Security authentication method and device for equipment access network, equipment and medium
By determining the device characteristic value and key pair based on the device physical information in the terminal device, and generating the device authentication certificate through random number signature verification, the problem of insufficient security of device access network in the prior art is solved, and higher security and data protection are achieved.
Patent Information
- Application Number
- CN202510411379.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-06-17
AI Technical Summary
The security authentication method for existing devices to access the network has the threat of easy leakage of identity credentials, risk of counterfeiting, and the "connection first and authentication" mechanism that business servers are exposed to open networks, resulting in threats to the security of the enterprise's intranet.
By determining the device characteristic value and device key pair based on device physical information in the terminal device, the preset registration process is performed to obtain the device identity credentials, and when the device has been registered, the device authentication credentials are generated through the client and server random number signature verification, and finally the identity verification is carried out through the identity admission ticket access security gateway.
It improves the security of equipment access network, reduces the risk of illegal equipment accessing enterprise networks, and provides solid guarantees for enterprise data security.
Smart Images

Figure CN120165878A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of identity authentication, and in particular to a method, device, equipment and medium for secure authentication of device access to a network. Background Art
[0002] In the existing security authentication schemes for device access to the network, static authentication methods based on the physical characteristics of the device combined with usernames and passwords are generally used. However, this method has inherent defects such as easy leakage of identity credentials and high risk of counterfeiting. In addition, the existing network access methods generally adopt a "connect first, then authenticate" mechanism, that is, the terminal must first establish a communication connection with the business server, and then perform the identity authentication process. In this process, the business server needs to be exposed to the open network for a long time, and attackers can use the unauthenticated initial connection as a springboard to launch man-in-the-middle attacks or network penetration, further threatening the security of the enterprise intranet.
[0003] From the above, it can be seen that how to improve the security of devices in the process of accessing the network is a technical problem that needs to be solved urgently. Summary of the invention
[0004] In view of this, the purpose of the present invention is to provide a security authentication method for device access to a network, which can improve the security of the device access to the network. The specific scheme is as follows:
[0005] In a first aspect, the present application provides a method for secure authentication of a device accessing a network, which is applied to a terminal device including security authentication software to be accessed to a target network, comprising:
[0006] When the device registration status is unregistered, when the current device environment meets the preset environment trust condition, the device characteristic value and the device key pair are determined based on the device physical information, and the device characteristic value and the device key pair are used to perform the preset registration process, so that the authentication controller issues a device identity certificate to the terminal device; wherein the device registration status is determined according to the identity information of whether the terminal device has been registered in the authentication controller; the device identity certificate is a certificate containing the device characteristic value and the device public key in the device key pair;
[0007] When the device registration status is registered, a client random number is generated, so that the authentication controller signs the client random number to obtain a first signature value and generates a server random number;
[0008] Obtaining the first signature value and the server random number sent by the authentication controller, and verifying the first signature value. After the verification is passed, signing the server random number, and transmitting the device authentication credential determined based on the obtained second signature value to the authentication controller, so that the authentication controller generates an identity access ticket based on the device authentication credential;
[0009] Based on the identity access ticket, access the security gateway so that the security gateway verifies the identity access ticket and the device trusted status through the authentication controller and obtains an identity authentication result;
[0010] When the identity authentication result indicates successful verification, access the target network.
[0011] Optionally, when the current device environment meets the preset environment trust conditions, determining the device feature value and the device key pair based on the device physical information includes:
[0012] Judge whether the credibility of the current device environment meets the preset environment trust conditions and obtain a credibility judgment result;
[0013] If the credibility judgment result indicates satisfaction, collect the device physical information through the data collection component in the security authentication software to complete the information collection operation;
[0014] Calculate the device feature value using the device physical information and generate a device key pair.
[0015] Optionally, performing a preset registration process using the device feature value and the device key pair includes:
[0016] Sign the device feature value using the device private key in the device key pair and obtain a corresponding third signature value;
[0017] Determine the device feature value, the third signature value, and the device public key in the device key pair as device identity information;
[0018] Transmit the device identity information to the authentication controller so that the authentication controller checks the device registration status based on the device feature value in the device identity information, and when the device registration status is unregistered, issue a device identity credential for the terminal device based on the device identity information.
[0019] Optionally, verifying the first signature value, after successful verification, signing the server random number, and transmitting the device authentication credential determined based on the obtained second signature value to the authentication controller includes:
[0020] Verify the first signature value using the device public key and obtain a verification result;
[0021] When the verification result indicates successful verification, sign the server random number using the device private key to obtain a second signature value;
[0022] Determine a device authentication credential based on the second signature value, and transmit the device authentication credential to the authentication controller.
[0023] In a second aspect, the present application provides a security authentication method for a device to access a network, which is applied to a server including an authentication controller, and includes:
[0024] Obtain a device feature value and a device public key sent by a terminal device, verify the device registration status based on the device feature value, and when the device registration status is unregistered, register the terminal device that has executed a preset registration process to issue a device identity credential for the terminal device; wherein, the device feature value and the device public key are the device feature value and the device key pair determined by the terminal device based on device physical information when the device registration status is unregistered and the current device environment meets preset trusted conditions; the device registration status is the status determined according to whether the identity information of the terminal device has been registered in the authentication controller; the device identity credential is a credential containing the device feature value and the device public key in the device key pair;
[0025] Obtain the client random number sent by the terminal device, sign the client random number with the authentication controller private key to obtain a first signature value and generate a server random number, and send the first signature value and the server random number to the terminal device; wherein, the client random number is a random number generated when the device registration status of the terminal device is registered;
[0026] Obtain the device authentication credential sent by the terminal device, verify the device authentication credential with the device public key, and when the device authentication credential passes the authentication, generate an identity access ticket and send the identity access ticket to the terminal device; wherein, the device authentication credential is the device authentication credential determined by the terminal device based on the second signature value; the second signature value is the signature value obtained after the terminal device signs the server random number after verifying the first signature value;
[0027] After the terminal device accesses the security gateway based on the identity access ticket, verify the identity access ticket and the device trusted status, and obtain an identity verification result;
[0028] When the identity verification result indicates that the verification is passed, allow the terminal device to access the target network.
[0029] Optionally, the verifying the identity access ticket and the device trusted status and obtaining an identity verification result includes:
[0030] Verify the identity access ticket to obtain a first verification result;
[0031] Obtain the device attribute information and device status information collected by the security authentication software in the terminal device, and determine the device attribute information and the device status information as the first trust evaluation information;
[0032] Based on the first trust evaluation information, judge whether the current trusted state of the terminal device meets the preset state trusted condition, and obtain a second verification result;
[0033] Determine the identity authentication result based on the first verification result and the second verification result.
[0034] Optionally, the security authentication method for a device to access a network further includes:
[0035] During the process of the terminal device accessing the target network, obtain the device attribute information, device status information, device login information, and resource access information collected by the security authentication software in the terminal device, and determine the device attribute information, the device status information, the device login information, and the resource access information as the second trust evaluation information;
[0036] Based on the second trust evaluation information, judge whether the current trusted state of the terminal device meets the preset state trusted condition, and obtain a trust judgment result;
[0037] If the trust judgment result indicates non - satisfaction, revoke the identity admission ticket of the terminal device and prohibit the terminal device from accessing the target network.
[0038] In a third aspect, the present application provides a security authentication device for a device to access a network, which is applied to a terminal device including security authentication software to be connected to a target network, and includes:
[0039] A device registration module, configured to, when the device registration status is unregistered, based on the device physical information, determine a device feature value and a device key pair when the current device environment meets the preset trusted condition, and execute a preset registration process using the device feature value and the device key pair, so that the authentication controller issues a device identity certificate for the terminal device; wherein, the device registration status is a status determined according to whether the identity information of the terminal device has been registered in the authentication controller; the device identity certificate is a certificate containing the device feature value and the public key of the device in the device key pair;
[0040] A random number generation module, configured to, when the device registration status is registered, generate a client random number, so that the authentication controller signs the client random number to obtain a first signature value and generate a server random number;
[0041] An authentication credential generation module, configured to obtain a first signature value and the server random number sent by an authentication controller, verify the first signature value, and upon successful verification, sign the server random number and transmit the device authentication credential determined based on the obtained second signature value to the authentication controller, so that the authentication controller generates an identity access ticket based on the device authentication credential;
[0042] An information verification module, configured to access a security gateway based on the identity access ticket, so that the security gateway verifies the identity access ticket and the device trusted status through the authentication controller and obtains an identity verification result;
[0043] A network access module, configured to access the target network when the identity verification result indicates successful verification.
[0044] In a fourth aspect, the present application provides an electronic device, including:
[0045] A memory, configured to store a computer program;
[0046] A processor, configured to execute the computer program to implement the foregoing security authentication method for device access to a network.
[0047] In a fifth aspect, the present application provides a computer-readable storage medium, configured to store a computer program; wherein, when the computer program is executed by a processor, the foregoing security authentication method for device access to a network is implemented.
[0048] In this application, for a terminal device including security authentication software that is to be connected to a target network, when the device registration status is unregistered, if the current device environment meets the preset environment trust conditions, the device characteristic value and the device key pair are determined based on the device physical information, and a preset registration process is executed using the device characteristic value and the device key pair, so that the authentication controller issues a device identity credential for the terminal device; wherein, the device registration status is determined according to whether the identity information of the terminal device has been registered in the authentication controller; the device identity credential is a credential containing the device characteristic value and the public key of the device key pair; when the device registration status is registered, a client random number is generated, so that the authentication controller signs the client random number to obtain a first signature value and generates a server random number; the first signature value and the server random number sent by the authentication controller are obtained, the first signature value is verified, and after the verification passes, the server random number is signed, and the device authentication credential determined based on the obtained second signature value is transmitted to the authentication controller, so that the authentication controller generates an identity access ticket based on the device authentication credential; access the security gateway based on the identity access ticket, so that the security gateway verifies the identity access ticket and the device trust status through the authentication controller and obtains an identity verification result; when the identity verification result indicates that the verification is passed, access the target network. As can be seen from the above, when the device registration status of the terminal device in this application is unregistered and the current device environment meets the preset environment trust conditions, the device characteristic value and the device key pair are determined based on the device physical information, and then a preset registration process is executed using the device characteristic value and the device key pair, and the authentication controller will issue a device identity credential containing the device characteristic value and the public key of the device for the terminal device. If the device registration status is registered, the terminal device generates a client random number, so that the authentication controller signs it to obtain a first signature value and generates a server random number. After the terminal device obtains the first signature value and the server random number, the first signature value is verified. After the verification passes, the server random number is signed, the device authentication credential is determined based on the obtained second signature value and transmitted to the authentication controller, so that the authentication controller generates an identity access ticket accordingly. The terminal device accesses the security gateway with the identity access ticket, and the security gateway verifies the identity access ticket and the device trust status through the authentication controller to obtain an identity verification result. If the identity verification result is passed, the terminal device can access the target network. In this way, this application can improve the security during the process of device accessing the network, thus effectively resisting the access of illegal devices to the enterprise network and providing a solid guarantee for the data security of the enterprise. Brief Description of the Drawings
[0049] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on the provided drawings.
[0050] Figure 1 It is a schematic diagram of the system architecture of a security authentication solution for device access to a network disclosed in the present application;
[0051] Figure 2 It is a flowchart of a security authentication method for device access to a network of a terminal device including security authentication software applied to a target network to be accessed;
[0052] Figure 3 It is a schematic diagram of the flowchart of a specific security authentication method for device access to a network disclosed in the present application;
[0053] Figure 4 It is a schematic diagram of the flowchart of a security authentication method for device access to a network of a server including an authentication controller applied in the present application;
[0054] Figure 5 It is a schematic diagram of the structure of a security authentication device for device access to a network of a terminal device including security authentication software applied to a target network to be accessed;
[0055] Figure 6 It is a schematic diagram of the structure of a security authentication device for device access to a network of a server including an authentication controller applied in the present application;
[0056] Figure 7 It is a structural diagram of an electronic device disclosed in the present application. Detailed implementation manners
[0057] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0058] In the existing security authentication schemes for devices to access the network, a static authentication method based on the combination of device physical characteristics and username / password is generally adopted. However, such methods have inherent defects such as easy leakage of identity credentials and high risks of impersonation. Moreover, the existing network access methods generally adopt the "connect first and then authenticate" mechanism, that is, the terminal needs to first establish a communication connection with the service server and then execute the identity authentication process. During this process, the service server needs to be exposed to the open network for a long time, and attackers can use the unauthenticated initial connection as a springboard to launch man-in-the-middle attacks or network penetrations, further threatening the security of the enterprise internal network. Therefore, this application provides a security authentication method for devices to access the network, which can improve the security during the process of device accessing the network.
[0059] The system architecture adopted by the security authentication scheme for devices to access the network in this application can be referred to Figure 1 as shown, and specifically can include terminal device 01, security gateway 02, authentication controller 03, and business application 04. In addition, it should be noted that the security authentication software is included in the terminal device 01, that is, the security authentication client software; the authentication controller 03 is in the server; the business application 04 is in the target network.
[0060] Specifically, the security authentication software in the terminal device 01 can be installed internally in various terminal devices such as a PC (i.e., Personal Computer), tablet, and smart phone. And the security authentication software contains many modules. One is the device management module, which provides functions such as collection of terminal device physical information, calculation of device characteristic values, and online registration of devices; the second is the device authentication module, which provides security authentication based on keys before the terminal device accesses the enterprise network; the third is the device data collection, which provides the ability to collect terminal information such as device dynamic status, security status, and network status; the fourth is the device network communication module, which provides the ability for the device to securely access the enterprise network after the device authentication is passed; the fifth is the software password module, which provides functions such as generation, storage, operation, and export of symmetric and asymmetric cryptography keys for the client, and the private key cannot be exported.
[0061] Since most of the security authentication processes involved in this application are implemented based on the terminal device 01 and the authentication controller 03, correspondingly, the authentication controller 03 also contains many modules. One is the device management module, which has the ability to manage the entire life cycle of devices, such as managing the identity information of trusted devices, device identity credentials, device status, and device authentication policies; the second is the device credential issuance module, which can, after a trusted device is registered, provide the device with over-the-air online issuance of device identity credentials by docking with external password support systems such as certificate management and key management; the third is the device authentication module, which provides various device identity authentication and verification capabilities for the device; the fourth is the dynamic trust assessment module, which conducts trust assessment and generates access control security policies based on device attributes, security attributes, network status, and network traffic collected from the device data.
[0062] Specifically, the dynamic trust assessment module in the authentication controller 03 includes a device behavior data and status collection module, a data storage module, a data analysis module, and a dynamic data trust assessment module. Among them, the device behavior and status data collection module mainly collects device-related data through the security client data collection module, the data storage module mainly stores the collected structured and unstructured data, the device data analysis and calculation module calculates the collected data and analyzes the device behavior and device status in real time, and the dynamic data trust assessment module performs rule verification on the calculation results and performs risk control operations in a timely manner when certain rule conditions are met.
[0063] The security gateway 02 can forward the service data stream or the authentication control stream to the authentication controller according to the rules. The service application 04 is a service application system that can provide services for different terminals.
[0064] See Figure 2 and Figure 3 As shown in
[0065] Step S11: When the device registration status is unregistered, if the current device environment meets the preset environment trust conditions, determine the device feature value and the device key pair based on the device physical information, and execute the preset registration process using the device feature value and the device key pair, so that the authentication controller issues a device identity credential for the terminal device; wherein, the device registration status is determined according to whether the identity information of the terminal device has been registered in the authentication controller; the device identity credential is a credential containing the device feature value and the public key of the device in the device key pair.
[0066] In this embodiment, it is determined whether the credibility of the current device environment meets the preset environment credibility condition, and a credibility judgment result is obtained. This judgment process can be based on the environment detection rules built into the security authentication software. Specifically, the security authentication software can check the status of the operating system of the terminal device. For example, it checks whether there are unpatched serious security vulnerabilities in the operating system. If there are a large number of high-risk vulnerabilities, it is considered that the credibility of the device environment is low.
[0067] In a specific implementation manner, if the credibility judgment result indicates satisfaction, the data collection component in the security authentication software is used to collect the device physical information to complete the information collection operation. During the process of collecting the device physical information, for a computer device, its hardware information such as CPU model, motherboard model, and hard disk serial number can be collected; for a mobile device, such as a smart phone or a tablet computer, physical characteristic information such as the device's IMEI (i.e., International Mobile Equipment Identity), MAC (i.e., Media Access Control) address, and processor model can be collected. These collected device physical information can comprehensively reflect the physical characteristics of the terminal device.
[0068] After obtaining the device physical information, the device physical information is used to calculate the device feature value and generate a device key pair. During the process of calculating the device feature value, the collected device physical information can be comprehensively processed and hashed to obtain a unique device feature value, which can represent the identity of the terminal device. At the same time, through the software password module built into the security authentication software, a pair of device key pairs can be generated, including a device public key and a device private key. Among them, the device private key cannot be exported, that is, the client cannot extract the private key from the environment where the software password module is located and transfer it to other locations or devices through normal operation processes or interfaces, and it is only held and used locally.
[0069] Furthermore, the device private key in the device key pair is used to sign the device feature value, and a corresponding third signature value is obtained. The device feature value, the third signature value, and the device public key in the device key pair are determined as the device identity information. Finally, the device identity information is transmitted to the authentication controller, so that the authentication controller can check the device registration status based on the device feature value in the device identity information, and when the device registration status is unregistered, issue a device identity certificate for the terminal device based on the device identity information.
[0070] Step S12: When the device registration status is registered, a client random number is generated, so that the authentication controller signs the client random number to obtain a first signature value and generates a server random number.
[0071] In this embodiment, when the device registration status is registered, the security authentication software inside the terminal device will start the operation of generating a client random number. This client random number has randomness and unpredictability. After generating the client random number, the terminal device will quickly transmit it to the authentication controller so that the authentication controller can sign the client random number to obtain a first signature value and generate a server random number.
[0072] Step S13: Obtain the first signature value and the server random number sent by the authentication controller, verify the first signature value, and after the verification passes, sign the server random number, and transmit the device authentication credential determined based on the obtained second signature value to the authentication controller so that the authentication controller can generate an identity access ticket based on the device authentication credential.
[0073] In this embodiment, after obtaining the first signature value and the server random number sent by the authentication controller, the first signature value is verified. Specifically, using the device public key obtained and saved during the previous registration process, the terminal device verifies the first signature value according to the established signature verification algorithm and obtains a verification result.
[0074] When the verification result indicates that the verification passes, it means that the identity of the authentication controller is trustworthy and the client random number has not been tampered with during the transmission process. At this time, use the device private key to sign the server random number to obtain a second signature value. Then, determine the device authentication credential based on the second signature value and transmit the device authentication credential to the authentication controller so that the authentication controller can generate an identity access ticket based on the device authentication credential. Among them, the device authentication credential represents that the terminal device has passed the preliminary identity verification and has the qualification to further request access to the target network.
[0075] Step S14: Access the security gateway based on the identity access ticket so that the security gateway can verify the identity access ticket and the device trusted status through the authentication controller and obtain an identity verification result.
[0076] In this embodiment, after obtaining the identity access ticket, it will attempt to access the security gateway based on the identity access ticket. After the terminal device sends the identity access ticket to the security gateway, the security gateway will immediately transmit the identity access ticket and the relevant information of the device to the authentication controller so that the security gateway can verify the identity access ticket and the device trusted status through the authentication controller and obtain an identity verification result.
[0077] Step S15: When the identity verification result indicates that the verification passes, access the target network.
[0078] In this embodiment, when the authentication result indicates successful authentication, it means that the identity of the terminal device is legal, the terminal device is in a trusted state, and it has the qualification to access the target network. At this time, the security gateway will open an access channel for the terminal device to allow it to access the target network. After the terminal device accesses the target network, it can normally interact with enterprise business applications to obtain the required services and resources.
[0079] As can be seen from the above, when the device registration status of the terminal device in this application is unregistered and the current device environment meets the preset environment trust conditions, the device characteristic value and the device key pair are determined based on the device physical information, and then the preset registration process is executed using the device characteristic value and the device key pair. The authentication controller will issue a device identity certificate containing the device characteristic value and the device public key to the terminal device. If the device registration status is registered, the terminal device generates a client random number so that the authentication controller can sign it to obtain the first signature value and generate a server random number. After the terminal device obtains the first signature value and the server random number, it verifies the first signature value. After successful verification, it signs the server random number, determines the device authentication certificate based on the obtained second signature value, and transmits it to the authentication controller so that the authentication controller can generate an identity access ticket accordingly. When the terminal device accesses the security gateway with the identity access ticket, the security gateway verifies the identity access ticket and the device trusted state through the authentication controller to obtain the identity authentication result. If the identity authentication result is passed, the terminal device can access the target network. In this way, this application can improve the security during the device access to the network, effectively resist the access of illegal devices to the enterprise network, and provide a solid guarantee for the data security of the enterprise.
[0080] See Figure 4 As shown, the embodiment of this application also provides a security authentication method for device access to the network, which is applied to a server including an authentication controller, and includes:
[0081] Step S21: Obtain the device characteristic value and the device public key sent by the terminal device, check the device registration status based on the device characteristic value, and when the device registration status is unregistered, register the terminal device that has executed the preset registration process to issue a device identity certificate for the terminal device; wherein, the device characteristic value and the device public key are the device characteristic value and the device key pair determined by the terminal device based on the device physical information when the device registration status is unregistered and the current device environment meets the preset trust conditions; the device registration status is the situation determined according to whether the identity information of the terminal device has been registered in the authentication controller; the device identity certificate is a certificate containing the device characteristic value and the device public key in the device key pair.
[0082] Step S22: Obtain the client random number sent by the terminal device, sign the client random number using the private key of the authentication controller to obtain the first signature value, generate a server random number, and send the first signature value and the server random number to the terminal device; wherein, the client random number is a random number generated when the device registration status of the terminal device is registered.
[0083] Step S23: Obtain the device authentication credential sent by the terminal device, verify the device authentication credential using the device public key, and generate an identity access ticket when the device authentication credential passes the authentication, and send the identity access ticket to the terminal device; wherein, the device authentication credential is a device authentication credential determined by the terminal device based on the second signature value; the second signature value is a signature value obtained after the terminal device signs the server random number after verifying the first signature value.
[0084] Among them, the specific implementation processes of steps S21, S22, and S23 can refer to the corresponding content disclosed in the foregoing embodiments, and will not be elaborated herein.
[0085] Step S24: After the terminal device accesses the security gateway based on the identity access ticket, verify the identity access ticket and the device trusted status, and obtain an identity verification result.
[0086] In this embodiment, the authentication controller verifies the identity access ticket to obtain a first verification result. At the same time, obtain the device attribute information and device status information collected by the security authentication software in the terminal device, and determine the device attribute information and device status information as the first trust evaluation information. Among them, the device attribute information includes the hardware configuration, operating system version, software installation status, etc. of the device, and these information can reflect the basic characteristics of the device. The device status information includes the running status, network connection status, etc. of the device, reflecting the current real-time status of the device.
[0087] Further, judge whether the current trusted status of the terminal device meets the preset status trusted condition based on the first trust evaluation information, and obtain a second verification result. Then, determine the identity verification result based on the first verification result and the second verification result. It can be understood that only when both the first verification result and the second verification result are judged to pass, the identity verification result will be judged to pass, and as long as one verification result is judged to fail, the identity verification result will be judged to fail.
[0088] Step S25: When the identity verification result indicates that the verification passes, allow the terminal device to access the target network.
[0089] During the process of the terminal device accessing the target network, obtain the device attribute information, device status information, device login information, and resource access information collected by the security authentication software in the terminal device, and determine the device attribute information, device status information, device login information, and resource access information as the second trust evaluation information. Among them, the device login information may include the device login time, the number of device login errors, and the number of device login retries; the resource access information may include the resource access frequency, the resource access address, and the number of out-of-bounds accesses.
[0090] Based on the second trust evaluation information, determine whether the current trusted state of the terminal device meets the preset state trust condition. Similar to the above evaluation process, the authentication controller will compare the second trust evaluation information with the preset state trust condition and obtain a trust judgment result. If the trust judgment result indicates non-compliance, revoke the identity admission ticket of the terminal device and prohibit the terminal device from accessing the target network.
[0091] It should be noted that during the identity verification process before the device accesses the target network and the continuous monitoring process after accessing the network, when determining whether the device is trusted, the dynamic trust evaluation module in the authentication controller is used, and data calculation is the core of the evaluation system. Before the device accesses, the authentication controller collects the initial feature data of the device, such as the device model, operating system version, etc., and establishes a trust baseline. At this time, based on this information, determine whether the device meets the basic characteristics of a trusted device, laying a foundation for subsequent evaluations. After the device accesses the network, monitor the device behavior in real time, such as the network access frequency, data transmission volume, etc. Once the device behavior deviates from the trust baseline, an anomaly detection mechanism will be triggered. At the same time, combine the device behavior and characteristics to calculate the trust score. If the score is lower than the threshold, the authentication controller will take risk control measures such as restricting access and disconnecting the connection. Moreover, the dynamic trust evaluation module will continuously learn and adapt according to the real-time performance of the device and newly emerging security threats, and continuously optimize the evaluation criteria to ensure the security and stability of the entire network.
[0092] In addition, in this embodiment, after revoking the identity admission ticket and prohibiting the terminal device from accessing the target network, the authentication controller can record relevant abnormal information, including the time when the abnormality occurred, the specific abnormal situation, etc. This information can be used for subsequent security audits and analyses, helping network administrators understand the sources and characteristics of security threats, so as to take more effective preventive measures. In addition, the authentication controller can also send a notice to the terminal device, informing it that it has been prohibited from accessing the network due to the non-compliance of the trusted state, and reminding the device administrator to conduct inspections and repairs.
[0093] As can be seen from the above, the authentication controller in this embodiment verifies the registration status based on the device feature values, issues identity credentials to unregistered devices that have completed the preset process, and confirms the device identity at the source. When the device is already registered, the identity confirmation is strengthened through random number signature verification to generate an identity access ticket. After accessing the security gateway, the authentication controller not only verifies the ticket but also evaluates the trusted status based on the device attributes and status information. The dual verification determines whether to allow access. During the device's access to the target network, multi-dimensional information of the device is continuously collected to dynamically judge the trusted status. Once an anomaly is detected, the ticket is immediately revoked and access is prohibited. This not only greatly reduces the risk of illegal devices accessing the network but also enables prompt measures to be taken when the device malfunctions, effectively ensuring the secure and stable operation of the network.
[0094] Correspondingly, referring to Figure 5 as shown, an embodiment of the present application provides a security authentication device for device access to a network, which is applied to a terminal device including security authentication software to be connected to a target network, and includes:
[0095] A device registration module 11, configured to, when the device registration status is unregistered, based on the device physical information, determine a device feature value and a device key pair when the current device environment meets the preset trusted conditions, and execute a preset registration process using the device feature value and the device key pair, so that the authentication controller issues a device identity credential for the terminal device; wherein, the device registration status is a status determined according to whether the identity information of the terminal device has been registered in the authentication controller; the device identity credential is a credential containing the device feature value and the public key of the device in the device key pair;
[0096] A random number generation module 12, configured to, when the device registration status is registered, generate a client random number, so that the authentication controller signs the client random number to obtain a first signature value and generates a server random number;
[0097] An authentication credential generation module 13, configured to obtain the first signature value and the server random number sent by the authentication controller, verify the first signature value, and after the verification passes, sign the server random number, and transmit a device authentication credential determined based on the obtained second signature value to the authentication controller, so that the authentication controller generates an identity access ticket based on the device authentication credential;
[0098] An information verification module 14, configured to access the security gateway based on the identity access ticket, so that the security gateway verifies the identity access ticket and the device trusted status through the authentication controller and obtains an identity verification result;
[0099] A network access module 15, configured to access the target network when the identity verification result indicates that the verification is passed.
[0100] As can be seen from the above, when the registration status of the terminal device in this application is unregistered and the current device environment meets the preset environment trust conditions, the device characteristic value and the device key pair are determined based on the device physical information. Then, the preset registration process is executed using the device characteristic value and the device key pair. The authentication controller will issue a device identity credential containing the device characteristic value and the device public key to the terminal device. If the device registration status is registered, the terminal device generates a client random number so that the authentication controller can sign it to obtain the first signature value, and a server random number is generated. After the terminal device obtains the first signature value and the server random number, it verifies the first signature value. After the verification passes, it signs the server random number, determines the device authentication credential based on the obtained second signature value, and transmits it to the authentication controller so that the authentication controller can generate an identity access ticket accordingly. When the terminal device accesses the security gateway by virtue of the identity access ticket, the security gateway verifies the identity access ticket and the device trust status through the authentication controller to obtain the identity verification result. If the identity verification result is passed, the terminal device can access the target network. In this way, this application can improve the security during the process of device accessing the network, thus effectively preventing illegal devices from accessing the enterprise network and providing a solid guarantee for the data security of the enterprise.
[0101] In some specific embodiments, the device registration module 11 specifically includes:
[0102] A credibility judgment unit, configured to judge whether the credibility of the current device environment meets the preset environment trust conditions and obtain a credibility judgment result;
[0103] An information collection unit, configured to, if the credibility judgment result indicates satisfaction, collect the device physical information through the data collection component in the security authentication software to complete the information collection operation;
[0104] An information calculation unit, configured to calculate the device characteristic value using the device physical information and generate a device key pair.
[0105] In some specific embodiments, the device registration module 11 specifically includes:
[0106] A characteristic value signature unit, configured to sign the device characteristic value using the device private key in the device key pair and obtain a corresponding third signature value;
[0107] An information determination unit, configured to determine the device characteristic value, the third signature value, and the device public key in the device key pair as device identity information;
[0108] An information transmission unit for transmitting the device identity information to an authentication controller, so that the authentication controller checks the device registration status based on the device feature value in the device identity information, and when the device registration status is unregistered, issues a device identity credential for the terminal device based on the device identity information.
[0109] In some specific embodiments, the authentication credential generation module 13 specifically includes:
[0110] A signature value verification unit for verifying the first signature value using the device public key and obtaining a verification result;
[0111] A random number signature unit for, when the verification result indicates that the verification is passed, signing the server random number using the device private key to obtain a second signature value;
[0112] A credential determination unit for determining a device authentication credential based on the second signature value and transmitting the device authentication credential to the authentication controller.
[0113] See Figure 6 As shown, an embodiment of the present application provides a security authentication device for a device to access a network, which is applied to a server including an authentication controller, and includes:
[0114] A credential issuance module 21 for obtaining a device feature value and a device public key sent by a terminal device, checking the device registration status based on the device feature value, and when the device registration status is unregistered, registering the terminal device that has executed a preset registration process to issue a device identity credential for the terminal device; wherein, the device feature value and the device public key are the device feature value and the device key pair determined by the terminal device based on device physical information when the device registration status is unregistered and the current device environment meets preset trusted conditions; the device registration status is the situation determined according to whether the identity information of the terminal device has been registered in the authentication controller; the device identity credential is a credential containing the device feature value and the device public key in the device key pair.
[0115] An information transmission module 22 for obtaining the client random number sent by the terminal device, signing the client random number using the authentication controller private key, obtaining a first signature value and generating a server random number, and sending the first signature value and the server random number to the terminal device; wherein, the client random number is a random number generated when the device registration status of the terminal device is registered.
[0116] The bill generation module 23 is configured to obtain the device authentication credential sent by the terminal device, verify the device authentication credential by using the device public key, and generate an identity access bill when the device authentication credential passes the authentication, and send the identity access bill to the terminal device; wherein, the device authentication credential is the device authentication credential determined by the terminal device based on the second signature value; the second signature value is the signature value obtained after the terminal device signs the server random number after passing the verification of the first signature value.
[0117] The identity verification module 24 is configured to verify the identity access bill and the device trusted state when the terminal device accesses the security gateway based on the identity access bill, and obtain an identity verification result.
[0118] The verification and access module 25 is configured to allow the terminal device to access the target network when the identity verification result indicates that the verification is passed.
[0119] In some specific embodiments, the identity verification module 24 specifically includes:
[0120] The identity verification unit is configured to verify the identity access bill to obtain a first verification result;
[0121] The information determination unit is configured to obtain the device attribute information and device status information collected by the security authentication software in the terminal device, and determine the device attribute information and the device status information as the first trust evaluation information;
[0122] The first status judgment unit is configured to judge whether the current trusted state of the terminal device meets the preset state trusted condition based on the first trust evaluation information, and obtain a second verification result;
[0123] The result determination unit is configured to determine the identity verification result based on the first verification result and the second verification result.
[0124] In some specific embodiments, the verification and access module 25 specifically further includes:
[0125] The information acquisition unit is configured to obtain the device attribute information, device status information, device login information, and resource access information collected by the security authentication software in the terminal device during the process of the terminal device accessing the target network, and determine the device attribute information, the device status information, the device login information, and the resource access information as the second trust evaluation information;
[0126] The second status judgment unit is configured to judge whether the current trusted state of the terminal device meets the preset state trusted condition based on the second trust evaluation information, and obtain a trust judgment result;
[0127] A bill revocation unit, configured to revoke the identity admission bill of the terminal device and prohibit the terminal device from accessing the target network if the trust judgment result indicates non - satisfaction.
[0128] Furthermore, an embodiment of the present application also discloses an electronic device. Figure 7 It is a structural diagram of an electronic device 30 shown according to an exemplary embodiment. The content in the figure should not be considered as any limitation on the scope of use of the present application. The electronic device 30 may specifically include: at least one processor 31, at least one memory 32, a power supply 33, a communication interface 34, an input / output interface 35, and a communication bus 36. Among them, the memory 32 is used to store a computer program, and the computer program is loaded and executed by the processor 31 to implement the relevant steps in the security authentication method for device access to the network disclosed in any of the foregoing embodiments. Additionally, the electronic device 30 in this embodiment may specifically be an electronic computer.
[0129] In this embodiment, the power supply 33 is used to provide operating voltage for each hardware device on the electronic device 30; the communication interface 34 can create a data transmission channel between the electronic device 30 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed on it here; the input / output interface 35 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application requirements, and no specific limitation is made here.
[0130] In addition, as a carrier for resource storage, the memory 32 can be a read - only memory, a random access memory, a disk, or an optical disc, etc. The resources stored thereon may include an operating system 321, a computer program 322, etc., and the storage method can be short - term storage or permanent storage.
[0131] Among them, the operating system 321 is used to manage and control each hardware device and the computer program 322 on the electronic device 30, and it can be Windows Server, Netware, Unix, Linux, etc. The computer program 322, in addition to including a computer program capable of completing the security authentication method for device access to the network executed by the electronic device 30 disclosed in any of the foregoing embodiments, may further include a computer program capable of completing other specific tasks.
[0132] Furthermore, the present application also discloses a computer - readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the security authentication method for device access to the network disclosed above. For the specific steps of the method, reference may be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.
[0133] In this specification, the various embodiments are described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method section.
[0134] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered as exceeding the scope of this application.
[0135] The steps of the methods or algorithms described in combination with the embodiments disclosed in this article can be directly implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.
[0136] Finally, it should also be noted that in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
[0137] The above has introduced the technical solution provided by the present application in detail. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A security authentication method for a device to access a network, characterized in that: Terminal devices containing security authentication software that are used to access the target network include: When the device registration status is unregistered, when the current device environment meets the preset environment trust condition, the device characteristic value and the device key pair are determined based on the device physical information, and the device characteristic value and the device key pair are used to perform the preset registration process, so that the authentication controller issues a device identity certificate to the terminal device; wherein the device registration status is determined according to the identity information of whether the terminal device has been registered in the authentication controller; the device identity certificate is a certificate containing the device characteristic value and the device public key in the device key pair; When the device registration status is registered, a client random number is generated, so that the authentication controller signs the client random number to obtain a first signature value and generates a server random number; Obtaining the first signature value and the server random number sent by the authentication controller, and verifying the first signature value. After the verification is passed, signing the server random number, and transmitting the device authentication credential determined based on the obtained second signature value to the authentication controller, so that the authentication controller generates an identity access ticket based on the device authentication credential; Accessing a security gateway based on the identity access ticket so that the security gateway verifies the identity access ticket and the device trust status through the authentication controller and obtains an identity authentication result; When the identity authentication result indicates that the authentication is successful, the target network is accessed.
2. The method for secure authentication of a device accessing a network according to claim 1, characterized in that: When the current device environment meets the preset environment trust condition, determining the device characteristic value and the device key pair based on the device physical information includes: Determine whether the credibility of the current device environment meets the preset environment credibility conditions, and obtain the credibility judgment result; If the credibility judgment result shows that it is satisfied, the physical information of the device is collected through the data collection component in the security authentication software to complete the information collection operation; The device physical information is used to calculate the device characteristic value and generate a device key pair.
3. The method for secure authentication of a device accessing a network according to claim 1, characterized in that: The using the device characteristic value and the device key pair to perform a preset registration process includes: Signing the device characteristic value using the device private key in the device key pair, and obtaining a corresponding third signature value; Determine the device characteristic value, the third signature value, and the device public key in the device key pair as device identity information; The device identity information is transmitted to the authentication controller so that the authentication controller verifies the device registration status based on the device feature value in the device identity information, and when the device registration status is unregistered, issues a device identity certificate to the terminal device based on the device identity information.
4. The method for secure authentication of a device accessing a network according to claim 3, characterized in that: The verifying the first signature value, signing the server random number after the verification is passed, and transmitting the device authentication credential determined based on the obtained second signature value to the authentication controller, includes: Verifying the first signature value using the device public key and obtaining a verification result; When the verification result indicates that the verification is passed, the server random number is signed using the device private key to obtain a second signature value; A device authentication credential is determined based on the second signature value, and the device authentication credential is transmitted to the authentication controller.
5. A security authentication method for a device to access a network, characterized in that: Applies to the server side containing the authentication controller, including: Obtain a device characteristic value and a device public key sent by a terminal device, verify the device registration status based on the device characteristic value, and when the device registration status is unregistered, register the terminal device that has executed a preset registration process to issue a device identity certificate to the terminal device; wherein the device characteristic value and the device public key are a device characteristic value and a device key pair determined by the terminal device based on the device physical information when the device registration status is unregistered and the current device environment meets a preset trust condition; the device registration status is a status determined according to whether the identity information of the terminal device has been registered in the authentication controller; the device identity certificate is a certificate containing the device characteristic value and the device public key in the device key pair; Obtain the client random number sent by the terminal device, sign the client random number using the authentication controller private key, obtain a first signature value and generate a server random number, and send the first signature value and the server random number to the terminal device; wherein the client random number is a random number generated when the device registration status of the terminal device is registered; Obtaining a device authentication credential sent by the terminal device, verifying the device authentication credential using the device public key, and generating an identity access ticket when the device authentication credential passes authentication, and sending the identity access ticket to the terminal device; wherein the device authentication credential is a device authentication credential determined by the terminal device based on a second signature value; the second signature value is a signature value obtained by the terminal device signing the server random number after the first signature value is verified; After the terminal device accesses the security gateway based on the identity access ticket, the identity access ticket and the device trust status are verified, and an identity authentication result is obtained; When the identity authentication result indicates that the authentication is successful, the terminal device is allowed to access the target network.
6. The method for secure authentication of a device accessing a network according to claim 5, characterized in that: The verifying the identity access ticket and the device trust status and obtaining the identity authentication result includes: Verifying the identity access ticket to obtain a first verification result; Acquire device attribute information and device status information collected by security authentication software in the terminal device, and determine the device attribute information and the device status information as first trust evaluation information; Determine whether the current trust state of the terminal device meets a preset trust condition based on the first trust evaluation information, and obtain a second verification result; An identity authentication result is determined based on the first verification result and the second verification result.
7. The method for secure authentication of a device accessing a network according to claim 6, characterized in that: Also includes: In the process of the terminal device accessing the target network, obtaining device attribute information, device status information, device login information and resource access information collected by the security authentication software in the terminal device, and determining the device attribute information, the device status information, the device login information and the resource access information as second trust evaluation information; Determine whether the current trust state of the terminal device meets the preset trust condition based on the second trust evaluation information, and obtain a trust determination result; If the trust judgment result indicates that the trust is not satisfied, the identity access ticket of the terminal device is revoked, and the terminal device is prohibited from accessing the target network.
8. A security authentication device for a device to access a network, characterized in that: Terminal devices containing security authentication software that are used to access the target network include: A device registration module, for determining a device characteristic value and a device key pair based on device physical information when the device registration status is unregistered and when the current device environment meets a preset trust condition, and performing a preset registration process using the device characteristic value and the device key pair so that the authentication controller issues a device identity certificate to the terminal device; wherein the device registration status is a status determined according to the identity information of whether the terminal device has been registered in the authentication controller; and the device identity certificate is a certificate containing the device characteristic value and the device public key in the device key pair; A random number generation module, used for generating a client random number when the device registration status is registered, so that the authentication controller signs the client random number to obtain a first signature value and generates a server random number; An authentication credential generation module, used to obtain a first signature value and the server random number sent by the authentication controller, and verify the first signature value. After the verification is passed, the server random number is signed, and the device authentication credential determined based on the obtained second signature value is transmitted to the authentication controller, so that the authentication controller generates an identity access ticket based on the device authentication credential; An information verification module, used to access the security gateway based on the identity access ticket, so that the security gateway verifies the identity access ticket and the device trust status through the authentication controller and obtains the identity authentication result; The network access module is used to access the target network when the identity authentication result indicates that the authentication is passed.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor is used to execute the computer program to implement the security authentication method for device access to a network as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: Used to store a computer program; wherein, when the computer program is executed by a processor, the method for secure authentication of a device accessing a network as described in any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Information data security sharing method based on network security
CN122119954A