Intranet access method and device, network access system, equipment and storage medium
By introducing a verification mechanism for network access certificates and health check results in the network access system, the problem of uploading user account and password information for each authentication in the prior art is solved, and the effect of improving user access network security is achieved.
Patent Information
- Application Number
- CN202311755428.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-19
- Publication Date
- 2025-06-20
AI Technical Summary
In the prior art, each authentication requires uploading user account and password information, which poses a risk of user information leakage, resulting in unsafe access to the network.
By applying for the target intranet's network access certificate based on the health check results of the terminal to be accessed, the network access certificate is the corresponding relationship certificate of the terminal device description information, the terminal user description information and the certificate description information, and an identity authentication is initiated to the authentication server based on the network access certificate, so that the authentication server can verify the authenticity of the network access certificate, the terminal identity, the terminal user identity and the terminal health.
This avoids the leakage of user account password information during the intranet access, and improves the security of accessing network users.
Smart Images

Figure CN120185831A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the field of network security technology, and in particular, to an intranet access method, device, network access control system, device, and storage medium. Background Art
[0002] With the development of network technology, terminal devices accessing the network may pose various security threats to the company's network. Therefore, it is necessary to perform identity verification and security baseline compliance checks on terminal devices accessing the company's network, and only terminal devices that have passed identity verification and security baseline compliance checks can access the company's office network.
[0003] Existing network access control methods authenticate based on the IP (Internet Protocol) address and MAC (Media Access Control) address of the terminal device, and relevant information such as user accounts and passwords needs to be transmitted over the network for each authentication.
[0004] However, in the process of implementing the present invention, it is found that at least the following problems exist in the prior art:
[0005] In the prior art, user account and password information needs to be uploaded for each authentication, which poses a risk of user information leakage and leads to the problem of insecure user network access. Summary of the Invention
[0006] Embodiments of the present invention provide an intranet access method, device, network access control system, device, and storage medium to avoid the leakage of user account and password information during the process of accessing the intranet and improve the security of network access users.
[0007] In a first aspect, an embodiment of the present invention provides an intranet access method, which is applied to a network access client on a terminal to be accessed. The method includes:
[0008] Applying for an access certificate for the target intranet based on the health check result of the terminal to be accessed; the access certificate is a corresponding relationship voucher for terminal device description information, terminal user description information, and certificate description information;
[0009] Initiating an identity authentication to an authentication server based on the access certificate, so that the authentication server verifies the authenticity of the access certificate, the terminal identity, the terminal user identity, and the terminal health;
[0010] Responding to the authentication passed feedback information from the authentication server, and connecting the terminal to be accessed to the target intranet.
[0011] In a second aspect, an embodiment of the present invention further provides an intranet access device, which is integrated into a network access client on a terminal to be accessed. The device includes:
[0012] An access network certificate application module, configured to apply for an access network certificate for a target internal network based on the health check result of the to-be-connected terminal; the access network certificate is a corresponding relationship certificate of terminal device description information, terminal user description information, and certificate description information.
[0013] An identity authentication module, configured to initiate identity authentication to an authentication server based on the access network certificate, so that the authentication server verifies the authenticity of the access network certificate, the terminal identity, the terminal user identity, and the terminal health status.
[0014] An internal network access module, configured to connect the to-be-connected terminal to the target internal network in response to the authentication passed feedback information of the authentication server.
[0015] In a third aspect, an embodiment of the present invention provides a network access control system, which includes: a to-be-connected terminal, a cloud access control subsystem, and an internal network access control subsystem; the cloud access control subsystem includes a network access controller and a health check server; the internal network access control subsystem includes a certificate server and an authentication server.
[0016] The network access controller is configured to proxy the to-be-connected terminal to apply for an access network certificate from the certificate server, and issue the access network certificate to the to-be-connected terminal; when the network connection status between the to-be-connected terminal and the target internal network is abnormal, verify the real-time verification information uploaded by the to-be-connected terminal.
[0017] The health check server is configured to collect the security baseline detection results of the to-be-connected terminal.
[0018] The certificate server is configured to generate an access network certificate for the to-be-connected terminal, and verify the access network certificate when the to-be-connected terminal plans to access the target internal network.
[0019] The authentication server is configured to perform identity authentication on the to-be-connected terminal when the to-be-connected terminal plans to access the target internal network.
[0020] In a fourth aspect, an embodiment of the present invention provides an electronic device, which includes:
[0021] One or more processors;
[0022] A memory, configured to store one or more programs;
[0023] When the one or more programs are executed by the one or more processors, the one or more processors implement the internal network access method provided in any embodiment of the present invention.
[0024] In a fifth aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the intranet access method provided in any embodiment of the present invention.
[0025] The embodiments in the above invention have the following advantages or beneficial effects:
[0026] The technical solution of the present invention applies for an access certificate for the target intranet based on the health check result of the terminal to be accessed; the access certificate is a corresponding relationship voucher for the terminal device description information, the terminal user description information, and the certificate description information; initiate identity authentication to the authentication server based on the access certificate, so that the authentication server verifies the authenticity of the access certificate, the terminal identity, the terminal user identity, and the terminal health; in response to the authentication passed feedback information of the authentication server, connect the terminal to be accessed to the target intranet. Because the technical means of using the authenticity of the authentication certificate, the terminal identity, the user identity, and the terminal health to access the network are adopted, the technical problem that in the prior art, the user account and password information need to be uploaded every time for authentication, which poses a risk of user information leakage and leads to insecure network access for users, is overcome, the leakage of user account password information during the process of accessing the intranet is avoided, and the security of network access users is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 It is a flowchart of an intranet access method provided by an embodiment of the present invention;
[0028] Figure 2 It is an interaction schematic diagram of an intranet access method provided by this embodiment;
[0029] Figure 3 It is a structural schematic diagram of an intranet access device provided by an embodiment of the present invention;
[0030] Figure 4 It is a structural schematic diagram of a network access control system provided by an embodiment of the present invention;
[0031] Figure 5 It is a structural schematic diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0032] The present invention will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present invention, rather than limiting the present invention. Additionally, it should be noted that for the sake of description, only parts related to the present invention are shown in the drawings, rather than all the structures.
[0033] Figure 1The figure is a flowchart of an intranet access method provided by an embodiment of the present invention. This embodiment is applicable to the situation of accessing an enterprise intranet by a terminal device. This method can be executed by an intranet access device integrated in the terminal device. The device can be implemented in a software and / or hardware manner. This method can be applied to a network access client on the terminal to be accessed. As Figure 1 shown, the method specifically includes the following steps:
[0034] S110. Apply for an access certificate for the target intranet based on the health check result of the terminal to be accessed; the access certificate is a corresponding relationship voucher for terminal device description information, terminal user description information, and certificate description information.
[0035] Among them, the terminal to be accessed can be, for example, an intelligent mobile terminal device such as an office computer installed with a network access client. The health check result can include terminal device description information, terminal user description information, and terminal security baseline detection results. The terminal device description information in the health check result can include hardware information such as the main board, CPU (Central Processing Unit), and hard disk of the terminal device, and can also include identification information such as MAC (Media Access Control Address) and IP (Internet Protocol Address) that can identify the identity of the terminal to be accessed; the terminal user description information can refer to information for identifying the user identity; the terminal security baseline detection results can include, for example, anti-virus software information, whether the firewall service is enabled, the system patch version, whether the remote desktop is disabled, and other information. The target intranet can refer to an intranet of an enterprise, a company, etc. The access certificate can be used to prove the security of the terminal to be accessed to the target intranet. The access certificate can have information such as a certificate serial number, a certificate fingerprint, a certificate validity period, and a certificate user.
[0036] In this embodiment, when the terminal to be accessed attempts to access the target intranet for the first time through the network access client, an access certificate for the target intranet can be applied for first based on the health check result of the terminal to be accessed.
[0037] Optionally, before applying for an access certificate for the target intranet based on the health check result of the terminal to be accessed, it can also include: performing a health check on the terminal to be accessed, obtaining the health check result, and reporting the health check result to the health check server; when the terminal security baseline detection result meets the preset standard, triggering the execution of applying for an access certificate for the target intranet based on the health check result of the terminal to be accessed.
[0038] Among them, the health check server can be a server that collects the health data of terminal devices and can dynamically analyze the health of terminal devices. The preset standard can refer to the inspection standard for the security baseline of terminal devices. For example, if the terminal to be connected enables the firewall service, disables the remote desktop, and the system patch version is above 3.0, it is confirmed that the preset standard is met.
[0039] In this embodiment, if the health of the terminal to be connected does not meet the standard before applying for the network access certificate, then it is not necessary to apply for the network access certificate at this time. Therefore, the prerequisite for the terminal to be connected to apply for the network access certificate is that the terminal to be connected is a trusted device. Therefore, the terminal to be connected can be initially health-detected first. Specifically, the network access client can perform a health check on the terminal to be connected, obtain health check results such as terminal device description information, terminal user description information, and terminal security baseline detection results, and report the health check results to the health check server; if it is confirmed that the terminal security baseline detection result of the terminal to be connected meets the preset standard, the operation of applying for the network access certificate for the target intranet can be triggered based on the health check results of the terminal to be connected.
[0040] Optionally, applying for the network access certificate for the target intranet based on the health check results of the terminal to be connected may include: sending a request message for applying for the network access certificate to the network access controller; the request message includes terminal device description information, terminal user description information, and terminal security baseline detection results; receiving the network access certificate issued by the network access controller; the network access certificate is applied for by the network access controller to the certificate server based on the terminal device description information and terminal user description information after verifying the terminal security baseline detection result in the request message through the health check server.
[0041] Among them, the network access controller can be used to proxy the terminal to be connected to apply for the network access certificate for the target intranet, and the network access client requires the user to log in through an account, password, and verification code. The certificate server can be, for example, a CA server.
[0042] In this embodiment, the network access client of the terminal to be accessed sends a request message for an access certificate to the network access controller. The network access controller verifies whether the terminal to be accessed is a trusted device with the health check server according to the terminal security baseline check result in the request message. If the verification is passed, an access certificate is applied to the certificate server according to the terminal device description information and the terminal user description information. The certificate server creates an access certificate based on the terminal device description information and the terminal user description information, and issues the access certificate to the terminal to be accessed through the network access controller. Further, the network access client can install the root certificate in the access certificate to the trusted root certificate issuing authority of the terminal to be accessed, and install the access user certificate in the access certificate to the user certificate directory of the terminal to be accessed. It should be noted that after the network access controller applies for an access certificate for the terminal to be accessed, the corresponding relationship between the certificate fingerprint information of the access certificate, the terminal user description information, and the terminal device description information can also be recorded in the local database.
[0043] S120. Initiate identity authentication to the authentication server based on the access certificate, so that the authentication server verifies the authenticity of the access certificate, the terminal identity, the terminal user identity, and the terminal health status.
[0044] Among them, the authentication server can refer to the Radius server.
[0045] After the access certificate is installed on the terminal to be accessed, an EAP-TLS authentication based on 802.1x can be initiated to the Radius, so that the Radius verifies the authenticity of the access certificate, the terminal identity, the terminal user identity, and the terminal health status.
[0046] Specifically, the authenticity of the access certificate can be verified by the authentication server to the certificate server according to the certificate description information; the terminal identity can be verified by the authentication server to query the corresponding relationship between the access certificate and the terminal to be accessed from the health check server according to the device identification information in the certificate description information and the terminal device description information; the terminal user identity can be verified by the authentication server to query the corresponding relationship between the access certificate and the terminal user from the health check server according to the user identification information in the certificate description information and the terminal user description information; the terminal health status can be verified by the authentication server to query the terminal security baseline detection result of the terminal to be accessed from the health check server according to the device identification information.
[0047] S130. In response to the authentication passed feedback information from the authentication server, connect the terminal to be accessed to the target internal network.
[0048] Optionally, the internal network access method may further include: in response to the authentication failed feedback information from the authentication server, jump to the repair page to repair the security baseline of the terminal to be accessed.
[0049] In this embodiment, if the authentication server passes the verification of the authenticity of the network access certificate, the terminal identity, the terminal user identity, and the terminal health status, the terminal to be accessed can be divided into the network of the target intranet, and the terminal to be accessed can be connected to the target intranet; if the authentication server fails to pass the verification of the authenticity of the network access certificate, the terminal identity, the terminal user identity, and the terminal health status, the terminal to be accessed can be divided into the external network, so that the terminal to be accessed can access the external network but cannot be connected to the target intranet temporarily. At the same time, the network access client of the terminal to be accessed enters the repair page to prompt to repair the security baseline of the terminal to be accessed (such as updating system patches, etc.).
[0050] The technical solution of the present invention is to apply for a network access certificate for the target intranet based on the health check result of the terminal to be accessed; the network access certificate is a corresponding relationship certificate of the terminal device description information, the terminal user description information, and the certificate description information; initiate identity authentication to the authentication server based on the network access certificate, so that the authentication server verifies the authenticity of the network access certificate, the terminal identity, the terminal user identity, and the terminal health status; in response to the authentication passed feedback information of the authentication server, connect the terminal to be accessed to the target intranet. Because the technical means of using the authenticity of the authentication certificate, the terminal identity, the user identity, and the terminal health status to access the network are adopted, the technical problem that in the prior art, the user account and password information needs to be uploaded each time for authentication, which poses a risk of user information leakage and results in insecure network access for users, is overcome. The leakage of user account password information during the process of accessing the intranet is avoided, and the security of network access users is improved.
[0051] Optionally, the intranet access method may further include: detecting the network connection status between the terminal to be accessed and the target intranet in real time; if the network connection status is abnormal, establish an encrypted tunnel between the terminal to be accessed and the network access controller, and use the encrypted tunnel to report the real-time verification information to the network access controller, so that the network access controller verifies the real-time verification information; the real-time verification information includes the real-time terminal security baseline detection result, the real-time terminal user description information, the real-time device identification information, and the real-time certificate description information; receive the allow access feedback information sent by the authentication server according to the verification passed notification; the verification passed notification is sent after the network access controller verifies the real-time verification information; reconnect the terminal to be accessed to the target intranet according to the allow access feedback information.
[0052] Among them, the situation where the network connection status is abnormal may be, for example, that the network is disconnected due to network jitter or other malicious cracking.
[0053] Optionally, after the terminal to be connected accesses the target intranet, the network access client can continue to perform real-time detection on the terminal to be connected. For example, the certificate serial number, the MAC of the terminal device, the terminal user, and other health data of the terminal device can be periodically reported to the health check server. If the terminal to be connected is detected to be abnormal, the health check server can notify the authentication server to remove the terminal to be connected from the target intranet, so that the client software prompts the user to repair. For the terminal to be connected with malicious behavior, the certificate server can also be notified to revoke the network access certificate of the terminal to be connected.
[0054] To enable those skilled in the art to better understand the intranet access method of the present invention, Figure 2 FIG. is an interactive schematic diagram of an implementation of the intranet access method provided in this embodiment. Figure 2 It describes the process of the terminal to be connected accessing the intranet based on the network access certificate. This schematic diagram is mainly divided into three parts: accessing the external network, accessing the intranet, and continuous detection.
[0055] 1. Part of accessing the external network
[0056] Accessing the external network mainly solves the problems of the terminal to be connected installing the client software for the first time, performing a security scan on the device, and applying for and installing the network access certificate.
[0057] (1) First, the terminal to be connected needs to connect to a network that can access public network resources, then download the network access client, install and start the client. The first use of the client requires an account, password, and SMS verification code.
[0058] (2) The network access client performs a health check on the terminal to be connected and reports the health status data to the terminal health check server (i.e., the health check server). The health status data includes user information (terminal user description information), device information (terminal device description information), and device health data (terminal security baseline detection results).
[0059] (3) After the health check passes, the network access client applies to the network access controller for an intranet access certificate. When applying for the certificate, the network access client carries device information, user information, and security baseline detection results.
[0060] (4) After receiving the certificate application request, the network access controller queries the health status of the terminal to be connected from the terminal health check server. If it is a trusted device, it applies to the CA server for the network access certificates of the terminal to be connected and the terminal user to be connected.
[0061] (5) After the network access controller applies for the network access certificate for the terminal to be connected, it records the certificate fingerprint information, terminal user description information, and terminal device description information in the local database and issues the certificate to the terminal to be connected.
[0062] (6) After the terminal device receives the network access certificate, the client software installs the CA root certificate and network access user certificate into the trusted organization and user certificate directory.
[0063] 2. Access to the intranet
[0064] (1) After the network access client has installed the network access certificate on the terminal to be accessed, it initiates 802.1x-based EAP-TLS authentication to Radius.
[0065] (2) The Radius server reads the certificate information, terminal MAC address, and terminal user information of the terminal to be accessed, verifies the authenticity of the certificate from the CA server, and queries the terminal health check server for device health information and whether the binding information between the device and the user is normal.
[0066] (3) If the above information is verified and the certificate verification is passed, the terminal to be connected is divided into VLAN2, and the device can access Internet public network resources (equivalent to the external network) and enterprise intranet resources (equivalent to the internal network); if the MAC query shows that the device is temporarily untrusted, the terminal to be connected is divided into the isolated network VLAN1, and the device can access Internet public network resources but cannot access enterprise intranet resources, and is guided to be repaired.
[0067] (4) The network access client detects network status changes of the access terminal and immediately establishes a TLS encrypted tunnel with the network access controller. Through the encrypted tunnel, it reports the security baseline detection data, user information, MAC, IP, certificate serial number SN, certificate fingerprint, certificate user, validity period and other information of the access terminal in real time. After the network access controller verifies the information of the encrypted tunnel, it notifies Radius to divide the network permissions of the terminal device. If the above information is verified and meets the security standards, the device is divided into VLAN 2, and the device can access the enterprise intranet resources and Internet public network resources. The device that does not meet the security baseline standards is divided into VLAN 1, and the device can only access Internet public network resources, and automatically guides the user to repair it.
[0068] (5) For devices with restricted MAC address access or frequently changing devices, the network access controller mainly monitors the status of the TLS encryption tunnel, certificate information, IP information, and user information according to the configuration policy. For terminal devices with abnormal data, they are divided into the isolated network VLAN1 and guided for repair. In the scenario of terminal software abnormality or human damage, when users access enterprise intranet resources, they will jump to the repair guidance page.
[0069] 3. Continuous detection part
[0070] After the to-be-connected terminal accesses the enterprise intranet resources, the network access client continuously detects the health data of the to-be-connected terminal and periodically reports the data (device health data such as certificate serial number, terminal user, terminal MAC address, security baseline detection data, etc.) to the terminal health check server. If the terminal health check server returns that the device is abnormal, for the devices with abnormal health degree, notify Radius to kick the device out of the enterprise intranet resources. For devices with malicious behaviors, kick them out of the network and revoke the network access certificate.
[0071] The following is an embodiment of the intranet access device provided by the embodiment of the present invention. This device and the intranet access method of the above Embodiment 1 belong to the same inventive concept. For the details not described in detail in the embodiment of the intranet access device, reference can be made to the content of the above embodiments.
[0072] Figure 3 The following is a schematic structural diagram of the intranet access device provided by the embodiment of the present invention. This device is integrated into the network access client on the to-be-connected terminal. This device includes: an access certificate application module 310, an identity authentication module 320, and an intranet access module 330. Among them:
[0073] The access certificate application module 310 is used to apply for an access certificate for the target intranet based on the health check result of the to-be-connected terminal; the access certificate is a corresponding relationship certificate of terminal device description information, terminal user description information, and certificate description information;
[0074] The identity authentication module 320 is used to initiate identity authentication to the authentication server based on the access certificate, so that the authentication server verifies the authenticity of the access certificate, the terminal identity, the terminal user identity, and the terminal health degree;
[0075] The intranet access module 330 is used to respond to the authentication passed feedback information of the authentication server and connect the to-be-connected terminal to the target intranet.
[0076] The technical solution of the present invention applies for an access certificate for the target intranet based on the health check result of the to-be-connected terminal; the access certificate is a corresponding relationship certificate of terminal device description information, terminal user description information, and certificate description information; initiates identity authentication to the authentication server based on the access certificate, so that the authentication server verifies the authenticity of the access certificate, the terminal identity, the terminal user identity, and the terminal health degree; responds to the authentication passed feedback information of the authentication server and connects the to-be-connected terminal to the target intranet. Because of the technical means of using the authenticity of the authentication certificate, the terminal identity, the user identity, and the terminal health degree for network access, it overcomes the technical problem in the prior art that each authentication requires uploading user account and password information, which has the risk of user information leakage and leads to insecure network access for users, avoids the leakage of user account password information during the process of accessing the intranet, and improves the security of network access users.
[0077] In the above device, optionally, it further includes an access network certificate application trigger module, which is used to, before applying for an access network certificate for the target internal network based on the health check result of the to-be-connected terminal:
[0078] Perform a health check on the to-be-connected terminal to obtain the health check result, and report the health check result to the health check server; the health check result includes terminal device description information, terminal user description information, and terminal security baseline detection results;
[0079] When the terminal security baseline detection result meets the preset standard, trigger the execution of applying for an access network certificate for the target internal network based on the health check result of the to-be-connected terminal.
[0080] In the above device, optionally, the access network certificate application module 310 can specifically be used for:
[0081] Send a request message for applying for an access network certificate to the network access controller; the request message includes the terminal device description information, the terminal user description information, and the terminal security baseline detection result;
[0082] Receive the access network certificate issued by the network access controller; the access network certificate is applied for by the network access controller to the certificate server based on the terminal device description information and the terminal user description information after verifying the terminal security baseline detection result in the request message by using the health check server.
[0083] In the above device, optionally, it further includes a target internal network reconnection module, which is used for:
[0084] Real-time detect the network connection status between the to-be-connected terminal and the target internal network;
[0085] If the network connection status is abnormal, establish an encrypted tunnel between the to-be-connected terminal and the network access controller, and use the encrypted tunnel to report real-time verification information to the network access controller, so that the network access controller verifies the real-time verification information; the real-time verification information includes real-time terminal security baseline detection results, real-time terminal user description information, real-time device identification information, and real-time certificate description information;
[0086] Receive the allowed access feedback information sent by the authentication server according to the verification passed notification; the verification passed notification is sent by the network access controller after verifying the real-time verification information;
[0087] Reconnect the to-be-connected terminal to the target internal network according to the allowed access feedback information.
[0088] In the above device, optionally, it further includes a repair module for:
[0089] In response to the authentication failure feedback information from the authentication server, jump to a repair page to repair the security baseline of the to-be-connected terminal.
[0090] In the above device, optionally, the authenticity of the network access certificate is verified by the authentication server from the certificate server according to the certificate description information;
[0091] The identity of the terminal is verified by the authentication server from the health check server for the correspondence between the network access certificate and the to-be-connected terminal according to the device identification information in the certificate description information and the terminal device description information;
[0092] The identity of the terminal user is verified by the authentication server from the health check server for the correspondence between the network access certificate and the terminal user according to the user identification information in the certificate description information and the terminal user description information;
[0093] The health degree of the terminal is verified by the authentication server from the health check server for the terminal security baseline detection result of the to-be-connected terminal according to the device identification information.
[0094] The internal network access device provided by the embodiment of the present invention can execute the internal network access method provided by the first embodiment of the present invention, and has corresponding function modules and beneficial effects for executing the internal network access method.
[0095] Figure 4 It is a schematic structural diagram of a network access system provided by an embodiment of the present invention. The system includes: a to-be-connected terminal 410, a cloud access subsystem 420, and an internal network access subsystem 430; the cloud access subsystem 420 includes a network access controller 4201 and a health check server 4202; the internal network access subsystem 430 includes a certificate server 4301 and an authentication server 4302. Among them:
[0096] The network access controller 4201 is used to proxy the to-be-connected terminal to apply for a network access certificate from the certificate server, and issue the network access certificate to the to-be-connected terminal; when the network connection status between the to-be-connected terminal and the target internal network is abnormal, verify the real-time verification information uploaded by the to-be-connected terminal;
[0097] The health check server 4202 is used to collect the security baseline detection results of the to-be-connected terminal;
[0098] The certificate server 4301 is used to generate a network access certificate for the to-be-connected terminal and verify the network access certificate when the to-be-connected terminal plans to access the target internal network;
[0099] The authentication server 4302 is configured to authenticate the to-be-connected terminal when the to-be-connected terminal plans to connect to the target intranet.
[0100] Figure 5 FIG. is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. Figure 5 FIG. shows a block diagram of an exemplary electronic device 12 suitable for implementing embodiments of the present invention. Figure 5 The shown electronic device 12 is only an example and should not impose any limitation on the functions and usage scope of embodiments of the present invention.
[0101] As Figure 5 shown, the electronic device 12 is presented in the form of a general-purpose computing device. The components of the electronic device 12 may include, but are not limited to: one or more processors or processing units 16, a system memory 28, and a bus 18 connecting different system components (including the system memory 28 and the processing unit 16).
[0102] The bus 18 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the multiple bus structures. By way of example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.
[0103] The electronic device 12 typically includes a variety of computer system-readable media. These media can be any available media accessible by the electronic device 12, including volatile and non-volatile media, removable and non-removable media.
[0104] The system memory 28 may include computer system-readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. The electronic device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 34 can be used to read and write non-removable, non-volatile magnetic media ( Figure 5 not shown, typically referred to as a "hard disk drive"). Although Figure 5Not shown in the figure, a disk drive for reading and writing a removable non-volatile disk (such as a "floppy disk") and an optical disk drive for reading and writing a removable non-volatile optical disk (such as a CD-ROM, DVD-ROM or other optical medium) can be provided. In these cases, each drive can be connected to the bus 18 through one or more data medium interfaces. The system memory 28 may include at least one program product having a set (such as at least one) of program modules configured to perform the functions of the embodiments of the present invention.
[0105] A program / utility 40 having a set (at least one) of program modules 42 can be stored, for example, in the system memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment. The program modules 42 generally perform the functions and / or methods in the embodiments described in the present invention.
[0106] The electronic device 12 can also communicate with one or more external devices 14 (such as a keyboard, a pointing device, a display 24, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 12, and / or communicate with any device that enables the electronic device 12 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 22. Moreover, the electronic device 12 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 20. As shown in the figure, the network adapter 20 communicates with other modules of the electronic device 12 through the bus 18. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0107] The processing unit 16 executes various functional applications and data processing by running the programs stored in the system memory 28, such as implementing the steps of an intranet access method provided in the first embodiment of the present invention. The method includes:
[0108] Applying for an access certificate for the target intranet based on the health check result of the to-be-accessed terminal; the access certificate is a corresponding relationship voucher of terminal device description information, terminal user description information, and certificate description information;
[0109] Initiating an identity authentication to the authentication server based on the access certificate, so that the authentication server verifies the authenticity of the access certificate, the terminal identity, the terminal user identity, and the terminal health status;
[0110] In response to the authentication passed feedback information from the authentication server, connect the to-be-connected terminal to the target intranet.
[0111] Certainly, those skilled in the art can understand that the processor can also implement the technical solutions of the intranet access method provided in any embodiment of the present invention.
[0112] This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the steps of an intranet access method provided in the foregoing embodiments of the present invention. The method includes:
[0113] Apply for an access certificate for the target intranet based on the health check result of the to-be-connected terminal; the access certificate is a corresponding relationship certificate of terminal device description information, terminal user description information, and certificate description information;
[0114] Initiate identity authentication to the authentication server based on the access certificate, so that the authentication server verifies the authenticity of the access certificate, the terminal identity, the terminal user identity, and the terminal health status;
[0115] In response to the authentication passed feedback information from the authentication server, connect the to-be-connected terminal to the target intranet.
[0116] The computer storage medium of the embodiments of the present invention can adopt any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium can be, for example, but not limited to: an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device.
[0117] A computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take many forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.
[0118] The program code contained on a computer-readable medium can be transmitted with any appropriate medium, including but not limited to: wireless, wire, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0119] The computer program code for performing the operations of the present invention can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).
[0120] Those of ordinary skill in the art should understand that the above-mentioned modules or steps of the present invention can be implemented with a general-purpose computing device. They can be concentrated on a single computing device or distributed over a network composed of multiple computing devices. Optionally, they can be implemented with program code executable by a computer device, so that they can be stored in a storage device and executed by a computing device, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. Thus, the present invention is not limited to any specific combination of hardware and software.
[0121] Note that the above is only a preferred embodiment of the present invention and the technical principles applied. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present invention. Therefore, although the present invention has been described in more detail through the above embodiments, the present invention is not limited to the above embodiments. Without departing from the concept of the present invention, more other equivalent embodiments can be included, and the scope of the present invention is determined by the scope of the appended claims.
Claims
1. An intranet access method, applied to a network access client on a terminal to be accessed, characterized in that, The method includes: Applying for an access certificate for the target intranet based on the health check result of the to-be-connected terminal; the access certificate is a corresponding relationship certificate of terminal device description information, terminal user description information, and certificate description information; Initiating identity authentication to the authentication server based on the access certificate, so that the authentication server verifies the authenticity of the access certificate, the terminal identity, the terminal user identity, and the terminal health status; In response to the authentication passed feedback information from the authentication server, connecting the to-be-connected terminal to the target intranet.
2. The method according to claim 1, characterized in that, Before applying for an access certificate for the target intranet based on the health check result of the to-be-connected terminal, it further includes: Performing a health check on the to-be-connected terminal to obtain the health check result, and reporting the health check result to the health check server; the health check result includes terminal device description information, terminal user description information, and terminal security baseline detection result; When the terminal security baseline detection result meets the preset standard, triggering the execution of applying for an access certificate for the target intranet based on the health check result of the to-be-connected terminal.
3. The method according to claim 2, characterized in that, The applying for an access certificate for the target intranet based on the health check result of the to-be-connected terminal includes: Sending a request message for applying for an access certificate to the network access controller; the request message includes the terminal device description information, the terminal user description information, and the terminal security baseline detection result; Receiving the access certificate issued by the network access controller; the access certificate is applied by the network access controller to the certificate server based on the terminal device description information and the terminal user description information after verifying the terminal security baseline detection result in the request message by using the health check server and passing the verification.
4. The method according to claim 1, characterized in that, It further includes: Real-time detecting the network connection status between the to-be-connected terminal and the target intranet; If the network connection status is abnormal, establishing an encrypted tunnel between the to-be-connected terminal and the network access controller, and reporting real-time verification information to the network access controller by using the encrypted tunnel, so that the network access controller verifies the real-time verification information; the real-time verification information includes real-time terminal security baseline detection result, real-time terminal user description information, real-time device identification information, and real-time certificate description information; Receiving the allowed access feedback information sent by the authentication server according to the verification passed notice; The verification passed notice is sent by the network access controller after verifying the real-time verification information; Re-connecting the to-be-connected terminal to the target intranet according to the allowed access feedback information.
5. The method according to any one of claims 1-4, characterized in that, It further includes: In response to the authentication failed feedback information from the authentication server, jumping to a repair page to repair the security baseline of the to-be-connected terminal.
6. The method according to claim 1, characterized in that, The authenticity of the access certificate is verified by the authentication server to the certificate server according to the certificate description information; The terminal identity is verified by the authentication server by querying the corresponding relationship between the access certificate and the to-be-connected terminal from the health check server according to the device identification information in the certificate description information and the terminal device description information; The identity of the end user is verified by the authentication server by querying the relationship between the network access certificate and the end user from the health check server according to the user identification information in the certificate description information and the end user description information. The health of the terminal is verified by the authentication server by querying the terminal security baseline detection result of the terminal to be accessed from the health check server according to the device identification information.
7. An intranet access device, integrated in a network access client on a terminal to be accessed, characterized in that, It includes: A network access certificate application module, configured to apply for a network access certificate for the target intranet based on the health check result of the terminal to be accessed. The network access certificate is a corresponding relationship voucher for the terminal device description information, the end user description information, and the certificate description information. An identity authentication module, configured to initiate identity authentication to the authentication server based on the network access certificate, so that the authentication server verifies the authenticity of the network access certificate, the terminal identity, the end user identity, and the terminal health. An intranet access module, configured to connect the terminal to be accessed to the target intranet in response to the authentication passed feedback information from the authentication server.
8. A network access system, characterized in that, It includes a terminal to be accessed, a cloud access control subsystem, and an intranet access control subsystem; the cloud access control subsystem includes a network access controller and a health check server; the intranet access control subsystem includes a certificate server and an authentication server. The network access controller is configured to proxy the terminal to be accessed to apply for a network access certificate from the certificate server and issue the network access certificate to the terminal to be accessed. When the network connection status between the terminal to be accessed and the target intranet is abnormal, verify the real-time verification information uploaded by the terminal to be accessed. The health check server is configured to collect the security baseline detection results of the terminal to be accessed. The certificate server is configured to generate a network access certificate for the terminal to be accessed and verify the network access certificate when the terminal to be accessed plans to access the target intranet. The authentication server is configured to authenticate the terminal to be accessed when the terminal to be accessed plans to access the target intranet.
9. An electronic device, characterized in that, The electronic device includes: One or more processors; A memory, configured to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the intranet access method according to any one of claims 1-6.
10. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the program is executed by the processor, it implements the intranet access method according to any one of claims 1-6.
Citation Information
Cited By
Network access method and device, electronic equipment and storage medium
CN121567363A