Equipment network access detection method, electronic equipment, storage medium and program product
By generating and decrypting encrypted authentication information, combining time difference and blockchain technology to verify device tag data, the problems of low efficiency and insufficient security of equipment access detection in the existing technology are solved, and efficient and secure access detection are achieved.
Patent Information
- Application Number
- CN202510725188.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-06-03
AI Technical Summary
In the prior art, device network access detection relies on MAC addresses, resulting in low network access efficiency and error-proneness, making it difficult to effectively resist complex network attacks.
By obtaining the tag data and encrypted authentication information of the devices to be entered, using encryption rules to generate and decrypt the authentication information, combining time difference verification and blockchain technology, ensuring the consistency of tag data and time information, and refusing illegal devices to access the network.
It realizes efficient and comprehensive equipment network access inspection, improves the security and accuracy of network access inspection, and prevents the access of illegal equipment.
Smart Images

Figure CN120238378A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer network technologies, and in particular, to a device network access detection method, an electronic device, a storage medium, and a program product. Background Art
[0002] The legal network access of devices is an important link to ensure network security. However, in the related technologies, the device network access detection process relies on manual registration of MAC addresses, which not only greatly reduces the network access efficiency, but also easily causes omissions and errors. In addition, with the continuous evolution of network attack means, it has become difficult to effectively resist diverse network threats simply by verifying MAC addresses. Once unauthorized devices mix into the network, it will bring serious security risks to the entire network environment. In view of this, there is an urgent need for a more comprehensive and efficient device network access detection method to cope with the increasingly complex and changeable network security challenges. Summary of the Invention
[0003] The purpose of the embodiments of this application is to provide a device network access detection method, an electronic device, a storage medium, and a program product, so as to achieve the technical effect of improving the device network access detection efficiency.
[0004] In the first aspect of the embodiments of this application, a device network access detection method is provided. The method is applied to a network access detection device. The method includes: Obtain a network access request of a device to be networked, where the network access request includes first tag data of the device to be networked and encrypted authentication information; the encrypted authentication information is generated by the first tag data and first time information through a preset encryption rule; When the first tag data carried in the network access request is a preset tag, decrypt the encrypted authentication information according to the decryption rule corresponding to the encryption rule to obtain decrypted authentication information, where the decrypted authentication information includes second tag data and second time information; If the second tag data corresponds to the first tag data, and the time difference between the second time information and a reference time does not exceed a preset time difference threshold, then pass the network access request; the reference time includes the time when the network access request is received or the current time; If the second tag data does not correspond to the first tag data or the time difference exceeds the time difference threshold, then reject the network access request.
[0005] In the above implementation process, by verifying the consistency of the tag data and time information of the device to be networked, efficient and comprehensive device network access detection is achieved.
[0006] Further, the obtaining of the network access request of the device to be networked includes: Receive a request message sent by the device to be networked, where the request message carries the encrypted authentication information and the blockchain identifier; Obtain the first tag data from the blockchain indicated by the blockchain identifier, and obtain an access request including the first tag data and the encrypted authentication information.
[0007] In the above implementation process, by obtaining the first tag data of the device to be networked from the blockchain and performing matching verification with the encrypted authentication information carried in the message, the security of device networking is enhanced.
[0008] Further, the first tag data includes the attribute information of the device to be networked, and the attribute information includes the device name, device serial number, and local area network address. Determining that the first tag data carried in the access request is a preset tag includes: Obtain the target compliance attribute information of the device to be networked from a preset attribute information library, where the attribute information library stores the compliance attribute information of multiple devices including the device name, device serial number, and local area network address; If the attribute information is consistent with the target compliance attribute information, determine that the first tag data is the preset tag.
[0009] In the above implementation process, by comparing the attribute information of the device to be networked with the preset compliance attribute information, it is ensured that only devices with specified attributes can access the network.
[0010] Further, the first tag data includes the first positioning information collected by the positioning module in the device to be networked; determining that the first tag data carried in the access request is a preset tag includes: If the first positioning information indicates that the device to be networked is located within a preset area, determine that the first tag data is the preset tag.
[0011] In the above implementation process, the first positioning information collected by the positioning module is used to verify the device location, and only devices located within the preset area are allowed to access the network, effectively restricting the access of external illegal devices.
[0012] Further, the first tag data includes the Bluetooth connection information of the device to be networked. Determining that the first tag data carried in the access request is a preset tag includes: If the Bluetooth connection information indicates that the device to be networked is connected to a Bluetooth device located within a preset area, determine that the first tag data is the preset tag.
[0013] In the above implementation process, by verifying whether the device is within the preset area through the Bluetooth connection status, an additional security verification layer is provided for device networking, restricting the access of external illegal devices.
[0014] Further, the first tag data includes status information of the device to be networked; the status information is used to indicate the geographical location and network configuration information of the device to be networked; determining that the first tag data carried in the network access request is a preset tag includes: Determining the predicted geographical location and predicted network configuration status of the device to be networked based on historical network communication data with the device to be networked; If the status information indicates that the geographical location of the device to be networked is consistent with the predicted geographical location, and the device to be networked meets the predicted network configuration status, then determine that the first tag data is the preset tag.
[0015] In the above implementation process, the location and configuration status of the device are predicted by combining historical network communication data and compared with real-time information to ensure that the networked device is compliant and not forged.
[0016] Further, the method further includes: Obtaining historical network access behavior data of the device to be networked, and rejecting the network access request if the historical network access behavior data does not meet the requirements of preset normal network access behavior; wherein, the historical network access behavior data includes historical network access rules, historical network access request frequencies, and historical network access times.
[0017] In the above implementation process, by analyzing the historical network access behavior data of the device to be networked, abnormal behaviors are identified and rejected, effectively preventing potential network attacks and illegal device access.
[0018] A second aspect of the embodiments of the present application provides an electronic device, where the electronic device includes: A processor; A memory for storing executable instructions of the processor; Wherein, when the processor calls the executable instructions, the method according to any one of the first aspect is implemented.
[0019] A third aspect of the embodiments of the present application provides a computer-readable storage medium, on which computer instructions are stored, and when the computer instructions are executed by a processor, the steps of the method according to any one of the first aspect are implemented.
[0020] A fourth aspect of the embodiments of the present application provides a computer program product, where the computer program product includes a computer program, and when the computer program is executed by a processor, the method according to any one of the first aspect is implemented. Description of the Drawings
[0021] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0022] Figure 1 It is a schematic flowchart of a device network access detection method provided by an embodiment of the present application; Figure 2 It is a structural block diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0023] The following will describe the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application.
[0024] It should be noted that: similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first" and "second" are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0025] In the related art, if the device network access detection only relies on the consistency verification of the MAC address, it will not only lead to low network access detection efficiency and easy errors, but also when an attacker intercepts and tampers with the MAC address in the network access request packet, this single verification method will be difficult to effectively cope with such complex network attacks.
[0026] In view of any of the above problems, the embodiments of the present application provide a device network access detection method. Refer to Figure 1 , Figure 1 It is a schematic flowchart of a device network access detection method provided by an embodiment of the present application.
[0027] In this embodiment, the method is applied to a network access detection device; the method includes: Step S10: Obtain a network access request of a device to be networked, where the network access request includes first tag data of the device to be networked and encrypted authentication information; the encrypted authentication information is generated by the first tag data and first time information according to a preset encryption rule; It is understandable that a device to be networked (such as an Internet of Things device) needs to send a network access request to a network access detection device (such as a gateway, a server, etc.) in order to join the network for data interaction. The specific form of this network access request can be a heartbeat message. As a conventional signal for communication between the device and the network, the heartbeat message is used to maintain the connection status and detect the online status of the device. The heartbeat message carries both first tag data and encrypted authentication information at the same time. The first tag data can include the unique identifier of the device to be networked, such as the electronic tag of the device to be networked. The electronic tag can be the MAC address, serial number, device name, etc. of the device, and the electronic tag is used to uniquely identify the device in the network. The encrypted authentication information is the result of encrypting the first tag data and the tag generation time (the tag generation time is the first time information). This encryption process follows a preset encryption rule, and these rules can be implemented based on a certain encryption algorithm (such as Advanced Encryption Standard, Rivest-Shamir-Adleman encryption, etc.), or can involve the use of public and private keys. Through encryption processing, the confidentiality of the authentication information can be ensured, preventing it from being tampered with during transmission. Specifically, when generating the heartbeat message, the device to be networked will first obtain the current time as the tag generation time, and use it together with the first tag data as the input for encryption. Then, according to the preset encryption rule, use the corresponding encryption algorithm and key to encrypt the input data to generate the encrypted authentication information. This encrypted authentication information and the first tag data are embedded in the heartbeat message and sent to the network access detection device together.
[0028] It should be noted that the reason why time information is used to generate encrypted authentication information is that time information is a dynamically changing parameter, which makes each generated encrypted authentication information unique, thereby increasing the difficulty of cracking. Secondly, by comparing the time difference between the decrypted second time information and the time when the network access request is received or the current time, the timeliness of the network access request can be further verified. If the time difference is too large, then even if there is no problem with the encrypted authentication information itself, the network access request can be determined to be expired, thereby ensuring the stability of the network by intercepting expired network access requests. In contrast, if the encrypted authentication information is generated only based on the tag data, the encrypted authentication information generated each time will be the same (as long as the tag data remains unchanged), which will greatly reduce the security of encrypted communication, because the attacker can bypass the verification mechanism by intercepting and replaying the encrypted authentication information. Specifically, once the attacker intercepts the encrypted authentication information, the attacker will try to resend the information to the network access detection device in an attempt to bypass the normal verification mechanism. This behavior is called a "replay attack." Since the encrypted authentication information contains key data used to verify the identity of the device to be connected to the network and ensure the integrity of the information, if the encrypted authentication information is replayed, the network access detection device may mistakenly believe that the information comes from a legitimate device to be connected to the network and accept this tampered or forged encrypted authentication information.
[0029] Step S20: when the first tag data carried in the network access request is a preset tag, decrypt the encrypted authentication information according to a decryption rule corresponding to the encryption rule to obtain decrypted authentication information, wherein the decrypted authentication information includes second tag data and second time information; As an example, if the specific form of the network access request is a heartbeat message, then when the network access detection device receives the heartbeat message, it will first check whether the first label data carried in the heartbeat message is a preset label, wherein the preset label is a pre-set set of electronic labels used to identify which devices are authorized to join the network. When the first label data does not match the preset label, the network access request of the device is rejected. When the first label data matches the preset label, the network access detection device will decrypt the encrypted authentication information in the heartbeat message according to the decryption rules corresponding to the encryption rules to obtain the decrypted authentication information, and the decrypted authentication information includes the second label data and the second time information (i.e., the decryption result of the label generation time). At this time, the network access detection device will further verify the decrypted authentication information, wherein the verification includes label consistency verification and time validity verification.
[0030] It should be noted that the reason why the second tag data and the second time information can be obtained from the decrypted encrypted authentication information is that the encrypted authentication information is obtained based on the first tag data and the first time information according to certain encryption rules. During the decryption process, the same key and algorithm used during encryption are used to perform reverse operations on the encrypted authentication information, and the original information before encryption, that is, the second tag data and the second time information, can be restored. The decrypted information should be consistent with the information before encryption, that is, the second tag data and the second time information should be the same as the first tag data and the first time information respectively.
[0031] Step S30: If the second tag data corresponds to the first tag data and the time difference between the second time information and the reference time does not exceed a preset time difference threshold, then pass the network access request; the reference time includes the time when the network access request is received or the current time; It should be noted that the reason for performing tag consistency verification, that is, verifying whether the second tag data corresponds to the first tag data, is to ensure that the first tag data has not been tampered with or replaced during transmission. In encrypted communication, even though the encrypted authentication information itself has high security and is not easily tampered with, other parts of the data in the network access request may still be attacked and tampered with. Therefore, it is necessary to perform tag consistency verification to compare whether the decrypted second tag data is exactly the same as the first tag data, so as to determine whether the first tag data has been tampered with during transmission and verify the authenticity of the first tag data. If the tag consistency verification passes and the time difference between the decrypted second time information and the time when the network access request is received or the current time does not exceed the preset time difference threshold, it indicates that the network access request has not been tampered with and the request indeed comes from a legitimate device within the valid time limit. The network access detection device can accept this network access request and allow the device to access the network. Among them, the preset time difference threshold is set to ensure that the network access request is sent within a valid time range and prevent expired or delayed network access requests from being accepted. The time difference threshold can be determined according to the normal sending and arrival duration of the network access request, for example, it is 1 second.
[0032] In addition, the reference time is not limited to the moment when the network access request is received, but can also refer to the moment when the network access request is processed. Setting the reference time as the moment when the network access request is processed is to deal with some special situations, that is, when the network access detection device does not immediately process the network access request after receiving it, but temporarily stores the request and processes it at a later time. In this case, the reference time should be adjusted to the actual time point when the request is processed.
[0033] In the specific implementation process, the network access request will carry the MAC address of the device to be networked. The network access detection device first identifies the request to extract the MAC address, and then performs label consistency verification and time difference verification. When both of these verifications are successfully passed, the network access detection device will mark the MAC address as legal, thereby allowing this device to access the network.
[0034] Step S40: If the second label data does not correspond to the first label data or the time difference exceeds the time difference threshold, reject the network access request.
[0035] It should be noted that if the second label data matches the first label data, it can prove that the network access request has not been tampered with and indeed comes from the device corresponding to the label data. If the second label data does not match the first label data, it indicates that there may be identity forgery or request tampering. In this case, to ensure network security, the network access request should be rejected.
[0036] In addition, if the time difference exceeds the time difference threshold, it means that the encrypted authentication information may have expired or been tampered with during transmission, resulting in the time difference being too large and exceeding the time difference threshold. In this case, the network access request should also be rejected.
[0037] In this embodiment, by comprehensively verifying the first label data, encrypted authentication information and its time validity of the device to be networked, a more comprehensive and efficient network access review is achieved, ensuring the legality and security of device network access.
[0038] Based on any of the above embodiments, step S10 includes: Receiving a request message sent by the device to be networked, the request message carrying the encrypted authentication information and the blockchain identifier; Obtaining the first label data from the blockchain indicated by the blockchain identifier to obtain a network access request including the first label data and the encrypted authentication information.
[0039] In this embodiment, the first label data and the encrypted authentication information are separately sent to the network access detection device. The reason for separately sending the label data and the encrypted authentication information is to utilize the immutability of blockchain technology to enhance the security of the label data. By adopting the strategy of separately sending the label data and the encrypted authentication information, even if the encrypted authentication information is intercepted or tampered with during transmission, the authenticity and security of the label data can be guaranteed.
[0040] It should be noted that the request message can specifically be a heartbeat message for requesting network access, and the heartbeat message carries the encrypted authentication information and the blockchain identifier.
[0041] Specifically, in the process of obtaining the network access request of the device to be networked, a request message sent by the device to be networked is received. This request message is embedded with encrypted authentication information and a blockchain identifier. Among them, the blockchain identifier, as a unique identifier, points to a specific location or data on the blockchain. The blockchain identifier is used to guide the network access detection device to retrieve the first tag data of the device to be networked from the blockchain. The network access detection device will parse the blockchain identifier in the request message. After obtaining the blockchain identifier through parsing, the network access detection device can access the blockchain network or the corresponding blockchain storage system. Then, the network access detection device will locate the corresponding data block or transaction on the blockchain according to the blockchain identifier and extract the first tag data from it. Thus, a complete network access request including the first tag data and the encrypted authentication information can be obtained.
[0042] In this embodiment, by analyzing the request message of the device to be networked received, which carries encrypted authentication information and a blockchain identifier, the network access detection device can obtain the corresponding first tag data from the specified blockchain, thereby constructing a complete network access request including the first tag data and the encrypted authentication information, thus ensuring the security and data integrity of the network access request.
[0043] Based on any of the above embodiments, the first tag data includes the attribute information of the device to be networked, and the attribute information includes the device name, the device serial number, and the local area network address. Determining that the first tag data carried in the network access request is a preset tag includes: Obtaining the target compliance attribute information of the device to be networked from a preset attribute information library, where the attribute information library stores the compliance attribute information of multiple devices including the device name, the device serial number, and the local area network address; It should be noted that the device serial number refers to the SN (Serial Number) of the device, and the local area network address refers to the MAC address (Media Access Control Address) of the device.
[0044] The attribute information library is a database that stores the compliance attribute information of multiple devices, that is, it stores the correspondence between the devices and the compliance attribute information. These compliance attribute information cover the device name, the device serial number, and the local area network address. These information together constitute a standard attribute set of the devices considered to be compliant or allowed to access the network.
[0045] Specifically, when receiving an access request from a device to be accessed to the network, the access detection device first searches for relevant information of the device to be accessed to the network in the attribute information database. The goal of the search is to find the compliant attribute information corresponding to the device to be accessed to the network, that is, the target compliant attribute information. Next, the access detection device will compare the attribute information provided by the device to be accessed to the network with the target compliant attribute information obtained from the attribute information database. The content of the comparison includes whether the device name, device serial number, and local area network address are exactly the same. Through the comparison, the access detection device can determine whether the device to be accessed to the network meets the compliant requirements for network access.
[0046] If the said attribute information is consistent with the said target compliant attribute information, it is determined that the said first tag data is the said preset tag.
[0047] Specifically, during the comparison process, if the attribute information of the device to be accessed to the network is consistent with the compliant attribute information stored in the attribute information database, then it can be confirmed that the device to be accessed to the network is compliant. At this time, the first tag data provided by the device to be accessed to the network is regarded as the tag that meets the requirements, that is, the preset tag. This also means that the device to be accessed to the network meets all the standards for network access, so it should be allowed to access the network. On the contrary, if it is found during the comparison process that there are inconsistencies in the attribute information, then this may indicate that the first tag data of the device to be accessed to the network has been tampered with during the transmission process, or the device to be accessed to the network itself does not meet the compliant requirements. In this case, it cannot be considered that the device to be accessed to the network is compliant, and the first tag data it provides cannot be regarded as the preset tag. Therefore, the access request of this device to be accessed to the network should be rejected to ensure the security of the network.
[0048] In this embodiment, by analyzing and comparing the attribute information of the device to be accessed to the network with the compliant attribute information stored in the preset attribute information database, if the two are consistent, it can be effectively confirmed that the first tag data carried in the access request is the preset tag, thereby ensuring that the device accesses the network in compliance.
[0049] Based on any of the above embodiments, the said first tag data includes the first positioning information collected by the positioning module in the said device to be accessed to the network; determining that the first tag data carried in the said access request is the preset tag includes: If the said first positioning information indicates that the said device to be accessed to the network is located within the preset area, it is determined that the said first tag data is the said preset tag.
[0050] It should be noted that the positioning module built in or externally connected to the device to be accessed to the network is responsible for collecting the geographical location information of the device to be accessed to the network, that is, the first positioning information. This positioning module can be a GPS module, a Beidou module, a Wi-Fi positioning module, a Bluetooth positioning module, etc. The first positioning information can be specifically expressed as GNSS (Global Navigation Satellite System) data, which mainly contains the longitude and latitude coordinate data of the device.
[0051] In applications that require strict control over device access scenarios (such as company intranets, enterprise campus networks, smart cities, etc.), a preset area refers to a geographical area pre-set in the network management system. Only devices located in this area are considered compliant and eligible for network access. The boundaries of a preset area can be fixed or dynamically adjusted. A preset area can be defined by drawing a polygon, circle, or other shape on a map, or by setting a latitude and longitude range, city name, address range, etc.
[0052] In a specific implementation, when the device to be networked initiates a network access request, the first positioning information it carries will be sent to the network access detection device. The network access detection device will parse this positioning information and compare it with the preset area. If the first positioning information indicates that the device is located in the preset area, it means that the device is in a geographical location allowed by the network management policy, so it can be considered that the first tag data of the device (at least in terms of the positioning information) is compliant. In addition, if the first positioning information indicates that the device is not in the preset area, the network access detection device will reject the device's network access request, or require the device to move to the preset area and then re-initiate the request. This helps prevent unauthorized devices from accessing the network from unmonitored geographical locations.
[0053] In this embodiment, by introducing positioning information as a condition for network access detection, it can be ensured that only devices located in a compliant geographical location can access the network, thereby enhancing the security of the network.
[0054] Based on any of the above embodiments, the first tag data includes Bluetooth connection information of the device to be networked, and determining that the first tag data carried in the network access request is a preset tag includes: If the Bluetooth connection information indicates that the network access device is connected to a Bluetooth device located in a preset area, it is determined that the first tag data is the preset tag.
[0055] It should be noted that the built-in or external Bluetooth module in the device to be connected to the network is responsible for communicating with other Bluetooth devices and collecting connection information, namely Bluetooth connection information. This information includes the MAC address, device name, connection status, etc. of the connected Bluetooth device.
[0056] In the network management system, some Bluetooth devices can be pre-set as compliant access points. These compliant Bluetooth devices form a preset Bluetooth device list. Compliant Bluetooth devices are located in specific geographical locations, such as within a company, within an enterprise campus, in a conference room, within the coverage of a home network, etc. The preset area refers to the geographical area associated with the preset Bluetooth device. Only Bluetooth connection information within this area is considered compliant. This area can be fixed or dynamically adjusted.
[0057] Specifically, when a device to be networked initiates a network access request, the Bluetooth connection information it carries is sent to the network access detection device. The network access detection device will parse this information to determine the MAC address or device name of the Bluetooth device connected to the device to be networked, and compare it with a preset list of Bluetooth devices. Given the limitations of Bluetooth communication technology, its communication distance is relatively short. Therefore, when the Bluetooth connection information indicates that the device to be networked has successfully connected to a Bluetooth device within a preset area, it can be reasonably inferred that the current location of the device meets the requirements of the network management policy, and its Bluetooth communication status complies with the regulations. Based on this, it can be determined that the first tag data of the device (at least in terms of this part of the Bluetooth connection information) is compliant. If the Bluetooth connection information indicates that the device to be networked is not connected to any Bluetooth device within the preset area, or is connected to a Bluetooth device not in the preset list, then the network access detection device will reject the device's network access request, or require the device to move to the preset area and retry the connection before initiating the request. This helps prevent unauthorized devices from accessing the network through insecure Bluetooth connections.
[0058] In addition, the Bluetooth connection information may include the location information of the Bluetooth device. Based on the location information of the Bluetooth device, it can be known whether the device to be networked is located within the preset area. If the device to be networked is located within the preset area, then the first tag data is determined to be the preset tag.
[0059] In this embodiment, by analyzing the Bluetooth connection information of the device to be networked, if the information indicates that the device has successfully connected to a Bluetooth device located within the preset area, the first tag data can be confirmed as the preset tag. This mechanism not only improves the verification accuracy of device network access, but also effectively utilizes the short-distance communication characteristics of Bluetooth technology to enhance network security protection, ensuring that only devices in a specific area and meeting the connection conditions can access the network.
[0060] Based on any of the above embodiments, the first tag data includes the status information of the device to be networked; the status information is used to indicate the geographical location and network configuration information of the device to be networked; determining that the first tag data carried in the network access request is the preset tag includes: Determining the predicted geographical location and predicted network configuration status of the device to be networked based on the historical network communication data with the device to be networked; It should be noted that the geographical location can be a specific coordinate point or a regional range, which reflects the current location of the device; while the network configuration information describes the configuration status of the device in the network environment, such as whether it supports a specific network protocol, whether it has specific network permissions, and whether specific network security settings are enabled.
[0061] There is long-term network communication between the device to be networked and the network access detection device. The device to be networked will regularly send network access requests to the network access detection device. The specific form of these network access requests can be heartbeat messages, and these heartbeat messages contain the real-time geographical location and network configuration status of the device to be networked. By analyzing the historical heartbeat messages sent by the device to be networked, the network access detection device can predict the possible location of the device to be networked at a certain future moment and the network configuration status at a certain future moment (the predicted network configuration status can include the network access point, IP address, subnet mask, etc. of the device to be networked).
[0062] If the status information indicates that the geographical location of the device to be networked is consistent with the predicted geographical location, and the device to be networked meets the predicted network configuration status, then determine the first tag data as the preset tag.
[0063] Specifically, when the device to be networked sends a new heartbeat message, the message will contain the current real-time geographical location and network configuration status of the device to be networked. The network access detection device compares this real-time information with the previous prediction based on historical data. If the real-time information is consistent with the predicted information, it indicates that there is no abnormal change in the location and network configuration status of the device, and it can be preliminarily determined that the device to be networked is compliant, and the first tag data is indeed the preset tag, thereby promoting the subsequent network access detection process. If the real-time information is inconsistent with the predicted information, it indicates that the information may have been tampered with during transmission, or the location and network configuration status of the device have changed abnormally. At this time, it can be determined that the device to be networked is non-compliant and should not be connected to the network.
[0064] In this embodiment, by combining the geographical location information and network configuration information of the device, using the prediction of historical data and the verification of the current state, the accuracy and reliability of device identity verification are improved, thereby improving the comprehensiveness and accuracy of network access detection.
[0065] Based on any of the above embodiments, the method further includes: Obtain the historical network access behavior data of the device to be networked, and reject the network access request if the historical network access behavior data does not meet the preset normal network access behavior requirements; wherein, the historical network access behavior data includes historical network access rules, historical network access request frequencies, and historical network access times.
[0066] It can be understood that in the process of device network access management, in addition to verifying the tag data of the device to be networked, the analysis of its historical network access behavior data is equally important. Analyzing its historical network access behavior data aims to predict its possible network access intention by evaluating the device's past behavior, and accordingly decide whether to allow it to access the network at present.
[0067] It should be noted that the historical network access rules: for example, when and in what way the device usually attempts to access the network. In the case where the specific form of the network access request is a heartbeat message, the historical network access rules can be determined by the pattern of the historical heartbeat messages. Historical network access request frequency: the number of network access requests initiated by the device within a certain period of time. Historical network access time: the specific time point when the device successfully accesses the network.
[0068] As an example, an anomaly behavior detection model based on machine learning is established to analyze the heartbeat message pattern, access frequency, access time, etc. of the device, and identify and intercept abnormal or potential malicious behaviors in the network. In addition, the access control policy can be dynamically adjusted according to the historical behavior of the device and changes in the network environment, such as adding verification steps during specific time periods, restricting the access rights of high-risk devices, or triggering additional security reviews.
[0069] In the specific implementation, the historical network access behavior data is compared with the preset normal network access behavior requirements. If the historical network access behavior data of the device to be networked does not meet the preset normal network access behavior requirements, for example, the device frequently initiates network access requests at abnormal times, or its network access rules are significantly different from those of known secure devices, then the network access detection device will consider that the device to be networked may have security risks, and thus will reject its network access request.
[0070] In this embodiment, by introducing the historical network access behavior data of the device to be networked (including historical network access rules, historical network access request frequency, and historical network access time) as the judgment basis, and rejecting the network access request when it does not meet the preset normal network access behavior requirements, it is possible to effectively identify and prevent potential malicious devices from accessing the network, and improve the accuracy of network access detection.
[0071] Based on the method described in any of the above embodiments, the present application also provides a Figure 2 structural schematic diagram of an electronic device as shown. As Figure 2 , at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory. Of course, it may also include other hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the method described in any of the above embodiments.
[0072] Based on the method described in any of the above embodiments, the present application also provides a computer storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, it can be used to execute the method described in any of the above embodiments.
[0073] Based on the method described in any of the above embodiments, the present application further provides a computer program product, which includes one or more computer programs or instructions. The computer program or instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. When the computer program is executed by a processor, the method described in any of the above embodiments is implemented.
[0074] In several embodiments provided by the present application, it should be understood that the disclosed apparatus and method can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of the apparatus, method, and computer program product according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0075] In addition, in each embodiment of the present application, the various functional modules can be integrated together to form an independent part, or each module can exist separately, or two or more modules can be integrated to form an independent part.
[0076] If the function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0077] The above are only the embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, the present application may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0078] As described above, these are only the specific implementation manners of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all of them should be covered by the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
[0079] It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
Claims
1. A device network access detection method, characterized in that, The method is applied to an access network detection device; the method includes: Obtain an access network request of a device to be accessed, where the access network request includes first tag data and encrypted authentication information of the device to be accessed; the encrypted authentication information is generated by the first tag data and first time information through a preset encryption rule; When the first tag data carried in the access network request is a preset tag, decrypt the encrypted authentication information according to a decryption rule corresponding to the encryption rule to obtain decrypted authentication information, where the decrypted authentication information includes second tag data and second time information; If the second tag data corresponds to the first tag data and the time difference between the second time information and a reference time does not exceed a preset time difference threshold, then pass the access network request; the reference time includes the time when the access network request is received or the current time; If the second tag data does not correspond to the first tag data or the time difference exceeds the time difference threshold, then reject the access network request.
2. The method according to claim 1, wherein The obtaining of the access network request of the device to be accessed includes: Receive a request message sent by the device to be accessed, where the request message carries the encrypted authentication information and a blockchain identifier; Obtain the first tag data from the blockchain indicated by the blockchain identifier to obtain an access network request including the first tag data and the encrypted authentication information.
3. The method according to claim 1, characterized in that, The first tag data includes attribute information of the device to be accessed, and the attribute information includes a device name, a device serial number, and a local area network address. Determining that the first tag data carried in the access network request is a preset tag includes: Obtain target compliance attribute information of the device to be accessed from a preset attribute information library, where the attribute information library stores compliance attribute information of multiple devices including a device name, a device serial number, and a local area network address; If the attribute information is consistent with the target compliance attribute information, then determine that the first tag data is the preset tag.
4. The method according to claim 1, characterized in that, The first tag data includes first positioning information collected by a positioning module in the device to be accessed; determining that the first tag data carried in the access network request is a preset tag includes: If the first positioning information indicates that the device to be accessed is located within a preset area, then determine that the first tag data is the preset tag.
5. The method according to claim 1, wherein The first tag data includes Bluetooth connection information of the device to be accessed; determining that the first tag data carried in the access network request is a preset tag includes: If the Bluetooth connection information indicates that the device to be accessed is connected to a Bluetooth device located within a preset area, then determine that the first tag data is the preset tag.
6. The method according to claim 1, wherein The first tag data includes status information of the device to be accessed; the status information is used to indicate the geographical location and network configuration information of the device to be accessed; Determining that the first tag data carried in the access network request is a preset tag includes: Determine the predicted geographical location and predicted network configuration status of the device to be accessed based on historical network communication data with the device to be accessed; If the status information indicates that the geographical location of the device to be networked is consistent with the predicted geographical location, and the device to be networked meets the predicted network configuration status, then determine the first tag data as the preset tag.
7. The method according to claim 1, wherein The method further includes: Obtaining historical network access behavior data of the device to be networked, and rejecting the network access request if the historical network access behavior data does not meet the requirements of the preset normal network access behavior; wherein, the historical network access behavior data includes historical network access patterns, historical network access request frequencies, and historical network access times.
8. An electronic device, characterized in that, The electronic device includes: A processor; A memory for storing instructions executable by the processor; Wherein, when the processor calls the executable instructions, the method according to any one of claims 1-7 is implemented.
9. A computer-readable storage medium, characterized in that, A computer instruction is stored thereon, and when the computer instruction is executed by the processor, the steps of the method according to any one of claims 1-7 are implemented.
10. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is executed by the processor, the method according to any one of claims 1-7 is implemented.
Citation Information
Patent Citations
Systems and methods for generating location based entitlements
CN106416316A
Security authentication method and system
CN111885597A
Multi-agent management method and architecture based on Internet of Things, equipment and storage medium
CN113194012A
Method and system for network access authentication of intelligent device
CN113285807A
Network access method and device, electronic equipment and storage medium
CN113595744A
Cited By
Encryption authentication method and system for power monitoring system
CN120834954A
Encryption authentication method and system for power monitoring system
CN120834954B