A method for network access testing of devices, electronic devices, storage media, and software products.

By combining encrypted authentication information, blockchain technology, and multi-level verification methods, the problems of low efficiency and insufficient security in existing technologies for device network access testing have been solved, achieving efficient and secure device network access testing.

CN120238378BActive Publication Date: 2025-10-31ZIGUANG HENGYUE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510725188.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-10-31
Estimated Expiration
2045-06-03

AI Technical Summary

Technical Problem

In existing technologies, device network access detection relies on MAC addresses, resulting in low network access efficiency and a high risk of errors, making it difficult to effectively defend against network attacks.

Method used

By acquiring the first tag data and encrypted authentication information of the device to be connected to the network, generating encrypted authentication information using preset encryption rules, and combining blockchain technology, positioning module, Bluetooth connection information and historical network access behavior data for multi-level verification, the legality and security of the network access request are ensured.

Benefits of technology

It achieves efficient and comprehensive device access detection, improves the security and accuracy of access detection, and prevents unauthorized devices from accessing the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238378B_ABST
    Figure CN120238378B_ABST
Patent Text Reader

Abstract

This application provides a device network access detection method, electronic device, storage medium, and program product. The device seeking network access requests by generating a network access request containing tag data and encrypted authentication information. The network access detection device first verifies the matching degree of the tag data, and simultaneously decrypts the encrypted authentication information to obtain the time information carried within, and then judges the timeliness based on this time information. Only when the tag data matches a preset legitimate tag and the timeliness judgment is passed will the network access detection device approve the device seeking network access, effectively and comprehensively preventing the access of unauthorized devices and significantly improving the comprehensiveness and efficiency of network access detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer network technology, and more specifically, to a device network access detection method, electronic device, storage medium, and program product. Background Technology

[0002] Ensuring legitimate device access to the network is crucial for network security. However, current technologies rely on manual MAC address registration for network access detection, which significantly reduces efficiency and is prone to omissions and errors. Furthermore, with the continuous evolution of cyberattack methods, simply relying on MAC address verification is insufficient to effectively defend against diverse network threats. Once unauthorized devices infiltrate the network, they pose serious security risks to the entire network environment. Therefore, a more comprehensive and efficient device access detection method is urgently needed to address the increasingly complex and ever-changing challenges of network security. Summary of the Invention

[0003] The purpose of this application is to provide a device network access detection method, electronic device, storage medium, and program product to achieve the technical effect of improving the efficiency of device network access detection.

[0004] A first aspect of this application provides a method for network access detection of a device, the method being applied to a network access detection device; the method includes:

[0005] Obtain the network access request of the device to be connected to the network, wherein the network access request includes the first tag data and encrypted authentication information of the device to be connected to the network; the encrypted authentication information is generated by the first tag data and the first time information through a preset encryption rule;

[0006] If the first tag data carried in the network access request is a preset tag, the encrypted authentication information is decrypted according to the decryption rule corresponding to the encryption rule to obtain the decrypted authentication information, which includes the second tag data and the second time information.

[0007] If the second tag data corresponds to the first tag data, and the time difference between the second time information and the reference time does not exceed a preset time difference threshold, then the network access request is approved; the reference time includes the time when the network access request is received or the current time.

[0008] If the second tag data does not correspond to the first tag data or the time difference exceeds the time difference threshold, the network access request is rejected.

[0009] In the above implementation process, by verifying the consistency of the tag data and time information of the device to be connected to the network, efficient and comprehensive device access detection is achieved.

[0010] Furthermore, obtaining the network access request of the device to be accessed includes:

[0011] Receive a request message sent by the device to be connected to the network, the request message carrying the encrypted authentication information and the blockchain identifier;

[0012] The first tag data is obtained from the blockchain indicated by the blockchain identifier, and a network access request including the first tag data and the encrypted authentication information is obtained.

[0013] In the above implementation process, the security of device access to the network is enhanced by obtaining the first tag data of the device to be connected to the network from the blockchain and matching and verifying it with the encrypted authentication information carried in the message.

[0014] Further, the first tag data includes attribute information of the device to be connected to the network, including device name, device serial number, and local area network address. Determining that the first tag data carried in the network access request is a preset tag includes:

[0015] The target compliance attribute information of the device to be connected to the network is obtained from a preset attribute information database. The attribute information database stores compliance attribute information of multiple devices, including device name, device serial number, and local area network address.

[0016] If the attribute information is consistent with the target compliance attribute information, then the first tag data is determined to be the preset tag.

[0017] In the above implementation process, by comparing the attribute information of the device to be connected to the network with the preset compliance attribute information, it is ensured that only devices that meet the prescribed attributes can access the network.

[0018] Further, the first tag data includes first location information collected by the positioning module in the device to be connected to the network; determining that the first tag data carried in the network access request is a preset tag includes:

[0019] If the first location information indicates that the device to be connected to the network is located within a preset area, then the first tag data is determined to be the preset tag.

[0020] In the above implementation process, the device location is verified by the first location information collected by the positioning module, and only devices located within the preset area are allowed to access the network, which effectively restricts the access of unauthorized external devices.

[0021] Further, the first tag data includes the Bluetooth connection information of the device to be connected to the network, and determining that the first tag data carried in the network access request is a preset tag includes:

[0022] If the Bluetooth connection information indicates that the device to be connected to the network is connected to a Bluetooth device located within a preset area, then the first tag data is determined to be the preset tag.

[0023] In the above implementation process, the Bluetooth connection status is used to verify whether the device is within the preset area, providing an additional security verification layer for device network access and restricting the access of unauthorized external devices.

[0024] Further, the first tag data includes the status information of the device to be connected to the network; the status information is used to indicate the geographical location and network configuration information of the device to be connected to the network; determining that the first tag data carried in the network access request is a preset tag includes:

[0025] The predicted geographical location and predicted network configuration status of the device to be connected to the network are determined based on historical network communication data with the device to be connected to the network.

[0026] If the status information indicates that the geographical location of the device to be connected to the network is consistent with the predicted geographical location, and the device to be connected to the network conforms to the predicted network configuration status, then the first tag data is determined to be the preset tag.

[0027] In the above implementation process, the location and configuration status of the device are predicted by combining historical network communication data and compared with real-time information to ensure that the device entering the network is compliant and not counterfeit.

[0028] Furthermore, the method also includes:

[0029] The historical network access behavior data of the device to be connected to the network is obtained. If the historical network access behavior data does not meet the preset normal network access behavior requirements, the network access request is rejected. The historical network access behavior data includes historical network access patterns, historical network access request frequency, and historical network access time.

[0030] In the above implementation process, by analyzing the historical network access behavior data of devices to be connected to the network, abnormal behavior is identified and rejected, effectively preventing potential network attacks and unauthorized device access.

[0031] A second aspect of this application provides an electronic device, the electronic device comprising:

[0032] processor;

[0033] Memory used to store processor-executable instructions;

[0034] Wherein, when the processor invokes the executable instructions, it implements any of the methods described in the first aspect.

[0035] A third aspect of this application provides a computer-readable storage medium having computer instructions stored thereon, which, when executed by a processor, implement the steps of any of the methods described in the first aspect.

[0036] A fourth aspect of this application provides a computer program product, the computer program product including a computer program, which, when executed by a processor, implements any of the methods described in the first aspect. Attached Figure Description

[0037] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0038] Figure 1 A flowchart illustrating a device network access detection method provided in an embodiment of this application;

[0039] Figure 2 This is a structural block diagram of an electronic device provided in an embodiment of this application. Detailed Implementation

[0040] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0041] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0042] In related technologies, if device network access detection relies solely on MAC address consistency verification, it will not only lead to low network access detection efficiency and a high risk of errors, but also make it difficult to effectively deal with such complex network attacks when attackers intercept and tamper with the MAC address in the network access request message.

[0043] To address any of the issues raised above, embodiments of this application provide a method for device network access detection, referring to... Figure 1 , Figure 1 This is a flowchart illustrating a device network access detection method provided in an embodiment of this application.

[0044] In this embodiment, the method is applied to a network access detection device; the method includes:

[0045] Step S10: Obtain the network access request of the device to be connected to the network, wherein the network access request includes the first tag data and encrypted authentication information of the device to be connected to the network; the encrypted authentication information is generated by the first tag data and the first time information through a preset encryption rule;

[0046] Understandably, devices seeking to join the network (such as IoT devices) need to send a network access request to network detection devices (such as gateways or servers) to join the network and interact with data. This request can take the form of a heartbeat message. Heartbeat messages are a common communication signal between devices and the network, used to maintain connection and detect device online status. The heartbeat message carries both initial tag data and encrypted authentication information. The initial tag data can include the unique identifier of the device, such as its electronic tag. The electronic tag can contain the device's MAC address, serial number, device name, etc., and is used to uniquely identify the device within the network. The encrypted authentication information is the result of encrypting the initial tag data and the tag generation time (i.e., the initial time information). This encryption process follows preset encryption rules, which can be based on an encryption algorithm (such as Advanced Encryption Standard, Rivest-Shamir-Adleman encryption, etc.) or involve the use of public and private keys. Encryption ensures the confidentiality of the authentication information and prevents tampering during transmission. Specifically, when a device seeking network access generates a heartbeat message, it first obtains the current time as the tag generation time and uses it, along with the first tag data, as encrypted input. Then, according to preset encryption rules, it uses the corresponding encryption algorithm and key to encrypt the input data, generating encrypted authentication information. This encrypted authentication information, along with the first tag data, is embedded in the heartbeat message and sent to the network access detection device.

[0047] It's important to note that using time information to generate encrypted authentication information serves two main purposes. First, time information is a dynamically changing parameter, ensuring that each generated encrypted authentication message is unique, thus increasing the difficulty of cracking it. Second, by comparing the time difference between the decrypted second time information and the time the network access request was received or the current time, the timeliness of the network access request can be further verified. If the time difference is too large, even if the encrypted authentication information itself is valid, the network access request can be deemed expired, thereby ensuring network stability by intercepting expired requests. In contrast, if encrypted authentication information is generated solely based on tag data, each generated message will be identical (as long as the tag data remains unchanged). This significantly reduces the security of encrypted communication, as attackers can bypass the verification mechanism by intercepting and replaying the encrypted authentication information. Specifically, once an attacker intercepts the encrypted authentication information, they will attempt to resend this information to the network access detection device to try and bypass the normal verification mechanism; this behavior is known as a "replay attack." Because encrypted authentication information contains critical data used to verify the identity of the device seeking network access and ensure information integrity, if the encrypted authentication information is replayed, the network access detection device may mistakenly believe that the information comes from a legitimate device seeking network access and accept this tampered or forged encrypted authentication information.

[0048] Step S20: If the first tag data carried in the network access request is a preset tag, the encrypted authentication information is decrypted according to the decryption rule corresponding to the encryption rule to obtain the decrypted authentication information, which includes the second tag data and the second time information.

[0049] As an example, if the network access request takes the form of a heartbeat message, then when the network access detection device receives the heartbeat message, it first checks whether the first tag data carried in the heartbeat message is a preset tag. The preset tag is a pre-defined set of electronic tags used to identify which devices are authorized to join the network. If the first tag data does not match the preset tag, the network access request for that device is rejected. If the first tag data matches the preset tag, the network access detection device decrypts the encrypted authentication information in the heartbeat message according to the decryption rules corresponding to the encryption rules, obtaining decrypted authentication information. The decrypted authentication information includes second tag data and second time information (i.e., the decryption result of the tag generation time). At this point, the network access detection device further verifies the decrypted authentication information, including tag consistency verification and time validity verification.

[0050] It's important to note that the second tag data and second time information can be obtained from the decrypted encrypted authentication information because the encrypted authentication information is derived from the first tag data and first time information according to certain encryption rules. During decryption, the same key and algorithm used during encryption are used to reverse the process, restoring the original information before encryption, namely the second tag data and second time information. The decrypted information should be identical to the pre-encryption information; that is, the second tag data and second time information should be the same as the first tag data and first time information, respectively.

[0051] Step S30: If the second tag data corresponds to the first tag data, and the time difference between the second time information and the reference time does not exceed a preset time difference threshold, then the network access request is approved; the reference time includes the time when the network access request is received or the current time.

[0052] It's important to note that tag consistency verification—that is, verifying whether the second tag data corresponds to the first tag data—is necessary to ensure that the first tag data has not been tampered with or replaced during transmission. In encrypted communication, even if the encrypted authentication information itself is highly secure and difficult to tamper with, other parts of the network access request data can still be attacked and tampered with. Therefore, tag consistency verification is required to compare whether the decrypted second tag data is completely consistent with the first tag data, thereby determining whether the first tag data has been tampered with during transmission and verifying its authenticity. If the tag consistency verification passes, and the time difference between the decrypted second time information and the time of receiving the network access request or the current time does not exceed the preset time difference threshold, it indicates that the network access request has not been tampered with, and the request does indeed come from a legitimate device within its valid time frame. The network access detection device can accept the network access request and allow the device to join the network. The preset time difference threshold is set to ensure that the network access request is sent within a valid time range, preventing expired or delayed network access requests from being accepted. The time difference threshold can be determined based on the normal arrival time of a network access request, for example, 1 second.

[0053] Furthermore, the reference time is not limited to the moment the network access request is received; it can also refer to the moment the network access request is processed. Setting the reference time to the moment the network access request is processed is to address certain special cases where the network access detection device, upon receiving the request, does not process it immediately but temporarily stores it and processes it at a later time. In this case, the reference time should be adjusted to the actual time the request is processed.

[0054] In practice, the network access request includes the MAC address of the device seeking network access. The network access detection device first identifies the request to extract the MAC address, and then performs tag consistency verification and time difference verification. Only when both verifications are successful will the network access detection device mark the MAC address as legitimate, thus allowing the device to access the network.

[0055] Step S40: If the second tag data does not correspond to the first tag data or the time difference exceeds the time difference threshold, then the network access request is rejected.

[0056] It should be noted that if the second tag data matches the first tag data, it proves that the network access request has not been tampered with and indeed originated from the device corresponding to the tag data. If the second tag data does not match the first tag data, it indicates that there may be identity forgery or request tampering. In this case, to ensure network security, the network access request should be rejected.

[0057] Furthermore, if the time difference exceeds the time difference threshold, it indicates that the encrypted authentication information may have expired or been tampered with during transmission, resulting in a time difference exceeding the threshold. In this case, the network access request should also be rejected.

[0058] In this embodiment, by comprehensively verifying the first tag data, encrypted authentication information and time validity of the device to be connected to the network, a more comprehensive and efficient network access review is achieved, ensuring the legality and security of the device's network access.

[0059] Based on any of the above embodiments, step S10 includes:

[0060] Receive a request message sent by the device to be connected to the network, the request message carrying the encrypted authentication information and the blockchain identifier;

[0061] The first tag data is obtained from the blockchain indicated by the blockchain identifier, and a network access request including the first tag data and the encrypted authentication information is obtained.

[0062] In this embodiment, the first tag data and the encrypted authentication information are sent separately to the network access detection device. The reason for sending the tag data and encrypted authentication information separately is to leverage the immutability of blockchain technology to enhance the security of the tag data. By adopting this strategy, even if the encrypted authentication information is intercepted or tampered with during transmission, the authenticity and security of the tag data can still be guaranteed.

[0063] It should be noted that the request message can specifically be a heartbeat message used to request network access, and the heartbeat message carries encrypted authentication information and a blockchain identifier.

[0064] Specifically, during the process of obtaining the network access request from a device seeking network access, a request message sent by the device is received. This request message embeds encrypted authentication information and a blockchain identifier. The blockchain identifier, as a unique identifier, points to a specific location or data on the blockchain. It guides the network access detection device to retrieve the first tag data of the device seeking network access from the blockchain. The network access detection device parses the blockchain identifier in the request message. After obtaining the blockchain identifier, the device can access the blockchain network or the corresponding blockchain storage system. Then, based on the blockchain identifier, the device locates the corresponding data block or transaction on the blockchain and extracts the first tag data. Thus, a complete network access request containing the first tag data and encrypted authentication information is obtained.

[0065] In this embodiment, by analyzing the received request message from the device to be connected to the network, which carries encrypted authentication information and a blockchain identifier, the network access detection device can obtain the corresponding first tag data from the specified blockchain, thereby constructing a complete network access request containing the first tag data and encrypted authentication information, thus ensuring the security and data integrity of the network access request.

[0066] Based on any of the above embodiments, the first tag data includes attribute information of the device to be connected to the network, the attribute information including device name, device serial number, and local area network address, and determining that the first tag data carried in the network access request is a preset tag includes:

[0067] The target compliance attribute information of the device to be connected to the network is obtained from a preset attribute information database. The attribute information database stores compliance attribute information of multiple devices, including device name, device serial number, and local area network address.

[0068] It should be noted that the device serial number refers to the device's SN (Serial Number), while the local area network address refers to the device's MAC address (Media Access Control Address).

[0069] The attribute information database is a database that stores compliance attribute information for multiple devices, that is, it stores the correspondence between devices and compliance attribute information. This compliance attribute information includes device name, device serial number, and local area network address. This information together constitutes a standard set of attributes for devices that are considered compliant or allowed to access the network.

[0070] Specifically, when a network access request is received from a device seeking network access, the network access detection device first searches for relevant information about the device in its attribute information database. The goal of this search is to find the compliance attribute information corresponding to the device, i.e., the target compliance attribute information. Next, the network access detection device compares the attribute information provided by the device with the target compliance attribute information retrieved from the attribute information database. The comparison includes verifying whether the device name, device serial number, and local area network address are completely identical. Through this comparison, the network access detection device can determine whether the device meets the compliance requirements for network access.

[0071] If the attribute information is consistent with the target compliance attribute information, then the first tag data is determined to be the preset tag.

[0072] Specifically, during the comparison process, if the attribute information of the device seeking network access matches the compliant attribute information stored in the attribute information database, then the device can be confirmed as compliant. In this case, the first tag data provided by the device is considered a compliant tag, i.e., a preset tag. This also means that the device meets all network access standards and should therefore be allowed to access the network. Conversely, if inconsistencies are found in the attribute information during the comparison process, it may indicate that the first tag data of the device seeking network access has been tampered with during transmission, or that the device itself does not meet compliance requirements. In this case, the device cannot be considered compliant, and its provided first tag data cannot be considered a preset tag. Therefore, the network access request of this device should be rejected to ensure network security.

[0073] In this embodiment, by analyzing the attribute information of the device to be connected to the network and comparing it with the compliance attribute information stored in the preset attribute information database, if the two are consistent, it can be effectively confirmed that the first tag data carried in the network access request is the preset tag, thereby ensuring that the device is connected to the network in compliance with regulations.

[0074] Based on any of the above embodiments, the first tag data includes first location information collected by the positioning module in the device to be connected to the network; determining that the first tag data carried in the network access request is a preset tag includes:

[0075] If the first location information indicates that the device to be connected to the network is located within a preset area, then the first tag data is determined to be the preset tag.

[0076] It should be noted that the built-in or external positioning module in the device to be connected to the network is responsible for collecting the device's geographical location information, i.e., the primary positioning information. This positioning module can be a GPS module, a BeiDou module, a Wi-Fi positioning module, a Bluetooth positioning module, etc. The primary positioning information can specifically be represented as GNSS (Global Navigation Satellite System) data, which mainly includes the device's latitude and longitude coordinates.

[0077] In applications requiring strict control over device access (such as corporate intranets, enterprise campus networks, and smart cities), a preset area refers to a geographical region pre-defined in the network management system. Only devices located within this area are considered compliant and eligible for network access. The boundaries of the preset area can be fixed or dynamically adjusted. Preset areas can be defined by drawing polygons, circles, or other shapes on a map, or by setting latitude and longitude ranges, city names, address ranges, etc.

[0078] In practice, when a device initiates a network access request, its initial location information is sent to the network access detection device. The network access detection device parses this location information and compares it with a preset area. If the initial location information indicates that the device is within the preset area, then the device is in a geographical location permitted by the network management policy, and therefore the device's initial tag data (at least in terms of location information) can be considered compliant. Conversely, if the initial location information indicates that the device is not within the preset area, the network access detection device will reject the device's network access request or require the device to move to the preset area before re-initiating the request. This helps prevent unauthorized devices from accessing the network from unmonitored geographical locations.

[0079] In this embodiment, by introducing location information as a condition for network access detection, it can be ensured that only devices located in compliant geographical locations can access the network, thereby enhancing network security.

[0080] Based on any of the above embodiments, the first tag data includes the Bluetooth connection information of the device to be connected to the network, and determining that the first tag data carried in the network access request is a preset tag includes:

[0081] If the Bluetooth connection information indicates that the device to be connected to the network is connected to a Bluetooth device located within a preset area, then the first tag data is determined to be the preset tag.

[0082] It should be noted that the built-in or external Bluetooth module in the device to be connected to the network is responsible for communicating with other Bluetooth devices and collecting connection information, i.e., Bluetooth connection information. This information includes the MAC address, device name, and connection status of the connected Bluetooth device.

[0083] In a network management system, a set of Bluetooth devices can be pre-defined as compliant access points, forming a pre-defined list of Bluetooth devices. These compliant Bluetooth devices are located in specific geographical locations, such as within a company premises, corporate campus, meeting room, or within the coverage area of ​​a home network. A pre-defined area refers to the geographical region associated with the pre-defined Bluetooth devices; only Bluetooth connections within this area are considered compliant. This area can be fixed or dynamically adjusted.

[0084] Specifically, when a device seeking network access initiates a network access request, its Bluetooth connection information is sent to the network access detection device. The network access detection device parses this information to determine the MAC address or device name of the Bluetooth device connected to the device seeking network access, and compares it with a pre-defined list of Bluetooth devices. Given the limitations of Bluetooth communication technology, its communication range is relatively short. Therefore, when the Bluetooth connection information indicates that the device seeking network access has successfully connected to a Bluetooth device within a pre-defined area, it can be reasonably inferred that the device's current location complies with network management policies, and its Bluetooth communication status is compliant. Based on this, the device's first tag data (at least in terms of the Bluetooth connection information) can be considered compliant. If the Bluetooth connection information indicates that the device seeking network access is not connected to any Bluetooth device within a pre-defined area, or has connected to a Bluetooth device not in the pre-defined list, the network access detection device will reject the device's network access request, or require the device to move to a pre-defined area and retry the connection request. This helps prevent unauthorized devices from accessing the network through insecure Bluetooth connections.

[0085] In addition, Bluetooth connection information may include the location information of the Bluetooth device. Based on the location information of the Bluetooth device, it can be determined whether the device to be connected to the network is located in a preset area. If the device to be connected to the network is located in a preset area, the first tag data is determined to be a preset tag.

[0086] In this embodiment, by analyzing the Bluetooth connection information of the device to be connected to the network, if the information indicates that the device has successfully connected to a Bluetooth device located in a preset area, the first tag data can be confirmed as a preset tag. This mechanism not only improves the verification accuracy of device access to the network, but also effectively utilizes the short-range communication characteristics of Bluetooth technology to enhance network security protection, ensuring that only devices located in a specific area and meeting the connection conditions can access the network.

[0087] Based on any of the above embodiments, the first tag data includes the status information of the device to be connected to the network; the status information is used to indicate the geographical location and network configuration information of the device to be connected to the network; determining that the first tag data carried in the network access request is a preset tag includes:

[0088] The predicted geographical location and predicted network configuration status of the device to be connected to the network are determined based on historical network communication data with the device to be connected to the network.

[0089] It should be noted that the geographic location can be a specific coordinate point or a region, reflecting the current location of the device; while the network configuration information describes the device's configuration status in the network environment, such as whether it supports specific network protocols, whether it has specific network permissions, and whether specific network security settings are enabled.

[0090] There is long-term network communication between the device seeking network access and the network access detection device. The device seeking network access periodically sends network access requests to the network access detection device. The specific form of these requests can be heartbeat messages, which contain the real-time geographical location and network configuration status of the device seeking network access. By analyzing the historical heartbeat messages sent by the device seeking network access, the network access detection device can predict the possible location of the device seeking network access at a future time, as well as its network configuration status at that future time (the predicted network configuration status may include the device's network access point, IP address, subnet mask, etc.).

[0091] If the status information indicates that the geographical location of the device to be connected to the network is consistent with the predicted geographical location, and the device to be connected to the network conforms to the predicted network configuration status, then the first tag data is determined to be the preset tag.

[0092] Specifically, when a device seeking network access sends a new heartbeat message, the message contains the device's current real-time geographical location and network configuration status. The network access detection device compares this real-time information with previous predictions based on historical data. If the real-time information matches the prediction, it indicates that the device's location and network configuration status have not changed abnormally, and the device can be preliminarily determined to be compliant, with the first tag data confirming the preset tag, thus advancing the subsequent network access detection process. If the real-time information does not match the prediction, it indicates that the information may have been tampered with during transmission, or that the device's location and network configuration status have changed abnormally. In this case, the device can be determined to be non-compliant and should not be allowed to access the network.

[0093] In this embodiment, by combining the device's geographical location information and network configuration information, and utilizing historical data prediction and current status verification, the accuracy and reliability of device authentication are improved, thereby enhancing the comprehensiveness and accuracy of network access detection.

[0094] Based on any of the above embodiments, the method further includes:

[0095] The historical network access behavior data of the device to be connected to the network is obtained. If the historical network access behavior data does not meet the preset normal network access behavior requirements, the network access request is rejected. The historical network access behavior data includes historical network access patterns, historical network access request frequency, and historical network access time.

[0096] Understandably, in the process of managing device network access, in addition to verifying the tag data of the device to be added to the network, the analysis of its historical network access behavior data is equally important. Analyzing its historical network access behavior data aims to predict its possible network access intentions by evaluating the device's past behavior, and based on this, decide whether to allow it to access the network at present.

[0097] It should be noted that historical network access patterns, such as when and how a device typically attempts to access the network, can be determined by the pattern of historical heartbeat messages when the network access request is presented as a heartbeat message. Historical network access request frequency: the number of times a device initiates a network access request within a certain period. Historical network access time: the specific time point at which the device successfully accesses the network.

[0098] As an example, an abnormal behavior detection model based on machine learning can be established to analyze the heartbeat message patterns, access frequency, and access time of devices, identifying and blocking abnormal or potential malicious behaviors in the network. Furthermore, access control policies can be dynamically adjusted based on the historical behavior of devices and changes in the network environment, such as adding verification steps within specific time periods, restricting access permissions for high-risk devices, or triggering additional security audits.

[0099] In practice, historical network access behavior data is compared with preset normal network access behavior requirements. If the historical network access behavior data of the device to be connected to the network does not meet the preset normal network access behavior requirements, such as the device frequently initiating network access requests at abnormal times, or its network access pattern being significantly different from that of known security devices, then the network access detection device will consider the device to be connected to the network to potentially pose a security risk and will therefore reject its network access request.

[0100] In this embodiment, by introducing historical network access behavior data of the device to be connected to the network (including historical network access patterns, historical network access request frequency, and historical network access time) as a judgment basis, and rejecting the network access request when it does not meet the preset normal network access behavior requirements, it can effectively identify and prevent potential malicious devices from accessing the network and improve the accuracy of network access detection.

[0101] Based on the methods described in any of the above embodiments, this application also provides, as follows: Figure 2 The diagram shows the structure of an electronic device. Figure 2At the hardware level, the electronic device includes a processor, an internal bus, a network interface, memory, and non-volatile memory, and may also include other hardware required for business operations. The processor reads the corresponding computer program from the non-volatile memory into memory and then runs it to implement the methods described in any of the above embodiments.

[0102] Based on the methods described in any of the above embodiments, this application also provides a computer storage medium storing a computer program, which, when executed by a processor, can be used to perform the methods described in any of the above embodiments.

[0103] Based on the methods described in any of the above embodiments, this application also provides a computer program product, which includes one or more computer programs or instructions. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. When executed by a processor, the computer program implements the methods described in any of the above embodiments.

[0104] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0105] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0106] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0107] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0108] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0109] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A method for network access testing of equipment, characterized in that, The method is applied to network access testing equipment; the method includes: Obtain a network access request from a device seeking network access, wherein the network access request includes first tag data and encrypted authentication information of the device seeking network access; the encrypted authentication information is generated by the first tag data and first time information through a preset encryption rule; the first tag data includes the status information and Bluetooth connection information of the device seeking network access; the status information is used to indicate the geographical location and network configuration information of the device seeking network access. The predicted geographical location and predicted network configuration status of the device to be connected to the network are determined based on historical network communication data with the device to be connected to the network. If, based on the status information, it is determined that the geographical location of the device to be connected to the network is consistent with the predicted geographical location, and the device to be connected to the network conforms to the predicted network configuration status, and the Bluetooth connection information indicates that the device to be connected to the network is connected to a Bluetooth device located in a preset area, the encrypted authentication information is decrypted according to the decryption rule corresponding to the encryption rule to obtain the decrypted authentication information, which includes second tag data and second time information. If the second tag data corresponds to the first tag data, and the time difference between the second time information and the reference time does not exceed a preset time difference threshold, then the network access request is approved; the reference time includes the time when the network access request is received or the current time. Obtain historical network access behavior data of the device to be connected to the network; the historical network access behavior data includes historical network access patterns, historical network access request frequency, and historical network access time; The historical network access behavior data is input into the abnormal behavior detection model to obtain the behavior pattern detection results; If the second tag data does not correspond to the first tag data, or the time difference exceeds the time difference threshold, or the behavior pattern detection result indicates that the device to be connected to the network has abnormal behavior, then the network access request is rejected.

2. The method as described in claim 1, characterized in that, The process of obtaining the network access request from the device to be connected to the network includes: Receive a request message sent by the device to be connected to the network, the request message carrying the encrypted authentication information and the blockchain identifier; The first tag data is obtained from the blockchain indicated by the blockchain identifier, and a network access request including the first tag data and the encrypted authentication information is obtained.

3. The method as described in claim 1, characterized in that, The first tag data also includes attribute information of the device to be connected to the network. The attribute information includes the device name, device serial number, and local area network address. When the geographical location of the device to be connected to the network is determined to be consistent with the predicted geographical location based on the status information, and the device to be connected to the network conforms to the predicted network configuration status, and the Bluetooth connection information indicates that the device to be connected to the network is connected to a Bluetooth device located within a preset area, the encrypted authentication information is decrypted according to the decryption rule corresponding to the encryption rule to obtain decrypted authentication information, including: The target compliance attribute information of the device to be connected to the network is obtained from a preset attribute information database. The attribute information database stores compliance attribute information of multiple devices, including device name, device serial number, and local area network address. If, based on the status information, it is determined that the geographical location of the device to be connected to the network is consistent with the predicted geographical location, and the device to be connected to the network conforms to the predicted network configuration status, and the Bluetooth connection information indicates that the device to be connected to the network is connected to a Bluetooth device located in a preset area, and the attribute information is consistent with the target compliance attribute information, the encrypted authentication information is decrypted according to the decryption rule corresponding to the encryption rule to obtain the decrypted authentication information.

4. The method as described in claim 1, characterized in that, The first tag data also includes first location information collected by the positioning module in the device to be connected to the network; when the geographical location of the device to be connected to the network is determined to be consistent with the predicted geographical location based on the status information, and the device to be connected to the network conforms to the predicted network configuration status, and the Bluetooth connection information indicates that the device to be connected to the network is connected to a Bluetooth device located in a preset area, the encrypted authentication information is decrypted according to the decryption rule corresponding to the encryption rule to obtain decrypted authentication information, including: If, based on the status information, it is determined that the geographical location of the device to be connected to the network is consistent with the predicted geographical location, and the device to be connected to the network conforms to the predicted network configuration status, and the Bluetooth connection information indicates that the device to be connected to the network is connected to a Bluetooth device located within a preset area, and the first positioning information indicates that the device to be connected to the network is located within a preset area, the encrypted authentication information is decrypted according to the decryption rule corresponding to the encryption rule to obtain the decrypted authentication information.

5. An electronic device, characterized in that, The electronic device includes: processor; Memory used to store processor-executable instructions; Wherein, when the processor invokes the executable instructions, it implements the method according to any one of claims 1-4.

6. A computer-readable storage medium, characterized in that, It stores computer instructions that, when executed by a processor, implement the steps of any of the methods described in claims 1-4.

7. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-4.

Citation Information

Patent Citations

  • Security authentication method and system

    CN111885597A

  • Network access method and device, electronic equipment and storage medium

    CN113595744A