Security management and control method and device, equipment and storage medium

By starting the container for access devices without security control components in the network security control device and configuring proxy security control components, the problem of devices being unable to interact is solved, and the security control of access devices is realized, and data security and confidentiality are improved.

CN120238324APending Publication Date: 2025-07-01CHENGDU TD TECH LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311858324.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

In the prior art, access equipment without security control components in the equipment cannot interact with the security control components on the network, resulting in low security control intensity, affecting the security and confidentiality of data, and unable to meet the security control requirements of the industry system.

Method used

The container is started in the network-side security control device for the access device without security control components. The agent security control component is pre-configured in the container. The device information is obtained through the agent security control component and logged in in the network-side security control component to achieve security control.

Benefits of technology

It realizes effective safety control of equipment without safety control components, ensures data security and confidentiality, and meets the security control requirements of industry systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238324A_ABST
    Figure CN120238324A_ABST
Patent Text Reader

Abstract

The invention provides a security control method and device, equipment and a storage medium, and can be used in the technical field of information security. The method comprises the following steps: in response to identification that a target access device is accessed to a target security data link network, starting a corresponding container for the target access device, a proxy security control component being pre-configured in the container, the container being located in a network-end security control device, and the target access device being an access device without a security control component; running a proxy security management and control component in the container, acquiring equipment information of the target access equipment by adopting the proxy security management and control component, and logging in the target access equipment in a network-end security management and control component based on the proxy security management and control component and the equipment information; and performing security management and control on the target access equipment based on the network side security management and control component. According to the invention, consistent security management and control of the access device without the security management and control component and the access device with the security management and control component can be realized, and the security and confidentiality of data are effectively guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular, to a security control method, device, equipment, and storage medium. Background Art

[0002] Industry systems have strict requirements for data security, confidentiality, etc. They use a secure data link network for data security control to meet the security control requirements of industry systems. In the secure data link network, there are network-side security control components. The security control of the access device by the network-side security control component is realized through the interaction between the network-side security control component and the security control component in the access device. Therefore, when there is no security control component in the access device, the access device cannot interact with the network-side security control component, and thus the security control of the access device by the network-side security control component cannot be realized.

[0003] Currently, when an access device without a security control component in the device accesses the secure data link network, generally, a security device allow list is configured in the secure data link network to achieve preliminary security control of the access device without a security control component. However, the security control intensity of this security control method is relatively low, which affects the security and confidentiality of data in the industry system, and it is impossible to achieve security control that meets the security control requirements of the industry system based on the network-side security control component. Summary of the Invention

[0004] This application provides a security control method, device, equipment, and storage medium to solve the technical problems in the prior art that the security control intensity is relatively low, which affects the security and confidentiality of data in the industry system, and it is impossible to achieve security control that meets the security control requirements of the industry system based on the network-side security control component.

[0005] In a first aspect, this application provides a security control method, which is applied to a network-side security control device. The network-side security control device includes a network-side security control component. The method includes:

[0006] In response to identifying that a target access device accesses a target secure data link network, a corresponding container is started for the target access device. A proxy security control component is pre-configured in the container, and the container is located in the network-side security control device. The target access device is an access device without a security control component;

[0007] The proxy security control component is run in the container, and the device information of the target access device is obtained by using the proxy security control component. Based on the proxy security control component and the device information, the target access device is logged in to the network-side security control component;

[0008] Security control of the target access device based on the network - side security control component.

[0009] In a possible design, the network - side security control device further includes: an access device management component and a container management software;

[0010] Starting a corresponding container for the target access device includes:

[0011] Using the access device management component to determine whether the target access device is a device that initially accesses the target secure data link network;

[0012] If so, using the access device management component to obtain the device operation characteristic data of the target access device, determining the configuration information of the container to be started according to the device operation characteristic data, and sending the configuration information to the container management software, so that the container management software starts the corresponding container based on the configuration information;

[0013] If not, using the access device management component to obtain the device identification information of the target access device, determining the corresponding container based on the device identification information and the pre - constructed mapping relationship, and sending the corresponding container identification to the container management software, so that the container management software starts the corresponding container. Multiple preset access device identification information and the container identification information having a mapping relationship with it are stored in the mapping relationship.

[0014] In a possible design, it includes: in response to identifying that the target access device disconnects from the target secure data link network, controlling the container corresponding to the target access device to save the security control data and container configuration information before the target access device goes offline;

[0015] Closing the container corresponding to the target access device;

[0016] Constructing the mapping relationship between the device identification information and the container identification information of the target access device, and storing the mapping relationship in the container management software.

[0017] In a possible design, it includes: logging in the target access device in the network - side security control component based on the proxy security control component and the device information, including:

[0018] Using the proxy security control component to send the device information to the network - side security control component, so that the target access device logs in the network - side security control component.

[0019] In a possible design, before logging in the target access device in the network - side security control component based on the proxy security control component and the device information, it further includes:

[0020] Determine whether the target access device is registered in the network - side security control component;

[0021] If not, use the access device management component to obtain the device information of the target access device, and send it to the corresponding proxy security control component, and use the proxy security control component to send the device information to the network - side security control component to instruct the network - side security control component to register the target access device based on the device information.

[0022] In a possible design, it includes: in response to the failure of the target access device to register, determine the reason for the registration failure;

[0023] In response to the reason for the registration failure being that the target access device is an insecure device, send a kill instruction and a registration failure message to the target access device through the proxy security control component and the access device management component in sequence; so that the target access device performs a kill operation based on this;

[0024] In response to the reason for the registration failure being a network exception, re - register the target access device based on the device information.

[0025] In a possible design, the security control of the target access device based on the network - side security control component includes:

[0026] Use the network - side security control component to determine the allowed service scope corresponding to the target access device;

[0027] Based on the result of whether the services processed by the target access device in the target secure data - link network are within the allowed service scope, perform security control on the target access device.

[0028] In a possible design, the security control of the target access device based on the result of whether the services processed by the target access device in the target secure data - link network are within the allowed service scope includes:

[0029] Send the allowed service scope to the firewall, so that the firewall determines whether the services processed by the target access device in the target secure data - link network are within the allowed service scope, and intercepts the services not within the allowed service scope; or,

[0030] Send the allowed service scope to the proxy security control component, and use the proxy security component to determine whether the services processed by the target access device in the target secure data link network are within the allowed service scope, and control the target access device to prohibit processing services that are not within the allowed service scope. In a possible design, identifying whether a device accessing the target secure data link network is a target access device includes:

[0031] Send security control component identification indication information to the device accessing the target secure data link network, where the security control component identification indication information is the information identified by the security control component;

[0032] If the security control component identification response information sent by the device accessing the target secure data link network is received, determine that the target secure data link network device is not the target access device;

[0033] If the security control component identification response information sent by the device accessing the target secure data link network is not received, determine that the target secure data link network device is the target access device.

[0034] In a second aspect, the present application provides a security control device, which is located in a network-side security control device. The network-side security control device includes a network-side security control component. The device includes:

[0035] A start module, configured to start a corresponding container for the target access device in response to identifying that the target access device accesses the target secure data link network. The container is pre-configured with a proxy security control component, and the container is located in the network-side security control device. The target access device is an access device without a security control component;

[0036] An operation module, configured to run the proxy security control component in the container;

[0037] An acquisition module, configured to acquire device information of the target access device by the proxy security control component;

[0038] A login module, configured to log in the target access device in the network-side security control component based on the proxy security control component and the device information;

[0039] A security control module, configured to perform security control on the target access device based on the network-side security control component.

[0040] In a third aspect, the present application provides a device including: a processor, and a memory communicatively connected to the processor;

[0041] The memory stores computer-executable instructions;

[0042] The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 9.

[0043] In a fourth aspect, the present application provides a computer-readable storage medium storing computer-executable instructions, which are used to implement the method according to any one of the first aspects when executed by a processor.

[0044] In a fifth aspect, the present application provides a computer program product including a computer program, which implements the method according to the first aspect when executed by a processor.

[0045] The security control method, device, equipment and storage medium provided by the present application are applied to a network-side security control device, which includes a network-side security control component. The method includes: in response to identifying that a target access device accesses a target secure data link network, starting a corresponding container for the target access device, where a proxy security control component is pre-configured in the container, and the container is located in the network-side security control device, and the target access device is an access device without a security control component; running the proxy security control component in the container, and using the proxy security control component to obtain device information of the target access device, and logging in the target access device in the network-side security control component based on the proxy security control component and the device information; performing security control on the target access device based on the network-side security control component. Since the target access device is an access device without a security control component, when the target access device accesses the target secure data link network, a container configured with a proxy security control component is started for the target access device, and the proxy security control component in the container is run. The proxy security control component can proxy the target access device to interact with the network-side security control device, and can proxy the security control component to log in the device in the network-side security control component according to the obtained device information of the target access device during the interaction. For the target access device that can be logged in to the network-side security control component, security control that meets the security control requirements of the industry system is performed, thereby ensuring the same security control as that of the access device with a security control component, protecting the security and confidentiality of data, and meeting the security control requirements of the industry system. Description of the Drawings

[0046] The drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.

[0047] Figure 1 It is an application scenario diagram of the security control method provided by an embodiment of the present application;

[0048] Figure 2 The flowchart of the security control method provided by an embodiment of the present application;

[0049] Figure 3 The flowchart of the security control method provided by another embodiment of the present application;

[0050] Figure 4 The structural schematic diagram of the security control device provided by an embodiment of the present application;

[0051] Figure 5 The structural schematic diagram of the electronic device provided by an embodiment of the present application.

[0052] Through the above-mentioned drawings, the specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and text descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Specific Embodiments

[0053] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0054] To clearly understand the technical solution of the present application, the solutions of the prior art will be introduced in detail first.

[0055] To ensure the security of data within the system, the industry system conducts security control over the data within the system by applying a secure data link network. A network-side security control component operates within the secure data link network. Devices accessing the secure data link network need to successfully register and log in through the security control component running within their devices and the security control component on the network side before they can perform corresponding business processes within the industry system. However, target access devices that are unable to normally run the security control component within their devices due to insufficient hardware capabilities cannot register and log in to the security control component on the network side through the security control component. Currently, for target access devices that cannot normally run the security control component within their devices, the network side initially secures these target access devices by setting up a list of allowed security devices. The list of devices configured in the list of allowed security devices as security devices allows the network side to permit the target access device to access the network for business processing when the device identifier of the target access device exists in the list of allowed security devices. Since the target access device has not registered and logged in to the security control component on the network side, the security control component on the network side cannot perform security control that meets the security control requirements of the industry system for the target access device, resulting in a relatively low level of security control over the target access device and affecting the security and confidentiality of the data.

[0056] Therefore, when facing the technical problems in the prior art, in order to be able to perform security control that meets the security control requirements of the industry system for access devices based on the network-side security control component, it is necessary to solve the problem that access devices cannot normally run the security control component within their devices. Thus, a proxy security control component can be configured for the access device, and this proxy security control component is used to perform the same operations as the original security control component. Regarding the configuration of the proxy security control component, it can be run within the container of the network-side security control device. Therefore, by presetting the proxy security control component within the container to implement security control proxy for the target access device, security control that meets the security control requirements of the industry system can be achieved. Specifically, the proxy security control component is used to enable the target access device to log in to the network-side security control component and perform security control on the target access device after logging in.

[0057] Figure 1 The application scenario diagram of the security control method provided by an embodiment of this application is as Figure 1As shown in the figure. The system corresponding to the security control method in the embodiments of the present application may include: a network-side security control device 101, a network-side security control component 102, a container A 103, a target access device 104, an access device management component 105, a proxy security control component 106, and a container management software 107. The network-side security control device 101 includes a network-side security control component 102, a container A 103, an access device management component 105, a proxy security control component 106, and a container management software 107. The container management software 107 is used to manage at least one container, including the container A 103, and the container A 103 contains a proxy security control component 106 inside. The target access device 104 is an access device without a security control component. When the target access device 103 accesses the secure data link network, the target access device 104 sends its device information to the access device management component 105. The access device management component 105 identifies the target access device 104. When it is identified that the target access device 104 is an access device without a security control component, the access device management component 105 sends container startup information to the container management software 107 to start the container A 103, and runs the proxy security control component 106 after starting the container A 103. After the proxy security control component 106 runs, it obtains the device information of the target access device 104, and logs in to the network-side security control component 102 according to the device information of the target access device 104, so as to realize the security control of the target access device 104 by the network-side security control component 102.

[0058] The following uses specific embodiments to elaborate in detail on the technical solutions of the present application and how the technical solutions of the present application solve the above technical problems. These several specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The following will describe the embodiments of the present application with reference to the accompanying drawings.

[0059] Figure 2 It is a flowchart of a security control method provided by an embodiment of the present application. As Figure 2 shown, the execution subject of this embodiment is a security control device, and this security control device is located in the network-side security control device, where the network-side security control device can be an electronic device. The security control method provided in this embodiment includes the following steps:

[0060] Step 201, in response to identifying that a target access device accesses a target secure data link network, start a corresponding container for the target access device. A proxy security control component is pre-configured in the container. The container is located in the network-side security control device, and the target access device is an access device without a security control component.

[0061] Among them, the network-side security control device includes a network-side security control component.

[0062] Among them, the target access device is an access device without a security control component that needs to access the target secure data link network.

[0063] Among them, the target secure data link network is a secure network for transmitting and managing data.

[0064] Among them, the network-side security control device can be any gateway in the target secure data link network.

[0065] It can be understood that there can be multiple gateways in the target secure data link network.

[0066] Among them, a container is an executable unit of software. Using a form of operating system virtualization, it can provide a complete running environment for an application program and can run on a desktop, in the cloud, etc.

[0067] Among them, the security control component is a component capable of performing data security control.

[0068] Among them, the network-side security control component is a component that manages and controls the security control rules on the network side.

[0069] Among them, the proxy security control component is a component that acts as a security control proxy for the target access device.

[0070] It can be understood that both the network-side security control component and the proxy security control component are security control components, but they provide security control for different devices.

[0071] Specifically, in this embodiment, in response to identifying that the target access device accesses the target secure data link network and starting a corresponding container for the target access device, it can specifically be: after the network-side security control component identifies that the target access device is an access device without a security control component according to a preset identification rule, it starts a corresponding container for the target access device.

[0072] Among them, when the access device accesses the target secure data link network, the network-side security control device determines whether the target access device accesses the target secure data link network by identifying whether the access device has a security control component.

[0073] Specifically, a request for whether there is a security control component can be sent to the access device. The access device determines whether it has a security control component based on this request, can generate a response indicating whether it has a security control component based on the determination result, and send this response to the network-side security control device. Then, the network-side security control device parses this response to obtain the determination result, and further identifies whether the target access device accesses the target secure data link network.

[0074] It can be understood that whether a target access device accesses the target secure data link network can also be identified by other means, which is not limited in this embodiment.

[0075] Among them, when the network-side security control device starts a corresponding container for the target access device, specifically: the network-side security control device obtains the device identification information of the target access device, determines the corresponding container of the target access device according to the preset mapping relationship between its device identification information and the container identification information, and then the network-side security control device starts the corresponding container according to the determined container identification information.

[0076] Among them, the device identification information is the information identifying the target access device, which can be the product number of the device and is unique.

[0077] Among them, the container identification information is the information identifying the container corresponding to the target access device.

[0078] Step 202: Run the proxy security control component in the container, and use the proxy security control component to obtain the device information of the target access device, and log in the target access device in the network-side security control component based on the proxy security control component and the device information.

[0079] Specifically, in this embodiment, after the container is started, the proxy security control component pre-configured in the container is automatically run. After running, the proxy security control component reads the device information of the target access device received in the container, and sends the read device information of the target access device to the network-side security control component, so that the proxy security control component and the network-side security control component interact, and then the proxy security control component enables the target access device to log in in the network-side security control component based on the device information of the target access device.

[0080] Among them, the device information includes the device identification information, operating system, access method, etc. of the device without a security control component.

[0081] Among them, the operating system can be Windows, Linux, etc. The access method can be WIFI, Bluetooth, NFC, etc.

[0082] Step 203: Based on the security control of the target access device by the network-side security control component.

[0083] Specifically, in this embodiment, based on the security control of the target access device by the network-side security control component, specifically: the network-side security control component searches for the security control rule corresponding to the target access device in the preset security control rules according to the device information of the logged-in target access device, and performs security control on the target access device according to the security control rule corresponding to the target access device.

[0084] The security control method provided in this embodiment is applied to a network - side security control device. The network - side security control device includes a network - side security control component. In response to identifying that a target access device accesses the target secure data - link network, a corresponding container is started for the target access device. A proxy security control component is pre - configured in the container, and the container is located in the network - side security control device. The target access device is an access device without a security control component. The proxy security control component is run in the container, and the device information of the target access device is obtained by using the proxy security control component. Then, based on the proxy security control component and the device information, the target access device is logged in to the network - side security control component. The security control of the target access device is carried out based on the network - side security control component. Since the target access device is an access device without a security control component, when the target access device accesses the target secure data - link network, a container configured with a proxy security control component is started for the target access device, and the proxy security control component in the container is run. The proxy security control component can proxy the interaction between the target access device and the network - side security control device, and can proxy the security control component to log in the device in the network - side security control component according to the obtained device information of the target access device during the interaction. For the target access device that can be logged in to the network - side security control component, security control that meets the security control requirements of the industry system is carried out, thereby ensuring the same security control as that of the access device with a security control component, guaranteeing the security and confidentiality of data, and meeting the security control requirements of the industry system.

[0085] As an alternative implementation, on the basis of the above - mentioned embodiment, the network - side security control device further includes: an access device management component and a container management software.

[0086] Correspondingly, starting a corresponding container for the target access device includes:

[0087] Using the access device management component to determine whether the target access device is a device that initially accesses the target secure data - link network.

[0088] If so, the access device management component is used to obtain the device operation characteristic data of the target access device, and determine the configuration information of the container to be started according to the device operation characteristic data, and send the configuration information to the container management software, so that the container management software starts the corresponding container based on the configuration information.

[0089] If not, the access device management component is used to obtain the device identification information of the target access device, and determine the corresponding container based on the device identification information and the pre - constructed mapping relationship, and send the corresponding container identification to the container management software, so that the container management software starts the corresponding container. The mapping relationship stores multiple preset access device identification information and the container identification information having a mapping relationship with it.

[0090] Among them, the access device management component is a component for managing the access of target access devices to the network side.

[0091] Among them, the preset access device is an access device that has successfully accessed the target secure data link network.

[0092] Specifically, in this embodiment, the access device management component automatically records the device information of the preset access device that has successfully accessed the target secure data link network, as well as the container configuration and container identification information of the corresponding container started according to the accessed preset access device, and constructs a mapping relationship among the device information, container identification information, and corresponding container configuration of the preset access device that has successfully accessed, and can store this mapping relationship in the form of a data table.

[0093] Among them, the device information of the preset access device that has successfully accessed the target secure data link network, the container identification information of the corresponding container, and the container configuration have a one-to-one correspondence relationship, that is, the device information of one target access device corresponds to one container identification information and the corresponding container configuration.

[0094] Then, after the target access device accesses the target secure data link network, it can be determined whether the device information of the target access device exists in this mapping relationship based on this mapping relationship. If not, it is determined that the target access device is a device that initially accesses the target secure data link network. If so, it is determined that the target access device is not a device that initially accesses the target secure data link network.

[0095] Specifically, in this embodiment, there is a preset container configuration file in the access device management component, which may include container configuration information that has a mapping relationship with the device operation characteristic data of the target access device. The container configuration information that has a mapping relationship with the device operation characteristic data of the target access device is set by the staff of the network side security control component, and this embodiment does not make any limitations.

[0096] Then, if it is determined that the target access device is an initial access, the access device management component will send a request to obtain the device operation characteristic data of the target access device to the target access device. As a result, after receiving the request, the target access device sends its device operation characteristic data to the access device management component. Furthermore, the access device management component determines the configuration information of the container to be started and generates the container identification information of the container to be started based on the obtained device operation characteristic data of the target access device in the preset container configuration file. Therefore, the access device management component sends the obtained configuration information and container identification information of the container to be started to the container management software, and the container management software creates and starts a container corresponding to the configuration information and container identification information of the container to be started based on the configuration information and container identification information of the container to be started.

[0097] Among them, the device operation characteristic data is the operation characteristic data representing the target access device, such as the operating memory, device model, etc.

[0098] Among them, the container management software is the management software for creating, managing, starting, and running containers, such as Docker container software, etc., which is not limited in this embodiment.

[0099] Among them, the configuration information of the container to be started is the relevant configuration for creating and running the corresponding container, such as disk occupancy, operating memory, etc.

[0100] Then, after determining that the target access device is not a first-time access device, the access device management component will search for the same device identification information in the device information of the preset access devices that have successfully accessed the target security data link network recorded in the access device management component according to the device identification information in the device information of the target access device, so as to determine the container identification information that has a mapping relationship with the device identification information of the preset access device, and the access device management component will send the container identification information to the container management software, and then the container management software will start the container corresponding to the container identification information.

[0101] The security control method provided in this embodiment, wherein the network-side security control device further includes: an access device management component and a container management software; starting a corresponding container for the target access device includes: using the access device management component to determine whether the target access device is a device that first accesses the target security data link network; if so, using the access device management component to obtain the device operation characteristic data of the target access device, and determining the configuration information of the container to be started according to the device operation characteristic data, and sending the configuration information to the container management software, so that the container management software starts the corresponding container based on the configuration information; if not, using the access device management component to obtain the device identification information of the target access device, and determining the corresponding container based on the device identification information and the pre-constructed mapping relationship, and sending the corresponding container identification to the container management software, so that the container management software starts the corresponding container, and the mapping relationship stores multiple preset access device identification information and the container identification information having a mapping relationship with it. Since when starting a container for the target access device, it can be determined whether the target access container is a device that first accesses the target security data link network, so as to make corresponding responses to the target access devices that are first-time access or non-first-time access, and thus can meet the different access requirements of the target access devices, effectively avoiding resource waste when re-creating containers for each target access device.

[0102] As an optional implementation manner, on the basis of any one of the above embodiments, it further includes:

[0103] In response to identifying that the target access device has left the target secure data link network, control the container corresponding to the target access device to save the security control data and container configuration information of the target access device before it goes offline.

[0104] Close the container corresponding to the target access device.

[0105] Build a mapping relationship between the device identification information and the container identification information of the target access device, and store the mapping relationship in the container management software.

[0106] Among them, the security control data includes the registration status of the target access device, the corresponding registration information, and the security control data after logging in to the security control component at the network end.

[0107] It can be understood that if the target access device is only registered in the security control component at the network end and has not logged in, the security control data only contains the registration status and the corresponding registration information. If the target access device is not registered in the security control device at the network end, it only contains the registration status.

[0108] Specifically, in this embodiment, after the target access device logs out of the security control component at the network end, the security control component at the network end determines that the target access device has left the target secure data link network.

[0109] Then, after the security control component at the network end identifies that the target access device has left the target secure data link network, the security control group at the network end sends the offline information of the target access device to the container management software. As a result, the container management software will control the container corresponding to its target access device to save the security control data and container configuration information of the target access device before it goes offline, and close the corresponding container after the container is successfully saved.

[0110] It can be understood that the target access device that goes offline in this embodiment is in a successfully connected state before going offline.

[0111] Specifically, in this embodiment, the container management software will establish a one-to-one mapping relationship between the device identification information of the target access device that goes offline and the container identification information of the container corresponding to the target access device, and save it.

[0112] It can be understood that the device identification information of one target access device corresponds to one container identification information.

[0113] The security control method provided in this embodiment, in response to identifying that the target access device has disconnected from the target secure data link network, controls the container corresponding to the target access device to save the security control data and container configuration information before the target access device goes offline; closes the container corresponding to the target access device; constructs a mapping relationship between the device identification information and the container identification information of the target access device, and stores the mapping relationship in the container management software. Since the container corresponding to the target access device that has gone offline is closed in a timely manner, the additional system overhead caused by the container operation can be reduced. And the corresponding mapping relationship established based on the device identification information of the target access device that has successfully accessed and the container identification information of the corresponding container is saved in the container management software, thereby realizing the effective management of the corresponding relationship between the target access device and the corresponding container.

[0114] As an alternative implementation, based on any of the above embodiments, logging in the target access device in the network-side security control component according to the proxy security control component and device information includes:

[0115] The proxy security control component is used to send the device information to the network-side security control component, so that the target access device can log in to the network-side security control component.

[0116] Specifically, in this embodiment, after the proxy security control component in the container runs, the proxy security control component in the container can send the obtained device information of the target access device to the network-side security control component, so that the network-side security control component realizes the login of the target access device based on the received device information of the target access device.

[0117] It can be understood that the proxy security control component logs in to the network-side security control component based on the device information of the target access device, which can be regarded as the proxy security control component performing security proxy for the target access device, that is, the proxy security control component logs in to the network-side security control component as the security control component of the target access device, thereby realizing the security control of the target access device by the network-side security control component.

[0118] Specifically, in this embodiment, the proxy security control component sends the device information of the target access device to the network-side security control component, and the network-side security control component can read the corresponding information in the device information of the target access device according to the preset login rules, and identify the corresponding information in the read device information of the target access device. When it is identified as a preset access device, the network-side security control component considers the target access device to have logged in successfully.

[0119] The security control method provided in this embodiment logs in the target access device in the network - side security control component based on the proxy security control component and device information, including: using the proxy security control component to send the device information to the network - side security control component, so that the target access device logs in the network - side security control component. Since the device information of the target access device is sent to the network - side for login through the proxy security control component in the container, the proxy security control component in the container realizes security proxy for the target access device, thereby realizing the security control of the target access device by the network - side security control component, and further ensuring the security and availability of the access device without a security control component at the network - side.

[0120] As an alternative implementation, based on any of the above embodiments, before logging in the target access device in the network - side security control component according to the proxy security control component and device information, it further includes:

[0121] Determine whether the target access device is registered in the network - side security control component.

[0122] If not, use the access device management component to obtain the device information of the target access device and send it to the corresponding proxy security control component, and use the proxy security control component to send the device information to the network - side security control component to instruct the network - side security control component to register the target access device based on the device information.

[0123] Specifically, in this embodiment, determining whether the target access device is registered in the network - side security control component can be specifically: the access device management component obtains the device information of the target access device. If the access device management component identifies that the target access device is a device newly accessing the target security data network, it is determined that the target access device is not registered in the network - side security control component. If the access device management component identifies that the target access device is a non - newly - accessing device, start the corresponding container of the target access device through the container management software, and determine the registration status of the target access device based on the security control data of the target access device saved in the corresponding container.

[0124] Among them, if there is a registration success record in the security control data of the target access device saved in the container, the corresponding target access device has been registered in the network - side security control component. If there is no registration success record in the security control data of the corresponding device saved by the container management software, the corresponding target access device is not registered in the network - side security control component.

[0125] Among them, after the device information of the target access device is registered once in the network-side security control component, when the registered target access device accesses the target secure data link again, it does not need to be registered repeatedly and can directly log in to the network-side security control component according to the registered device information.

[0126] Before the security control method provided in this embodiment logs in the target access device to the network-side security control component according to the proxy security control component and the device information, it further includes: determining whether the target access device is registered in the network-side security control component; if not, the access device management component is used to obtain the device information of the target access device and send it to the corresponding proxy security control component, and the proxy security control component is used to send the device information to the network-side security control component to instruct the network-side security control component to register the target access device based on the device information. Since before the target access device logs in to the network-side security management component, the registration status of the target access device is determined through the access device management component and the container management software, it can effectively avoid repeated registration of the registered target access device before logging in to the network-side security control component, thereby accelerating the access efficiency of the target access device that accesses again.

[0127] As an optional implementation manner, on the basis of any of the above embodiments, the following technical solutions are further included:

[0128] In response to the registration failure of the target access device, determine the reason for the registration failure.

[0129] In response to the reason for the registration failure being that the target access device is an insecure device, a kill instruction and a registration failure message are sent to the target access device successively through the proxy security control component and the access device management component; so that the target access device performs a kill operation based on this.

[0130] In response to the reason for the registration failure being a network exception, re-register the target access device based on the device information.

[0131] Among them, killing is an operation that can eliminate potential dangers caused by the device, which can prevent illegal users from entering the system to work. For example, it can be disabling the device and self-destroying the device, etc.

[0132] Specifically, in this embodiment, when the device information of the target access device fails to be registered in the network-side security control component, the network-side security control component will determine the reason for the registration failure. If it is determined that the registration failure is caused by a network anomaly, repeated registration will be performed based on the device information. If it is determined that the registration failure is due to the target access device corresponding to the device information being an insecure device, the network-side security control component will send the registration failure, the reason for the registration failure, and a kill command to the proxy security control component. After receiving the information sent by the network-side security control component, the proxy security control component sends the device information and the kill command to the access device management component through a container, so that the access device management component sends the kill command to the corresponding target access device, and then the target access device executes the kill command.

[0133] Among them, the reason for being identified as an insecure device may be that due to reasons such as loss of the target access device, the staff of the network-side security control component calibrates its device as an insecure device in the network-side security control component.

[0134] Optionally, the network-side security control component issuing a kill command to the target access device due to the target access device being an insecure device not only exists after the registration failure, but may also exist before the target access device logs in or before the target access device is not off the network.

[0135] Optionally, in this embodiment, after the network-side security control component issues a kill operation command, the operation corresponding to the kill command may be to disable the target access device or start the self-destruction program of the target access device, etc., and this embodiment does not limit this.

[0136] It can be understood that disabling the target access device in the kill command may be to block the internal program of the target access device so that it cannot perform network access operations. And starting the self-destruction program of the target access device in the kill command may be an operation to start the internal program that automatically destroys the target access device. After executing the self-destruction program, the internal program of the target access device is damaged, and then the target access device can no longer be used.

[0137] The security control method provided in this embodiment determines the reason for the registration failure in response to the registration failure of the target access device; in response to the reason for the registration failure being that the target access device is an insecure device, a kill instruction and a registration failure message are sent to the target access device sequentially through the proxy security control component and the access device management component; so that the target access device performs a kill operation based on this; in response to the reason for the registration failure being a network exception, the target access device is re-registered based on the device information. Since the reason for the registration failure is determined and analyzed when the target access device fails to register, different responses are made for different failure reasons, which improves the efficiency of handling problems that occur during the registration of the target access device, and the target access device identified as an insecure device is killed, thus avoiding the re-access of insecure target access devices.

[0138] As an alternative implementation, based on any of the above embodiments, the security control of the target access device by the network-side security control component includes:

[0139] The network-side security control component is used to determine the allowed service scope corresponding to the target access device.

[0140] Based on the result of whether the service processed by the target access device in the target secure data link network is within the allowed service scope determined by the allowed service scope, the security control of the target access device is carried out.

[0141] Specifically, in this embodiment, the corresponding allowed service scope of each target access device may be different according to the different target access devices, and the allowed service scope of the target access device is configured by the service manager, and this embodiment does not limit this.

[0142] Specifically, in this embodiment, the network-side security control component finds the allowed service scope corresponding to the target access device from the allowed service scopes of the preset access devices according to the device information of the logged-in target access device. If the service processed by the target access device is included in the allowed service scope of the target access device, the network-side security control component allows the target access device to process; if the service processed by the target access device is not included in the allowed service scope of the target access device, the network-side security control component restricts the target access device from processing. Furthermore, the network-side security control component performs security control on the target access device according to the obtained allowed service scope of the target access device.

[0143] The security control method provided in this embodiment, based on the security control of the target access device by the network-side security control component, includes: using the network-side security control component to determine the allowed service scope corresponding to the target access device; based on the result of whether the services processed by the target access device in the target secure data link network are within the allowed service scope, performing security control on the target access device. Since security control of the allowed service scope is performed on the target access device, different target access devices can determine matching allowed service scopes. Compared with the same security control method for different access devices, the security of the target secure data link network can be further improved.

[0144] As an alternative implementation, based on any of the above embodiments, performing security control on the target access device based on the result of whether the services processed by the target access device in the target secure data link network are within the allowed service scope includes:

[0145] Sending the allowed service scope to the firewall so that the firewall determines whether the services processed by the target access device in the target secure data link network are within the allowed service scope and intercepts services not within the allowed service scope; or,

[0146] Sending the allowed service scope to the proxy security control component and using the proxy security component to determine whether the services processed by the target access device in the target secure data link network are within the allowed service scope and controlling the target access device to prohibit processing services not within the allowed service scope.

[0147] Among them, the firewall is a technology for protecting network security that can prevent unauthorized access and data leakage.

[0148] Optionally, in this embodiment, when performing security control on the services processed by the target access device in the target secure data link network based on the allowed service scope corresponding to the target access device, security control can be achieved by correspondingly configuring the firewall through the allowed service scope corresponding to the target access device, or by the interaction between the network-side security control component and the proxy security control component. This embodiment does not make any limitations in this regard.

[0149] Specifically, in this embodiment, when security control is performed through a firewall, the network-side security control component sends the allowed service scope corresponding to the target access device to the firewall, and the firewall restricts the service access of the target access device based on the allowed service scope corresponding to the target access device. For example, when the target access device performs an allowed service process, the target access device can normally access and process the corresponding service. When the target access device performs other service processes outside the allowed service scope, the firewall will restrict the target access device from accessing and processing other services outside the allowed service scope.

[0150] Specifically, in this embodiment, when security control is performed by sending the allowed service scope corresponding to the target access device to the proxy security control component, the network-side security control component sends the allowed service scope corresponding to the target access device to the proxy security control component. The proxy security control component determines whether to allow the target access device to perform the corresponding service access and processing according to the allowed service scope corresponding to the target access device when the target access device performs service access and processing. When the target access device performs other service processes outside the allowed service scope, the proxy security control component will restrict the target access device from accessing and processing other services outside the allowed service scope.

[0151] The security control method provided in this embodiment controls the security of the target access device based on the result of determining whether the service processed by the target access device in the target secure data link network is within the allowed service scope, including: sending the allowed service scope to the firewall so that the firewall determines whether the service processed by the target access device in the target secure data link network is within the allowed service scope and intercepts services not within the allowed service scope; or sending the allowed service scope to the proxy security control component and using the proxy security component to determine whether the service processed by the target access device in the target secure data link network is within the allowed service scope and controlling the target access device to prohibit processing services not within the allowed service scope. Since the security control of the target access device can be realized by setting the firewall or sending it to the proxy security control component based on the allowed service scope of the target access device, different security control methods can be selected according to different target access devices, thus increasing the flexibility and diversity of realizing security control for the target access device.

[0152] As an alternative embodiment, based on any of the above embodiments, identifying whether the device accessing the target secure data link network is the target access device includes:

[0153] Sending security control component identification indication information to the device accessing the target secure data link network, where the security control component identification indication information is the information identified by the security control component.

[0154] If the security control component identification response information sent by the device accessing the target secure data link network is received, it is determined that the target secure data link network device is not the target access device.

[0155] If the security control component identification response information sent by the device accessing the target secure data link network is not received, it is determined that the target secure data link network device is the target access device.

[0156] Specifically, in this embodiment, when a device accesses the target secure data link network, the network-side security control device sends security control component identification indication information to the device accessing the target secure data link network. If there is a normally operating security control component in the device accessing the target secure data link network, the security control component identification indication information sent by the network-side security control device can be received and a response message can be returned. If there is no normally operating security control component in the device accessing the target secure data link network, the security control component identification indication information sent by the network-side security control device cannot be received and no response message will be returned. Furthermore, the network-side security control device determines the device accessing the target secure data link network that has not returned a response message as the target access device.

[0157] The security control method provided in this embodiment identifies whether the device accessing the target secure data link network is the target access device, and includes: sending security control component identification indication information to the device accessing the target secure data link network, where the security control component identification indication information is the information identified by the security control component; if the security control component identification response information sent by the device accessing the target secure data link network is received, it is determined that the target secure data link network device is not the target access device; if the security control component identification response information sent by the device accessing the target secure data link network is not received, it is determined that the target secure data link network device is the target access device. Since the identification of the target access device is achieved by sending security control component identification indication information to the device accessing the target secure data link network, the target access device that needs to log in to the network-side security component through the proxy security control component can be accurately found, and then the intelligent management of the target access device and the non-target access device can be realized.

[0158] Figure 3 It is a flowchart of the security control method provided in another embodiment of the present application. As Figure 3 shown, the execution subject of this embodiment is a security control system. The security control system includes a network-side security control device and a target access device. The network-side security control device includes a network-side security control component, an access device management component, a container management software, a container, and a proxy security control component. The security control method provided in this embodiment includes the following steps:

[0159] Step 301, the target access device sends its corresponding device information to the access device management component.

[0160] Step 302, the access device management component determines that the target access device is a device that initially accesses the target secure data link network based on the received device information of the target access device.

[0161] Step 303, the access device management component obtains the device operation characteristic data of the target access device, determines the configuration information and container identification information of the container to be started according to the device operation characteristic data, and sends the container identification information, configuration information of the container to be started, and the device information of the target access device to the container management software.

[0162] Among them, the access device management component establishes a mapping relationship between the device information of the target access device and the container identification information of the container and saves it.

[0163] Step 304, the container management software receives the container identification information, configuration information of the container to be started, and the device information of the target access device, and starts the container according to the configuration information of the container to be started.

[0164] Step 305, the corresponding container of the target access device runs the proxy security control component.

[0165] Among them, the proxy security control component exists in the started container.

[0166] Step 306, the proxy security control component obtains the device information of the target access device and sends it to the network-side security control component.

[0167] Step 307, the network-side security control component registers and logs in the target access device based on the received device information of the target access device.

[0168] Step 308, the network-side security control component obtains the allowable service scope corresponding to the logged-in target access device, and performs security control based on the allowable service scope corresponding to the logged-in target access device.

[0169] Step 309, the target access device completes the service processing and exits the target secure data link network.

[0170] Among them, after the target access device exits the target secure data link network, the container management software closes the container corresponding to the target access device.

[0171] Step 310, the network-side security control component sends the information that the target access device exits the target secure data link network to the container management software, and the container management software closes the corresponding container.

[0172] Step 311: The target access device accesses again and sends the device identification information of the target access device to the access device pipeline component.

[0173] Step 312: The access device management component compares the device identification information of the target access device with the saved access device identification information to obtain the container identification information of the corresponding container of the access device.

[0174] Step 313: The access device management component sends the container identification information to the container management software to start the corresponding container and run the proxy security control component in the container.

[0175] Step 314: The proxy security control component in the container corresponding to the target access device obtains the saved registration information of the target access device and logs in to the network-side security control component.

[0176] It can be understood that after step 314 is executed, steps 308-310 are continued.

[0177] In this embodiment, the implementation manners of each step are similar to those of the corresponding solutions in the above embodiment, and will not be elaborated here one by one.

[0178] Figure 4 It is a schematic structural diagram of a security control device provided by an embodiment of the present application. As Figure 4 shown, if the security control device provided by this embodiment is located in an electronic device, the security control device 40 provided by this embodiment includes: a startup module 41, an operation module 42, an acquisition module 43, a login module 44, and a security control module 45.

[0179] Among them, the startup module 41 is used to start a corresponding container for the target access device in response to identifying that the target access device accesses the target secure data link network. The proxy security control component is pre-configured in the container, and the container is located in the network-side security control device. The target access device is an access device without a security control component. The operation module 42 is used to run the proxy security control component in the container. The acquisition module 43 is used for the proxy security control component to acquire the device information of the target access device. The login module 44 is used to log in the target access device to the network-side security control component based on the proxy security control component and the device information. The security control module 45 is used to perform security control on the target access device based on the network-side security control component.

[0180] The security control device provided by this embodiment can execute Figure 2 the method embodiment shown, and the specific implementation principle and technical effect are similar, and will not be elaborated here.

[0181] Optionally, the network-side security control device further includes: an access device management component and a container management software.

[0182] Accordingly, the startup module 41, when starting the corresponding container for the target access device, is specifically used for:

[0183] Using the access device management component to determine whether the target access device is a device that initially accesses the target secure data link network; if so, using the access device management component to obtain the device operation characteristic data of the target access device, and determining the configuration information of the container to be started according to the device operation characteristic data, and sending the configuration information to the container management software, so that the container management software starts the corresponding container based on the configuration information; if not, using the access device management component to obtain the device identification information of the target access device, and determining the corresponding container based on the device identification information and the pre-constructed mapping relationship, and sending the corresponding container identification to the container management software, so that the container management software starts the corresponding container, and the mapping relationship stores multiple preset access device identification information and the container identification information having a mapping relationship with it.

[0184] Optionally, the security control device provided in this embodiment further includes a control module, a storage module, a construction module, and a shutdown module.

[0185] Among them, the control module is used to control the corresponding container of the target access device to save the security control data and container configuration information before the target access device goes offline in response to identifying that the target access device has left the target secure data link network. The shutdown module is used to shut down the corresponding container of the target access device. The construction module is used to construct the mapping relationship between the device identification information and the container identification information of the target access device. The storage module is used to store the mapping relationship in the container management software.

[0186] Optionally, the login module 44 is specifically used for: using the proxy security control component to send the device information to the network-side security control component, so that the target access device logs in to the network-side security control component.

[0187] Optionally, the security control device provided in this embodiment further includes a determination module and a sending module.

[0188] Among them, the determination module, before the login module logs in the target access device to the network-side security control component based on the proxy security control component and the device information, is used for:

[0189] Determine whether the target access device is registered in the network-side security control component.

[0190] The obtaining module 43 is further configured to, if not, obtain the device information of the target access device by using the access device management component. The sending module is configured to send it to the corresponding proxy security control component, and use the proxy security control component to send the device information to the network-side security control component, so as to instruct the network-side security control component to register the target access device based on the device information.

[0191] Optionally, the security control device provided in this embodiment further includes a registration module.

[0192] Correspondingly, the determining module is further configured to determine the reason for the registration failure in response to the failure of the target access device to register. The sending module is further configured to, in response to the reason for the registration failure being that the target access device is an insecure device, sequentially send a kill instruction and a registration failure message to the target access device through the proxy security control component and the access device management component; so that the target access device performs a kill operation based on this. The registration module is further configured to, in response to the reason for the registration failure being a network exception, re-register the target access device based on the device information.

[0193] Optionally, in the security control module 45, it is specifically configured to:

[0194] Use the network-side security control component to determine the allowed service scope corresponding to the target access device. Based on the allowed service scope, perform security control on the target access device according to the result of whether the service processed by the target access device in the target secure data link network is within the allowed service scope.

[0195] Optionally, when the security control module 45 performs security control on the target access device according to the result of whether the service processed by the target access device in the target secure data link network is within the allowed service scope based on the allowed service scope, it is specifically configured to:

[0196] Send the allowed service scope to the firewall, so that the firewall determines whether the service processed by the target access device in the target secure data link network is within the allowed service scope, and intercepts the service that is not within the allowed service scope; or, send the allowed service scope to the proxy security control component, and use the proxy security component to determine whether the service processed by the target access device in the target secure data link network is within the allowed service scope, and control the target access device to prohibit processing the service that is not within the allowed service scope.

[0197] Optionally, the security control device provided in this embodiment further includes an identification module.

[0198] Wherein, when the identification module identifies whether the device accessing the target secure data link network is the target access device, it is specifically configured to:

[0199] Send security control component identification indication information to the network device accessing the target secure data link. The security control component identification indication information is the information identified by the security control component. If the security control component identification response information sent by the network device accessing the target secure data link is received, it is determined that the target secure data link network device is not the target access device. If the security control component identification response information sent by the network device accessing the target secure data link is not received, it is determined that the target secure data link network device is the target access device.

[0200] The security control device provided in this embodiment can execute the method embodiments shown in any of the above. The specific implementation principles and technical effects are similar and will not be elaborated here.

[0201] Figure 5 It is a schematic structural diagram of an electronic device provided in an embodiment of the present application. As Figure 5 shown, the electronic device 50 provided in this embodiment includes: a processor 51 and a memory 52 communicatively connected to the processor.

[0202] Among them, the memory 51 stores computer execution instructions; the processor 51 executes the computer execution instructions stored in the memory 52 to implement the security control method provided in any of the above embodiments. The relevant descriptions can be understood by referring to the relevant descriptions and effects corresponding to the steps in the drawings, and will not be elaborated here.

[0203] Among them, the program may include program code, and the program code includes computer execution instructions. The memory 52 may include a high-speed RAM memory, and may also include non-volatile memory, such as at least one disk memory.

[0204] Among them, in this embodiment, the memory 52 is connected to the processor 51 through a bus. The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 5 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.

[0205] An embodiment of the present application further provides a computer-readable storage medium storing computer-executable instructions, which are used to implement the security control method provided in any of the above embodiments when executed by a processor. For example, the computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.

[0206] An embodiment of the present application further provides a computer program product, including a computer program, which implements the security control method provided in any of the above embodiments when executed by a processor.

[0207] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps may be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to the present application.

[0208] Furthermore, it should be noted that although the steps in the flowchart are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least some of the steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps.

[0209] It should be understood that the above device embodiments are illustrative only, and the device of the present application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units, modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed.

[0210] In addition, without special description, in each embodiment of the present application, each functional unit / module can be integrated in one unit / module, or each unit / module can exist physically alone, or two or more units / modules can be integrated together. The above integrated unit / module can be implemented in the form of hardware or in the form of a software program module.

[0211] When the integrated unit / module is implemented in the form of hardware, the hardware can be a digital circuit, an analog circuit, etc. The physical implementation of the hardware structure includes but is not limited to transistors, memristors, etc. Unless otherwise specified, the artificial intelligence processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic storage medium or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), etc.

[0212] When the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes: USB flash drives, read-only memory (ROM), random access memory (RAM), mobile hard disks, magnetic disks, or optical discs, etc., all of which can store program codes.

[0213] In the above embodiments, the descriptions of the various embodiments each have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope described in this specification.

[0214] Other embodiments of the present application will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include known common knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and examples are only illustrative, and the true scope and spirit of the present application are pointed out by the following claims.

[0215] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.

Claims

1. A security control method, characterized in that, The method is applied to a network-side security control device, which includes a network-side security control component. The method includes: In response to identifying that a target access device accesses a target secure data link network, starting a corresponding container for the target access device. A proxy security control component is pre-configured in the container, and the container is located in the network-side security control device. The target access device is an access device without a security control component. Running the proxy security control component in the container, and using the proxy security control component to obtain the device information of the target access device, and logging in the target access device in the network-side security control component based on the proxy security control component and the device information. Based on the network-side security control component for security control of the target access device.

2. The method according to claim 1, characterized in that, The network-side security control device further includes: an access device management component and a container management software. The starting a corresponding container for the target access device includes: Using the access device management component to determine whether the target access device is a device that initially accesses the target secure data link network. If so, using the access device management component to obtain the device operation characteristic data of the target access device, determining the configuration information of the container to be started according to the device operation characteristic data, and sending the configuration information to the container management software, so that the container management software starts a corresponding container based on the configuration information. If not, using the access device management component to obtain the device identification information of the target access device, determining the corresponding container based on the device identification information and a pre-constructed mapping relationship, and sending the corresponding container identification to the container management software, so that the container management software starts the corresponding container. Multiple preset access device identification information and the container identification information having a mapping relationship with it are stored in the mapping relationship.

3. The method according to claim 2, wherein It further includes: In response to identifying that the target access device disconnects from the target secure data link network, controlling the container corresponding to the target access device to save the security control data and container configuration information before the target access device goes offline. Closing the container corresponding to the target access device. Constructing the mapping relationship between the device identification information and the container identification information of the target access device, and storing the mapping relationship in the container management software.

4. The method according to claim 1, wherein The logging in the target access device in the network-side security control component based on the proxy security control component and the device information includes: Using the proxy security control component to send the device information to the network-side security control component, so that the target access device logs in the network-side security control component.

5. The method according to claim 4, characterized in that, Before the logging in the target access device in the network-side security control component based on the proxy security control component and the device information, it further includes: Determining whether the target access device is registered in the network-side security control component. If not, the access device management component is used to obtain the device information of the target access device and send it to the corresponding proxy security control component, and the proxy security control component is used to send the device information to the network-side security control component to instruct the network-side security control component to register the target access device based on the device information.

6. The method according to claim 5, characterized in that, It further includes: In response to the failure of the target access device to register, determine the reason for the registration failure; In response to the reason for the registration failure being that the target access device is an insecure device, the proxy security control component and the access device management component are used to send a kill instruction and a registration failure message to the target access device in sequence, so that the target access device performs a kill operation based on this; In response to the reason for the registration failure being a network exception, re-register the target access device based on the device information.

7. The method according to claim 1, wherein The security control of the target access device based on the network-side security control component includes: Using the network-side security control component to determine the allowed service range corresponding to the target access device; Based on the result of whether the service processed by the target access device in the target secure data link network is within the allowed service range, perform security control on the target access device.

8. The method according to claim 7, wherein The security control of the target access device based on the result of whether the service processed by the target access device in the target secure data link network is within the allowed service range includes: Sending the allowed service range to the firewall, so that the firewall determines whether the service processed by the target access device in the target secure data link network is within the allowed service range and intercepts the services that are not within the allowed service range; or, Sending the allowed service range to the proxy security control component, and using the proxy security component to determine whether the service processed by the target access device in the target secure data link network is within the allowed service range, and controlling the target access device to prohibit processing services that are not within the allowed service range.

9. The method according to any one of claims 1-8, characterized in that, Identifying whether the device accessing the target secure data link network is the target access device includes: Sending security control component identification indication information to the device accessing the target secure data link network, where the security control component identification indication information is the information identified by the security control component; If the security control component identification response information sent by the device accessing the target secure data link network is received, it is determined that the target secure data link network device is not the target access device; If the security control component identification response information sent by the device accessing the target secure data link network is not received, it is determined that the target secure data link network device is the target access device.

10. A security control device, characterized in that, The device is located in a network-side security control device, and the network-side security control device includes a network-side security control component. The device includes: A startup module, configured to start a corresponding container for the target access device in response to identifying that the target access device accesses the target secure data link network, wherein a proxy security control component is pre-configured in the container, the container is located in the network-side security control device, and the target access device is an access device without a security control component; An operation module, configured to operate the proxy security control component in the container; An acquisition module, configured to enable the proxy security control component to acquire device information of the target access device; A login module, configured to log in the target access device in the network-side security control component based on the proxy security control component and the device information; A security control module, configured to perform security control on the target access device based on the network-side security control component.

11. An electronic device, characterized in that, Comprising: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 9.

12. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, they are used to implement the method according to any one of claims 1 to 9.