terminal device to be detected when the first detection result indicates that the terminal device to be detected is in the target location, where the access management policy is used to indicate the network access permission of the terminal device to be detected in the target location; the second transmission unit 43 sends an emergency handling instruction to the terminal device to be detected when the first detection result indicates that the location of the terminal device to be detected is unknown, where the emergency handling instruction is used to instruct the terminal device to be detected to start an emergency handling mechanism, which solves the problem of low recognition accuracy in identifying the location of the terminal device to be detected in the related art. By performing a connectivity detection on the client software of the terminal device to be detected, when the detection result indicates that the terminal device to be detected is in the target location, an access management policy is sent to the terminal device to be detected; when the detection result indicates that the location of the terminal device to be detected is unknown, an emergency handling instruction is sent to the terminal device to be detected, thereby achieving the technical effects of optimizing the location judgment and emergency access process and enhancing the user experience and service continuity.
[0086] Optionally, in the access control device of the terminal device provided in the embodiments of the present application, the first detection unit 41 includes: a first acquisition module, configured to acquire preset parameters of a preset server, where the preset parameters include at least one of the following: address information of the preset server, port number, and domain name information; a first generation module, configured to generate a detection instruction according to the preset parameters and send the detection instruction to the client software; a sending module, configured to, when receiving a detection response fed back by the client software, send a preset command to the client software and monitor the client software, where the detection response is used to indicate that the client software has received the detection instruction, and the preset command is used to instruct the client software to establish a connection with the preset server; a second generation module, configured to, when receiving a first connection response fed back by the client software, generate a judgment result that the terminal device to be detected is in the target location, where the first connection response indicates that the client software has received a response fed back by the preset server within a preset time period; a third generation module, configured to, when receiving a second connection response fed back by the client software, generate a judgment result that the location of the terminal device to be detected is unknown, where the second connection response indicates that the client software has not received a response fed back by the preset server within a preset time period, or the preset server refuses to establish a connection with the client software.
[0087] Optionally, in the access control device of the terminal device provided in the embodiments of the present application, the first sending unit 42 includes: an identification module, configured to identify the location type of the target location, where the location type includes an intranet location and a remote access location; a second acquisition module, configured to, when the target location is an intranet location, acquire a first access management policy according to the intranet location and authenticate the terminal device to be detected; a push module, configured to, when the authentication of the terminal device to be detected is passed, push the first access management policy to the terminal device to be detected; a third acquisition module, configured to, when the target location is a remote access location, acquire a second access management policy according to the remote access location and, when the authentication of the terminal device to be detected is correct, push the second access management policy to the terminal device to be detected.
[0088] Optionally, in the access control device of the terminal device provided in the embodiments of the present application, the device further includes: a first receiving unit, configured to, after sending an access management policy to the terminal device to be detected, receive a policy execution result fed back by the terminal device to be detected, where the policy execution result is used to characterize the execution situation of the terminal device to be detected when executing the access management policy; an identification unit, configured to identify the policy execution result and, when the policy execution result indicates that there is an abnormality when the terminal device to be detected executes the access management policy, send an emergency processing instruction to the terminal device to be detected.
[0089] Optionally, in the access control device of the terminal device provided in the embodiments of the present application, the device further includes: a second receiving unit, configured to receive an authentication request initiated by the terminal device to be detected after sending an emergency processing instruction to the terminal device to be detected, where the authentication request includes the identification information of the terminal device to be detected and an emergency processing key; a verification unit, configured to authenticate the terminal device to be detected according to the identification information and the emergency processing key; a determination unit, configured to, when the identification information is verified to be passed, determine the terminal device to be detected as a device of a target location, and send an emergency processing policy to the terminal device to be detected, where, when the terminal device to be detected receives the emergency processing policy, adjust the firewall rules and network access permissions of the terminal device to be detected according to the emergency processing policy.
[0090] Optionally, in the access control device of the terminal device provided in the embodiments of the present application, the device further includes: a second detection unit, configured to re-perform a connectivity detection on the client software after sending an emergency processing policy to the terminal device to be detected, and obtain a second detection result; a recovery unit, configured to, when the second detection result indicates that the terminal device to be detected is in a target location, recover the firewall rules and network access permissions of the terminal device to be detected; a migration unit, configured to, when the second detection result indicates that the location of the terminal device to be detected is unknown, migrate the terminal device to be detected to an isolation area and restrict the terminal device to be detected from accessing the network.
[0091] Optionally, in the access control device of the terminal device provided in the embodiments of the present application, the obtaining unit 40 includes: a fourth obtaining module, configured to obtain M financial management systems in the financial operation cluster to which the client management system belongs, where M is a positive integer; a decoupling module, configured to decouple the M financial management systems from the client management system and perform the step of obtaining the terminal device to be detected.
[0092] It should be noted here that the above-mentioned obtaining unit 40, the first detection unit 41, the first sending unit 42, and the second sending unit 43 correspond to steps S201 to S204 in Embodiment 1. The examples and application scenarios implemented by the two modules and the corresponding steps are the same, but are not limited to the content disclosed in the above-mentioned Embodiment 1. It should be noted that the above-mentioned modules or units may be hardware components or software components stored in a memory (for example, the memory 104) and processed by one or more processors (for example, the processors 102a, 102b,..., 102n), and the above-mentioned units may also be part of the device and may run in the computer terminal 10 provided in Embodiment 1.
[0093] Embodiment 3
[0094] Embodiments of the present application may provide a computer terminal, which may be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the above computer terminal may also be replaced with a mobile terminal or other terminal devices such as electronic devices.
[0095] Optionally, in this embodiment, the above computer terminal may be located in at least one of multiple network devices in a computer network.
[0096] In this embodiment, the above computer terminal may execute the program code of the following steps in the access control method for terminal devices: obtaining a terminal device to be detected, and obtaining the client software installed on the terminal device to be detected; performing a connectivity detection on the client software to obtain a first detection result, where the connectivity detection is used to determine whether the terminal device to be detected is in a target location; in the case where the first detection result indicates that the terminal device to be detected is in the target location, sending an access management policy to the terminal device to be detected, where the access management policy is used to indicate the network access permission of the terminal device to be detected in the target location; in the case where the first detection result indicates that the location of the terminal device to be detected is unknown, sending an emergency handling instruction to the terminal device to be detected, where the emergency handling instruction is used to instruct the terminal device to be detected to start an emergency handling mechanism.
[0097] Optionally, the above computer terminal may execute the program code of the following steps in the access control method for terminal devices: obtaining preset parameters of a preset server, where the preset parameters at least include one of the following: address information of the preset server, port number, and domain name information; generating a detection instruction according to the preset parameters, and sending the detection instruction to the client software; in the case of receiving a detection response feedback from the client software, sending a preset command to the client software and monitoring the client software, where the detection response is used to indicate that the client software has received the detection instruction, and the preset command is used to instruct the client software to establish a connection with the preset server; in the case of receiving a first connection response feedback from the client software, generating a judgment result that the terminal device to be detected is in the target location, where the first connection response indicates that the client software has received a response feedback from the preset server within a preset time period; in the case of receiving a second connection response feedback from the client software, generating a judgment result that the location of the terminal device to be detected is unknown, where the second connection response indicates that the client software has not received a response feedback from the preset server within a preset time period, or the preset server refuses to establish a connection with the client software.
[0098] Optionally, the above computer terminal may execute the program code of the following steps in the access control method of the terminal device: identify the venue type of the target venue, where the venue type includes an intranet venue and a remote access venue; in the case that the target venue is an intranet venue, obtain the first access management policy according to the intranet venue, and authenticate the terminal device to be detected; in the case that the terminal device to be detected passes the authentication, push the first access management policy to the terminal device to be detected; in the case that the target venue is a remote access venue, obtain the second access management policy according to the remote access venue, and push the second access management policy to the terminal device to be detected in the case that the terminal device to be detected is verified without error.
[0099] Optionally, the above computer terminal may execute the program code of the following steps in the access control method of the terminal device: receive the policy execution result fed back by the terminal device to be detected, where the policy execution result is used to characterize the execution situation of the access management policy by the terminal device to be detected; identify the policy execution result, and in the case that the policy execution result characterizes that there is an abnormality in the execution of the access management policy by the terminal device to be detected, send an emergency handling instruction to the terminal device to be detected.
[0100] Optionally, the above computer terminal may execute the program code of the following steps in the access control method of the terminal device: receive the authentication request initiated by the terminal device to be detected, where the authentication request includes the identification information of the terminal device to be detected and the emergency handling key; authenticate the terminal device to be detected according to the identification information and the emergency handling key; in the case that the identification information passes the authentication, determine the terminal device to be detected as the device of the target venue, and send an emergency handling policy to the terminal device to be detected, where in the case that the terminal device to be detected receives the emergency handling policy, adjust the firewall rules and network access permissions of the terminal device to be detected according to the emergency handling policy.
[0101] Optionally, the above computer terminal may execute the program code of the following steps in the access control method of the terminal device: re-perform the connectivity detection on the client software to obtain a second detection result; in the case that the second detection result characterizes that the terminal device to be detected is in the target venue, restore the firewall rules and network access permissions of the terminal device to be detected; in the case that the second detection result characterizes that the venue of the terminal device to be detected is unknown, migrate the terminal device to be detected to the isolation area and restrict the terminal device to be detected from accessing the network.
[0102] Optionally, the above computer terminal may execute the program code of the following steps in the access control method of the terminal device: obtain M financial management systems in the financial operation cluster to which the client management system belongs, where M is a positive integer; decouple the M financial management systems from the client management system, and execute the step of obtaining the terminal device to be detected.
[0103] Optionally, Figure 5 is a block diagram of a structure of an electronic device according to an embodiment of the present application. As Figure 5 shown, the electronic device may include: one or more ( Figure 5 only one is shown in the figure) processors 502, a memory 504, a storage controller, and a peripheral interface, wherein the peripheral interface is connected to a radio frequency module, an audio module, and a display.
[0104] Among them, the memory can be used to store software programs and modules, such as program instructions / modules corresponding to the access control method and device of the terminal device in the embodiment of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the above-mentioned access control method of the terminal device. The memory may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely disposed relative to the processor, and these remote memories may be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0105] The processor may call the information and application programs stored in the memory through a transmission device to execute the above steps in the access control method of the terminal device.
[0106] By adopting the embodiment of the present application, a solution for access control of a terminal device is provided. By obtaining a terminal device to be detected and obtaining client software installed on the terminal device to be detected; performing a connectivity detection on the client software to obtain a first detection result, wherein the connectivity detection is used to determine whether the terminal device to be detected is in a target location; in the case where the first detection result indicates that the terminal device to be detected is in the target location, sending an access management policy to the terminal device to be detected, wherein the access management policy is used to indicate the network access permission of the terminal device to be detected in the target location; in the case where the first detection result indicates that the location of the terminal device to be detected is unknown, sending an emergency processing instruction to the terminal device to be detected, wherein the emergency processing instruction is used to instruct the terminal device to be detected to start an emergency processing mechanism, thereby achieving the purpose of enhancing the accuracy and flexibility of location determination and realizing the emergency access of the terminal device to be detected, and further solving the problem of low recognition accuracy when identifying the location of the terminal device to be detected.
[0107] Those of ordinary skill in the art can understand, Figure 5The structure shown is only schematic, and the electronic device can also be a terminal device such as a smart phone, a tablet computer, a personal digital assistant, and Mobile Internet Devices (MID), PAD, etc. Figure 5 It does not limit the structure of the above-mentioned electronic device. For example, the electronic device may further include more or fewer components (such as a network interface, a display device, etc.) than those shown Figure 5 in the figure, or have a different configuration from that shown Figure 5 in the figure.
[0108] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium. The storage medium may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disc, etc.
[0109] Embodiment 4
[0110] An embodiment of the present application further provides a storage medium. Optionally, in this embodiment, the above storage medium can be used to store the program code executed by the access control method of the terminal device provided in the first embodiment above.
[0111] Optionally, in this embodiment, the above storage medium may be located in any one of the computer terminals in the computer terminal group in the computer network, or in any one of the mobile terminals in the mobile terminal group.
[0112] Optionally, in this embodiment, the storage medium is set to store program code for performing the following steps: obtaining a terminal device to be detected, and obtaining the client software installed on the terminal device to be detected; performing a connectivity detection on the client software to obtain a first detection result, where the connectivity detection is used to determine whether the terminal device to be detected is in a target location; in the case where the first detection result indicates that the terminal device to be detected is in the target location, sending an access management policy to the terminal device to be detected, where the access management policy is used to indicate the network access permission of the terminal device to be detected in the target location; in the case where the first detection result indicates that the location of the terminal device to be detected is unknown, sending an emergency processing instruction to the terminal device to be detected, where the emergency processing instruction is used to instruct the terminal device to be detected to start an emergency processing mechanism.
[0113] The present application further provides a computer program product, which is suitable for executing a program of the steps of the access control method of the terminal device when executed on a data processing device.
[0114] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.
[0115] In the above embodiments of the present application, the descriptions of the respective embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0116] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0117] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0118] In addition, the functional units in the various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0119] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. And the foregoing storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks or optical disks and other various media that can store program codes.
[0120] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A method for controlling access to a terminal device, characterized in that: Applied to client management systems, including: Obtaining a terminal device to be detected, and obtaining client software installed on the terminal device to be detected; Performing a connectivity test on the client software to obtain a first test result, wherein the connectivity test is used to determine whether the terminal device to be tested is in a target location; In the case where the first detection result indicates that the terminal device to be detected is in the target location, sending an access management policy to the terminal device to be detected, wherein the access management policy is used to indicate the authority of the terminal device to be detected to perform network access at the target location; When the first detection result indicates that the location of the terminal device to be detected is unknown, an emergency processing instruction is sent to the terminal device to be detected, wherein the emergency processing instruction is used to instruct the terminal device to be detected to start an emergency processing mechanism.
2. The method according to claim 1, characterized in that Performing a connectivity test on the client software to obtain a first test result includes: Acquire preset parameters of a preset server, wherein the preset parameters include at least one of the following: address information, port number, and domain name information of the preset server; Generate a detection instruction according to the preset parameters, and send the detection instruction to the client software; In the case of receiving a detection response fed back by the client software, sending a preset command to the client software and monitoring the client software, wherein the detection response is used to indicate that the client software has received the detection instruction, and the preset command is used to instruct the client software to establish a connection with a preset server; In the case of receiving a first connection response fed back by the client software, generating a judgment result that the terminal device to be detected is in the target location, wherein the first connection response indicates that the client software receives a response fed back by the preset server within a preset time period; When a second connection response is received from the client software, a judgment result is generated that the location of the terminal device to be detected is unknown, wherein the second connection response indicates that the client software has not received a response from the preset server within the preset time period, or the preset server refuses to establish a connection with the client software.
3. The method according to claim 1, characterized in that Sending the access management policy to the terminal device to be detected includes: Identifying a location type of the target location, wherein the location type includes an intranet location and a remote access location; In the case where the target location is the intranet location, obtaining a first access management policy according to the intranet location, and performing identity authentication on the terminal device to be detected; When the terminal device to be detected passes the verification, pushing the first access management policy to the terminal device to be detected; In the case that the target place is the remote access place, a second access management policy is obtained according to the remote access place, and in the case that the terminal device to be detected is verified to be correct, the second access management policy is pushed to the terminal device to be detected.
4. The method according to claim 1, characterized in that: After sending the access management policy to the terminal device to be detected, the method further includes: Receiving a policy execution result fed back by the terminal device to be detected, wherein the policy execution result is used to characterize the execution status of the access management policy executed by the terminal device to be detected; The policy execution result is identified, and when the policy execution result indicates that an abnormality exists when the terminal device to be detected executes the access management policy, the emergency processing instruction is sent to the terminal device to be detected.
5. The method according to claim 1, characterized in that After sending the emergency processing instruction to the terminal device to be detected, the method further includes: Receiving an authentication request initiated by the terminal device to be detected, wherein the authentication request includes identification information of the terminal device to be detected and an emergency processing key; Performing identity authentication on the terminal device to be detected according to the identification information and the emergency processing key; When the identification information is verified, the terminal device to be detected is determined as a device at the target location, and an emergency processing strategy is sent to the terminal device to be detected, wherein, when the terminal device to be detected receives the emergency processing strategy, the firewall rules and network access rights of the terminal device to be detected are adjusted according to the emergency processing strategy.
6. The method according to claim 5, characterized in that After sending the emergency handling strategy to the terminal device to be detected, the method further includes: Re-testing the connectivity of the client software to obtain a second test result; If the second detection result indicates that the terminal device to be detected is in the target location, restoring the firewall rules and the network access rights of the terminal device to be detected; When the second detection result indicates that the location of the terminal device to be detected is unknown, the terminal device to be detected is moved to an isolation area, and network access by the terminal device to be detected is restricted.
7. The method according to claim 1, characterized in that Obtaining the terminal device to be detected includes: Obtain M financial management systems in the financial operation cluster to which the client management system belongs, where M is a positive integer; The M financial management systems are decoupled from the client management system, and the step of obtaining the terminal device to be detected is performed.
8. An access control device for a terminal device, characterized in that: include: An acquisition unit, used to acquire a terminal device to be detected and acquire client software installed on the terminal device to be detected; A first detection unit, configured to perform a connectivity detection on the client software to obtain a first detection result, wherein the connectivity detection is used to determine whether the terminal device to be detected is in a target location; A first sending unit, configured to send an access management policy to the terminal device to be detected when the first detection result indicates that the terminal device to be detected is in the target location, wherein the access management policy is used to indicate the authority of the terminal device to be detected to perform network access at the target location; The second sending unit is used to send an emergency processing instruction to the terminal device to be detected when the first detection result indicates that the location of the terminal device to be detected is unknown, wherein the emergency processing instruction is used to instruct the terminal device to be detected to start an emergency processing mechanism.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored executable program, wherein when the executable program is run, the device where the computer-readable storage medium is located is controlled to execute the access control method for the terminal device according to any one of claims 1 to 7.
10. An electronic device, characterized in that: include: A memory storing an executable program; A processor is used to run the program, wherein the program executes the access control method for the terminal device described in any one of claims 1 to 7 when running.
11. A computer program product comprising computer instructions, characterized in that: When the computer instructions are executed by a processor, the steps of the terminal device access control method described in any one of claims 1 to 7 are implemented.