Access permission query method and system, related equipment and storage medium

By preconfiguring access policies on network devices and querying based on the identity of end users and application users, the problems of high deployment costs and low access efficiency in the prior art are solved, and efficient access rights control is achieved.

CN120263431APending Publication Date: 2025-07-04HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410009365.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-02
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In enterprise networks, the prior art requires real-time refresh of access control list (ACL) rules by network management devices to control user access rights, resulting in high deployment costs and low access efficiency.

Method used

Network devices are pre-configured with access policies, and query the access policies locally based on the application user identity and terminal user identity of the terminal device to determine whether access is allowed, reducing dependence on network management devices.

Benefits of technology

Reduces the cost of deploying network management equipment, improves the efficiency of access permission query, and reduces configuration change time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263431A_ABST
    Figure CN120263431A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an access permission query method and system, related equipment and a storage medium, which are applied to the technical field of communication and are used for realizing that network equipment queries access permissions of a terminal user under different application users. The method provided by the embodiment of the invention comprises the following steps: network equipment acquires an application user identity of terminal equipment according to an access message, wherein the access message is used for the terminal equipment to request to access a server; and the network equipment queries in a preset access strategy according to the application user identity and the terminal user identity to obtain a query result, wherein the query result is used for indicating whether the terminal equipment has the authority of accessing the server or not. According to the embodiment of the invention, the network equipment has the capability of querying the network authority of the terminal equipment, so that additional network management equipment or network management software does not need to be deployed, and the deployment cost is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of communication technologies, and in particular, to a method, a system, related devices, and a storage medium for querying access permissions. Background Art

[0002] In an enterprise network, to ensure the security of application systems, different network access policies need to be deployed for different users on network devices to achieve allowing only specific users to access specific applications. For example, only the first user is allowed to access the first application, and the first user is not allowed to access the second application; only the second user is allowed to access the second application, and the second user is not allowed to access the first application. At this time, access control policies need to be deployed on network devices to block access packets from the first user to the second application and from the second user to the first application. The access control policy is also referred to as the user network access permission.

[0003] In a traditional campus network, controlling the access permissions of users to applications on network devices is mainly achieved through the access control list (ACL) technology. Administrators pre-configure ACL rules on network devices, and generally, the rules are organized using a whitelist. When a user sends a packet, the network device searches for ACL rules for matching. If a permit rule is found in the search and match, the packet is allowed to pass; if a deny rule is found in the search and match, the packet is discarded. The administrator or network management device confirms the application users on the server. For example, if the application user is an employee, the action of the rule with the source address as a visitor and the destination address as a screen mirroring server on the network device is refreshed to deny; if the application user is a visitor, the configuration rule on the network device is refreshed to permit.

[0004] Since it is necessary to view and refresh the ACL rules in real time through a network management device, when deploying a server, a network management device or software needs to be deployed, thus increasing the deployment cost. At the same time, since refreshing the ACL rules is a configuration change action, it takes a long time, resulting in low access efficiency for access permissions. Summary of the Invention

[0005] The embodiments of the present application disclose a method, a system, related devices, and a storage medium for querying access permissions, which are used to enable a network device to query the access permissions of a terminal user under different application users, and can enable the network device to have the ability to query the network permissions of a terminal device. Therefore, there is no need to deploy an additional network management device or network management software, thereby reducing the deployment cost.

[0006] The first aspect of the present application provides a method for querying access rights. The execution subject of this method can be a network device, or a component or device applied to the network device (such as a processor, a chip, or a chip system, etc.), or a logical module or software that can implement all or part of the functions of the network device. In this method, when a terminal device needs to access a server, it needs to send an access message to the network device, and the network device determines whether the terminal device has access rights. After receiving the access message from the terminal device, the network device obtains the application user identity of the terminal device according to the access message. The application user is the terminal user who holds the application rights in the current application. The network device can also obtain the terminal user identity of the terminal device in the internet protocol (IP) header of the message. The network device queries in a preset access policy according to the terminal user identity and the application user identity of the terminal device to obtain a query result. The access policy includes the corresponding relationship between the terminal user identity, the application user identity, and the access rights. The query result is used to indicate whether the terminal device has the right to access the server.

[0007] In this embodiment, since the network device can query the application user identity in the preset access policy, there is no need to deploy an additional network management device or network management software to refresh the access policy, thus reducing the deployment cost.

[0008] In some optional embodiments, after the network device queries the access policy, it will perform corresponding operations according to the query result. For example, if the query result is "permit", that is, the terminal device has the right to access the server, the network device forwards the access message to the server; if the query result is "deny", the terminal device does not have the right to access the server, the network device discards the access message.

[0009] In this embodiment, since the network device does not need to refresh the UCL rules and only needs to query the access policy to obtain the query result, the time consumed is reduced, thus improving the access efficiency.

[0010] In some optional embodiments, the network device can find the corresponding application user identity by the application user name. Specifically, the network device parses the access message to obtain the application user name of the terminal device, and then finds the corresponding application user identity according to the application user name.

[0011] In this embodiment, the network device can obtain the application user name according to the access message, so as to obtain the corresponding application user identity. Therefore, there is no need for a network management device or network management software to view the current application user on the server, reducing the deployment cost and improving the access efficiency.

[0012] In some alternative embodiments, the network device can obtain the destination address of the access packet based on the access packet, and the destination address is used to indicate the server to be accessed by the terminal device. The network device puts the destination address into a query packet and sends the query packet to the server. The network device receives a feedback packet from the server, and the feedback packet includes the application username of the terminal device.

[0013] In this embodiment, when the access packet does not include the application username or the access packet is encrypted for transmission, the network device can interface with the server to obtain the application username of the terminal device, reducing the cost of deploying network management devices or network management software.

[0014] In some alternative embodiments, when the access packet is transmitted in plaintext and includes the application username, the network device can directly parse the application username from the payload of the access packet.

[0015] In some alternative embodiments, the network device can look up the application user identity corresponding to the application username locally.

[0016] In this embodiment, since the network device can look up the application user identity corresponding to the application username locally, there is no need to deploy additional network management devices or network management software to query the server, reducing the deployment cost and improving the access efficiency.

[0017] A second aspect of this application provides an access permission query method. In this method, the server receives a query packet from the network device, and the query packet is used to request a query for the application username of the terminal device. The server obtains the application username according to the query packet and sends a feedback packet to the network device, and the feedback packet includes the application username.

[0018] In some alternative embodiments, the server obtains the destination address of the terminal device in the query packet, and the destination address is used to indicate the application that the terminal device needs to access. The server determines the application username of the terminal device according to the destination address.

[0019] In this embodiment, when the access packet does not include the application username or the access packet is encrypted for transmission, the network device can interface with the server to obtain the application username of the terminal device, reducing the cost of deploying network management devices or network management software.

[0020] A third aspect of this application provides a network device, including:

[0021] An obtaining unit, configured to obtain the application user identity of the terminal device according to an access packet, where the access packet is used for the terminal device to request access to a server;

[0022] A query unit, configured to query in a preset access policy according to the application user identity and the terminal user identity to obtain a query result, where the access policy includes the corresponding relationship between the terminal user identity, the application user identity, and the access permission, and the query result is used to indicate whether the terminal device has the permission to access the server.

[0023] Based on the third aspect, optionally, it further includes a processing unit;

[0024] The processing unit is configured to, after querying in the preset access policy according to the application user identity and the terminal user identity, if the terminal device has the permission to access the server, the network device forwards the access message to the server; if the terminal device does not have the permission to access the server, the network device discards the access message.

[0025] Based on the third aspect, optionally, the obtaining unit includes:

[0026] A parsing module, configured to parse the access message to obtain the application user name of the terminal device;

[0027] A searching module, configured to search for the application user identity corresponding to the application user name.

[0028] Based on the third aspect, optionally, the parsing module is specifically configured to:

[0029] Send a query message to the server, where the query message is used to request the server to query the application user name;

[0030] Receive a feedback message from the server, where the feedback message includes the application user name.

[0031] Based on the third aspect, optionally, the parsing module is specifically configured to:

[0032] Parse the application user name from the payload of the access message.

[0033] Based on the third aspect, optionally, the searching module is specifically configured to:

[0034] Search for the application user identity corresponding to the application user name locally.

[0035] A server provided by the fourth aspect of the present application includes:

[0036] A receiving unit, configured to receive a query message from the network device, where the query message is used for the network device to request the server to query the application user name of the terminal device;

[0037] An obtaining unit, configured to obtain the application user name according to the query message;

[0038] A sending unit, configured to send a feedback message to the network device, where the feedback message includes the application user name.

[0039] Based on the fourth aspect, optionally, the obtaining unit is specifically configured to:

[0040] Obtain the destination address of the terminal device in the query message, where the destination address is used to indicate the application that the terminal device needs to access;

[0041] Determine the application username of the terminal device according to the destination address.

[0042] A fifth aspect of the present application provides a network device, including: a processor and a communication interface,

[0043] The communication interface is configured to receive a signal from the terminal device or the server and transmit it to the processor, or send a signal from the processor to the server. The processor uses logic circuits or executes code instructions for the network device to implement the method described in the foregoing first aspect.

[0044] A sixth aspect of the present application provides a server, including: a processor and a communication interface,

[0045] The communication interface is configured to receive a signal from the network device and transmit it to the processor, or send a signal from the processor to the network device. The processor uses logic circuits or executes code instructions for the server to implement the method described in the foregoing second aspect.

[0046] A seventh aspect of the present application provides an access permission query system, including:

[0047] A terminal device, and the network device described in the foregoing third aspect, and the server described in the foregoing fourth aspect;

[0048] Or,

[0049] A terminal device, and the network device described in the foregoing third aspect.

[0050] An eighth aspect of the present application provides a computer-readable storage medium, including instructions. When the instructions run on a computer, the computer is caused to execute the method described in the foregoing first aspect, or the computer is caused to execute the method described in the foregoing second aspect.

[0051] A ninth aspect of the present application provides a computer program product containing instructions. When it runs on a computer, the computer is caused to execute the method described in the foregoing first aspect, or the computer is caused to execute the method described in the foregoing second aspect.

[0052] The beneficial effects of the third aspect to the ninth aspect can be understood by referring to the beneficial effects of the first aspect and its corresponding implementation manners and the second aspect and its corresponding implementation manners, and will not be elaborated here specifically. Description of the Drawings

[0053] Figure 1 It is a schematic diagram of an embodiment of the network architecture in the embodiment of the present application;

[0054] Figure 2 It is a schematic diagram of an embodiment of access policy configuration in the embodiment of the present application;

[0055] Figure 3 It is a schematic diagram of an application scenario of the access permission query method applicable to the embodiment of the present application;

[0056] Figure 4 It is a schematic diagram of another application scenario of the access permission query method applicable to the embodiment of the present application;

[0057] Figure 5 It is a schematic diagram of an embodiment of the access permission query method in the embodiment of the present application;

[0058] Figure 6 It is a schematic diagram of another embodiment of the access permission query method in the embodiment of the present application;

[0059] Figure 7 It is a schematic diagram of an embodiment of the access message format in the embodiment of the present application;

[0060] Figure 8 It is a schematic diagram of an embodiment of the network device in the embodiment of the present application;

[0061] Figure 9 It is a schematic diagram of an embodiment of the server in the embodiment of the present application;

[0062] Figure 10 It is a schematic diagram of another embodiment of the network device in the embodiment of the present application;

[0063] Figure 11 It is a schematic diagram of an embodiment of the server in the embodiment of the present application. Detailed implementation manners

[0064] The embodiment of the present application provides an access permission query method, system, related device and storage medium, which are applied to the field of communication technology and are used to implement the network device to query the access permission of the end user under different application users.

[0065] The embodiments of the present application will be described below with reference to the accompanying drawings. It can be known to those of ordinary skill in the art that with the development of technology and the emergence of new scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0066] In the description, claims and drawings of this application, terms such as "first" and "second" are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same attributes when describing embodiments of this application. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device including a series of units does not have to be limited to those units, but may include other units not clearly listed or inherent to these processes, methods, products or devices.

[0067] In this application, "for indicating" may include for direct indication and for indirect indication. When describing that a certain indication information is used to indicate A, it may include that the indication information directly indicates A or indirectly indicates A, and does not mean that A must be carried in the indication information.

[0068] In addition, the specific indication method can also be various existing indication methods, such as but not limited to, the above indication methods and their various combinations, etc. The specific details of various indication methods can refer to the prior art and will not be elaborated herein. As can be seen from the above, for example, when it is necessary to indicate multiple pieces of information of the same type, there may be a situation where the indication methods of different pieces of information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiments of this application do not limit the selected indication method. In this way, the indication methods involved in the embodiments of this application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0069] In the embodiments of this application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device will perform corresponding processing under a certain objective situation, which does not limit the time, and does not require the device to have a judgment action when implemented, nor does it mean that there are other limitations.

[0070] Please refer to Figure 1 , and the network architecture on which the access permission query method in the embodiments of this application is based will be briefly described below:

[0071] The terminal device 101 accesses the server 103 through the network device 102. An application is hosted on the server 103. The terminal device 101 sends an access message to the network device 102 to request access to the application on the server 103. Figure 1 The terminal device in can be referred to as a user equipment (UE) or a mobile station (MS) or a mobile terminal (MT), etc. Specifically, Figure 1The terminal device in [description] can be a mobile phone, a tablet computer, or a computer with wireless transceiver function. It can also be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in remote medical treatment, a wireless terminal in smart grid, a wireless terminal in smart city, a wireless terminal in smart home, a vehicle-mounted terminal, a vehicle with vehicle-to-vehicle (V2V) communication capability, a connected vehicle, a drone with unmanned aerial vehicle to unmanned aerial vehicle (UAV to UAV, U2U) communication capability, and so on. Figure 1 The network device in [description] can be a router, a switch, a firewall, or a load balancer.

[0072] In an enterprise network, to ensure the security of the application system, different network access policies need to be deployed on the network device for different users to achieve that only specific users are allowed to access specific applications. For example, as Figure 2 shown, two terminal devices correspond to user-1 and user-2 respectively, and applications -1 and -2 are hosted on the server. When only user-1 is allowed to access application-1 and not allowed to access application-2, and only user-2 is allowed to access application-2 and not allowed to access application-1, an access control policy needs to be deployed on the network device to block the access packets from user-1 to application-2 and from user-2 to application-1. The access control policy is also known as the user network access permission.

[0073] Figure 3 Shows an application scenario applicable to this application. In a conference room, the presenter projects the content to be presented onto the conference large screen by screen mirroring, and other conference participants watch the conference large screen. When the conference room is large, there may be some positions far from the conference large screen, which may easily lead to unclear viewing of the conference large screen. At this time, the conference system supports the drag-screen function, allowing non-presenters to drag the content on the conference large screen to their local terminal devices for viewing. From the perspective of information security, when an internal employee of the company projects and presents on the large screen, external visitors are not allowed to drag the screen to avoid information security leakage incidents. When an external visitor projects and presents, internal employees are allowed to drag the screen. As Figure 3As shown, Employee 1, Employee 2, and the visitor are in the same meeting room. When an employee casts the screen, other employees can drag the screen, but the visitor cannot. When the visitor casts the screen, the employees can drag the screen. That is, Employee 1 casts the interface on their computer to the meeting large screen through the screen mirroring software. Employee 2 can drag the screen to view, while the visitor cannot. When the visitor casts the interface on their computer to the meeting large screen through the screen mirroring software, Employees 1 and 2 can drag the screen to view.

[0074] Figure 3 It includes 3 terminal devices. Employee 1, Employee 2, and the visitor are the terminal user identities corresponding to each terminal device respectively. When a terminal device needs to perform a screen dragging operation, it needs to send an access message to the network device to request access to the screen mirroring server for the screen dragging operation. There is network management software configured on the network device, which is responsible for real-time viewing of the application users on the screen mirroring server, that is, the terminal users currently holding the screen mirroring permission, and refreshing the ACL rules on the network device according to the application users. As Figure 3 shown, the application user on the screen mirroring server is Employee 1. At this time, Employee 2 can drag the screen, while the visitor cannot. Therefore, the network management software refreshes the ACL rules on the network device and sets the action with the source IP address being the visitor and the destination IP address being the screen mirroring server to deny. The specific ACL rules are shown in Table 1 below:

[0075] Table 1:

[0076] Source IP Address Destination IP Address Action Employee 1 Network Segment Address Large Screen Server Address permit Employee 2 Network Segment Address Large Screen Server Address permit Visitor Network Segment Address Large Screen Server Address deny

[0077] It can be understood that in order to avoid restricting users to move only within the range of one network segment, the source address can be a user group. A user group is an integer identification (ID). This ID is decoupled from the IP address network segment, so that users can move within any network segment and still maintain their permissions unchanged. This policy is called the user group-based policy, and the corresponding ACL rule is called the user control list (UCL) rule. The corresponding UCL rules are shown in Table 2 below:

[0078] Table 2:

[0079]

[0080]

[0081] When the network device receives an access message from the terminal device, it discards the message with the source IP address being the visitor user group ID and the destination IP address being the screen mirroring server according to the action in the UCL rule and does not forward it to the screen mirroring server.

[0082] Figure 4Another application scenario is shown. When the application user on the screen mirroring server is a visitor, at this time both Employee 1 and Employee 2 can perform screen dragging. The network management software sets the action corresponding to the UCL rule with the source IP as the visitor user group ID and the destination IP address as the large screen server to permit. The specific UCL rule is shown in Table 3:

[0083] Table 3:

[0084] Source IP Address Destination IP Address Action Employee User Group ID Large Screen Server Address permit Visitor User Group ID Large Screen Server Address permit

[0085] When the network device receives an access packet from the terminal device, it forwards the packet with the source IP address as the visitor user group ID and the destination IP address as the screen mirroring server to the screen mirroring server according to the action in the UCL rule.

[0086] However, in this embodiment, it is necessary to additionally deploy a network management device or network management software to view the application users on the server in real time, resulting in additional deployment overhead and increased deployment costs. At the same time, since refreshing the UCL rule is a configuration change action, it generally takes seconds, so that the response speed is slow every time the terminal device needs to access the server, resulting in low access efficiency.

[0087] In view of this, please refer to Figure 5 , in the embodiment of the present application, the network administrator pre-configures an access policy on the network device, that is, user access rights, and the network device processes the access packets from the terminal device according to the user access rights. After receiving the access packet, the network device queries in the local access policy and performs forwarding or discarding actions on the access packet according to the query result.

[0088] Please refer to Figure 6 , an access right query method in the embodiment of the present application includes:

[0089] 601. The network administrator configures an access policy;

[0090] The network management administrator pre-configures access policies on network devices. The access policies include multiple UCL rules. Each UCL rule includes an end user, an application user, a destination IP address, and an action. The application user is the end user who currently holds the application permission. Taking screen mirroring as an example, both the end user and the application user include employees and visitors. The end user is the user who needs to perform the screen mirroring operation, and the application user is the user who is currently performing screen mirroring. The destination IP address is the address of the large screen server, and the action is used to indicate the operation that the network device performs on the access packet. In practical applications, the action in the UCL rule can have multiple representation methods. For example, "permit" can be used to indicate that the end user has the access permission, enabling the network device to forward the access packet to the server; "deny" can be used to indicate that the end user does not have the access permission, causing the network device to discard the access packet. Or, "allow" can be used to indicate that the network device can forward the access packet corresponding to the terminal device, and "block" can be used to indicate that the network device needs to discard the access packet corresponding to the terminal device. Specifically, it is not limited here. The UCL rules are specifically shown in Table 4 below:

[0091] Table 4:

[0092] End User Application User Destination Address Action Employee User Group ID Employee User Group ID Large Screen Server permit Visitor User Group ID Employee User Group ID Large Screen Server deny Employee User Group ID Visitor User Group ID Large Screen Server permit Visitor User Group ID Visitor User Group ID Large Screen Server permit

[0093] Among them, the end user in Table 4 is the user corresponding to the terminal device that sends the packet, and the application user is the user who holds the screen mirroring permission on the large screen server. The user group is a collection of multiple users. For example, the application user group is a collection of user identities on multiple application servers. The configured range of the application user group is from 0 to 4096.

[0094] It can be understood that the end user or the application user can be one or more of the user group ID, IP / IP network segment, and port number. Specifically, it is not limited here.

[0095] In the embodiment of the present application, since the UCL rules corresponding to the application users are pre-configured on the network device, it is not necessary to deploy additional network management devices or network management software to view the application users on the server. The network device can match the corresponding UCL rules according to the application users and the end users and perform corresponding operations, reducing the deployment cost and improving the access efficiency.

[0096] 602. The network device receives an access packet from the terminal device;

[0097] When the terminal device needs to access the server, it needs to send an access packet to the network device. The access packet can be a Transmission Control Protocol (TCP) packet or other types of packets. Specifically, it is not limited here. Taking the access packet as a TCP packet as an example, as Figure 7As shown, the TCP packet is included in the IP packet, and the IP packet is included in the MAC packet. The header of the IP packet includes the source IP address and destination IP address of the packet, and the header of the TCP packet includes the source port number and destination port number of the packet.

[0098] 603. The network device finds the identity of the end user according to the access packet;

[0099] The network device determines the identity of the end user of the terminal device according to the source IP address in the IP packet header. For example, the network device determines that the identity of the end user corresponding to the terminal device is an employee or a visitor according to the source IP address. If in Table 4, the end user in the UCL rule configured by the network device is represented by the source port number, the network device can determine the identity of the end user corresponding to the terminal device according to the source port number in the TCP packet header, and the specific details are not limited here.

[0100] 604. The network device finds the identity of the application user according to the access packet;

[0101] The network device can obtain the application user name corresponding to the terminal device according to the access packet, and then find the corresponding application user identity according to the application user name. Specifically, when the access packet is transmitted in plain text and the payload includes the application user name, the network device can obtain the application user name corresponding to the terminal device from the payload of the access packet. When the access packet is transmitted encrypted, or the application user name is not carried in the payload, the network device needs to interface with the server to obtain the application user name of the terminal device.

[0102] The network device sends a query packet to the server to request to query the application user name on the server. Specifically, the access packet includes the destination IP address or destination port number, and the network device carries the destination IP address or destination port number in the query packet and sends it to the server. The server finds the corresponding application according to the destination IP address or destination port number carried in the query packet and obtains the application user name. The server carries the application user name in the feedback packet and sends the feedback packet to the network device.

[0103] The network device searches for the corresponding application user identity based on the obtained application user name. When the application user name exists on the network device, the network device can search for the application user identity locally. When the application user name does not exist on the network device, the network device can search on the authentication server. The authentication server can be a radius server or other authentication servers, and specific details are not limited here. When the application user name does not exist on both the network device and the authentication server, the network device will report an error or perform a preset action. For example, the network configurator pre-sets that when the application user name does not exist on both the network device and the authentication server, the network device will discard the access message, and specific details are not limited here.

[0104] 605. The network device searches for an access policy based on the end-user identity and the application user identity;

[0105] The network device searches for the corresponding UCL rule in the access policy according to the obtained end-user identity and application user identity. For example, the network device determines that the end-user identity is a visitor and the application user identity is an employee based on the access message. According to Table 4, when the end-user is a visitor, the application user is an employee, and the destination address is the large-screen server, the corresponding action is deny, that is, the query result is that the terminal device does not have the permission to access the server.

[0106] 606. The network device decides to discard or forward the message according to the search result;

[0107] The search result is used to indicate whether the terminal device has the permission to access the server. The search result can be the specific operation performed by the network device, such as forwarding or discarding, or it can indicate that the network device performs a specific operation, such as permit or deny. Taking screen mirroring as an example, when the end-user is a visitor, the application user is an employee, and the destination address is the large-screen server, the corresponding action is deny, that is, the query result is that the terminal device does not have the permission to access the server. At this time, the network device discards the access message.

[0108] In the embodiment of the present application, since querying the UCL rule is not a configuration change action, the access time can be saved, thereby improving the access efficiency.

[0109] The configuration verification method in the embodiment of the present application is described above. Next, the network device in the embodiment of the present application is described. Please refer to Figure 8, in an embodiment of the present application, the network device may be a router, a switch, a firewall, or a load balancer, or may also be a component or device applied to the network device (such as a processor, a chip, or a chip system, etc.), or may also be a logical module or software that can implement all or part of the network device, which can implement the functions of the network device in the above method, or may also be a part of the script or application program running on the network device, etc. An embodiment of the network device includes:

[0110] An obtaining unit 801, configured to obtain the application user identity of the terminal device according to the access message, where the access message is used for the terminal device to request access to the server;

[0111] A query unit 802, configured to query in a preset access policy according to the application user identity and the terminal user identity to obtain a query result, where the access policy includes the corresponding relationship between the terminal user identity, the application user identity, and the access permission, and the query result is used to indicate whether the terminal device has the permission to access the server.

[0112] Optionally, the network device further includes a processing unit 803, configured to, after querying in the preset access policy according to the application user identity and the terminal user identity, if the terminal device has the permission to access the server, the network device forwards the access message to the server; if the terminal device does not have the permission to access the server, the network device discards the access message.

[0113] Optionally, the obtaining unit includes:

[0114] A parsing module 801-1, configured to parse the access message to obtain the application user name of the terminal device;

[0115] A searching module 801-2, configured to search for the application user identity corresponding to the application user name.

[0116] Optionally, the parsing module 801-1 is specifically configured to send a query message to the server, where the query message is used to request the server to query the application user name; and receive a feedback message from the server, where the feedback message includes the application user name.

[0117] Optionally, the parsing module 801-1 is specifically configured to: parse the application user name from the payload of the access message.

[0118] Optionally, the searching module 801-2 is specifically configured to: search for the application user identity corresponding to the application user name locally.

[0119] Please refer to Figure 9 , an embodiment of the server in an embodiment of the present application includes:

[0120] A receiving unit 901, configured to receive a query message from a network device, where the query message is used by the network device to request the server to query the application username of a terminal device, and the query message includes the destination address of an access message, and the access message is used by the terminal device to request access to the server;

[0121] An obtaining unit 902, configured to obtain the application username according to the query message;

[0122] A sending unit 903, configured to send a feedback message to the network device, where the feedback message includes the application username.

[0123] Optionally, the obtaining unit is specifically configured to: obtain a destination address, where the destination address is used to indicate the application that the terminal device needs to access; and determine the application username of the terminal device according to the destination address.

[0124] Figure 10 This is a schematic structural diagram of a network device provided by an embodiment of the present application. The network device is implemented by a general bus architecture. The network device may be a network management device or a network element device.

[0125] The network device includes at least one processor 1001, a communication bus 1002, a memory 1003, and at least one communication interface 1004.

[0126] Optionally, the processor 1001 is a general-purpose CPU, NP, microprocessor, or one or more integrated circuits for implementing the solution of the present application. For example, an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The above PLD is a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0127] The communication bus 1002 is used to transmit information between the above components. The communication bus 1002 is divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity, only a thick line is used in the figure to represent it, but it does not mean that there is only one bus or one type of bus.

[0128] Optionally, the memory 1003 is a read-only memory (ROM) or other type of static storage device that can store static information and instructions. Alternatively, the memory 1003 is a random access memory (RAM) or other type of dynamic storage device that can store information and instructions. Alternatively, the memory 1003 is an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. Optionally, the memory 1003 exists independently and is connected to the processor 1001 via the communication bus 1002. Optionally, the memory 1003 and the processor 1001 are integrated together.

[0129] The communication interface 1004 uses any device such as a transceiver for communicating with other devices or communication networks. The communication interface 1004 includes a wired communication interface. Optionally, the communication interface 1004 further includes a wireless communication interface. Among them, the wired communication interface is, for example, an Ethernet interface. The Ethernet interface is an optical interface, an electrical interface, or a combination thereof. The wireless communication interface is a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof, etc.

[0130] In a specific implementation, as an embodiment, the processor 1001 includes one or more CPUs, such as Figure 10 the CPU0 and CPU1 shown in

[0131] In a specific implementation, as an embodiment, the network device includes multiple processors, such as Figure 10 the processor 1001 and the processor 1005 shown in

[0132] In some embodiments, the memory 1003 is used to store the program code 1006 for executing the solution of this application, and the processor 1001 executes the program code 1006 stored in the memory 1003. That is to say, the network device realizes the above method embodiments through the processor 1001 and the program code 1006 in the memory 1003.

[0133] Figure 11 FIG. 4 is a schematic structural diagram of a server provided by an embodiment of this application. The server 1100 may include one or more central processing units (CPUs) 1101 and a memory 1105. One or more application programs or data are stored in the memory 1105.

[0134] Among them, the memory 1105 may be volatile storage or persistent storage. The programs stored in the memory 1105 may include one or more modules, and each module may include a series of instruction operations on the server. Further, the central processing unit 1101 may be configured to communicate with the memory 1105 and execute a series of instruction operations in the memory 1105 on the server 1100.

[0135] The server 1100 may further include one or more power supplies 1102, one or more wired or wireless network interfaces 1103, one or more input / output interfaces 1104, and / or one or more operating systems, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.

[0136] The central processing unit 1101 may perform the operations executed by the server in the foregoing embodiments, and details are not described herein again.

[0137] The embodiment of this application further provides a computer-readable storage medium, including instructions. When the instructions run on a computer, the computer is enabled to execute the method in the foregoing embodiments.

[0138] The embodiment of this application further provides a computer program product containing instructions. When it runs on a computer, the computer is enabled to execute the method in the foregoing embodiments.

[0139] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above may refer to the corresponding processes in the foregoing method embodiments, and details are not described herein again.

[0140] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the device or unit can be in electrical, mechanical, or other forms.

[0141] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0142] In addition, in each embodiment of this application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0143] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.

Claims

1. A method for querying access rights, characterized in that, The method includes: The network device obtains the application user identity of the terminal device according to the access packet, where the access packet is used for the terminal device to request access to the server; The network device queries in a preset access policy according to the application user identity and the terminal user identity to obtain a query result, where the access policy includes the corresponding relationship between the terminal user identity, the application user identity, and the access permission, and the query result is used to indicate whether the terminal device has the permission to access the server.

2. The access permission query method according to claim 1, characterized in that After the network device queries in a preset access policy according to the application user identity and the terminal user identity to obtain a query result, the method further includes: If the terminal device has the permission to access the server, the network device forwards the access packet to the server; If the terminal device does not have the permission to access the server, the network device discards the access packet.

3. The access right query method according to claim 1 or 2, characterized in that The network device obtains the application user identity of the terminal device according to the access packet, including: The network device parses the access packet to obtain the application user name of the terminal device; The network device looks up the application user identity corresponding to the application user name.

4. The access right query method according to claim 3, characterized in that The network device parses the access packet to obtain the application user name of the terminal device, including: The network device sends a query packet to the server, where the query packet is used to request the server to query the application user name, and the query packet includes the destination address of the access packet; The network device receives a feedback packet from the server, where the feedback packet includes the application user name.

5. The access permission query method according to claim 3, characterized in that The network device parses the access packet to obtain the application user name of the terminal device, including: The network device parses the application user name from the payload of the access packet.

6. The access right query method according to any one of claims 3 to 5, characterized in that The network device looks up the application user identity corresponding to the application user name, including: The network device looks up the application user identity corresponding to the application user name locally.

7. A method for querying access rights, characterized in that, The method includes: The server receives a query packet from the network device, where the query packet is used for the network device to request the server to query the application user name of the terminal device, the query packet includes the destination address of the access packet, and the access packet is used for the terminal device to request access to the server; The server obtains the application user name according to the query packet; The server sends a feedback packet to the network device, where the feedback packet includes the application user name.

8. The access right query method according to claim 7, wherein The server obtains the application user name according to the query packet, including: The server obtains the destination address, where the destination address is used to indicate the application that the terminal device needs to access; The server determines the application user name of the terminal device according to the destination address.

9. A network device, characterized in that, It includes: An obtaining unit, configured to obtain the application user identity of the terminal device according to the access packet, where the access packet is used for the terminal device to request access to the server; A query unit, configured to query in a preset access policy according to the application user identity and the terminal user identity to obtain a query result, where the access policy includes the corresponding relationship between the terminal user identity, the application user identity, and the access permission, and the query result is used to indicate whether the terminal device has the permission to access the server.

10. The network device according to claim 9, wherein It further includes a processing unit; The processing unit is configured to, after querying in the preset access policy according to the application user identity and the terminal user identity, if the terminal device has the permission to access the server, then the network device forwards the access message to the server; If the terminal device does not have the permission to access the server, then the network device discards the access message.

11. The network device according to claim 9 or 10, characterized in that, The obtaining unit includes: A parsing module, configured to parse the access message to obtain the application user name of the terminal device; A searching module, configured to search for the application user identity corresponding to the application user name.

12. The network device according to claim 11, characterized in that, Specifically, the parsing module is used to Send a query message to the server, where the query message is used to request the server to query the application user name; Receive a feedback message from the server, where the feedback message includes the application user name.

13. The network device according to claim 11, wherein Specifically, the parsing module is used to: Parse out the application user name from the payload of the access message.

14. The network device according to any one of claims 11 to 13, characterized in that, Specifically, the searching module is used to: Search locally for the application user identity corresponding to the application user name.

15. A server, characterized in that, It includes: A receiving unit, configured to receive a query message from a network device, where the query message is used for the network device to request the server to query the application user name of the terminal device, the query message includes the destination address of the access message, and the access message is used for the terminal device to request to access the server; An obtaining unit, configured to obtain the application user name according to the query message; A sending unit, configured to send a feedback message to the network device, where the feedback message includes the application user name.

16. The server according to claim 15, wherein Specifically, the obtaining unit is used to: Obtain the destination address, where the destination address is used to indicate the application that the terminal device needs to access; Determine the application user name of the terminal device according to the destination address.

17. A network device, characterized in that, It includes: A processor and a communication interface, The communication interface is configured to receive a signal from a terminal device or a server and transmit it to the processor or send a signal from the processor to the server, and the processor is used to implement the method according to any one of claims 1 to 6 for the network device through logic circuits or by executing code instructions.

18. A server, characterized in that, It includes: A processor and a communication interface, The communication interface is configured to receive a signal from a network device and transmit it to the processor or send a signal from the processor to the network device, and the processor is used to implement the method according to any one of claims 7 to 8 for the server through logic circuits or by executing code instructions.

19. An access right query system, characterized in that, It includes: A terminal device, and a network device according to any one of claims 9 to 14, and a server according to any one of claims 15 to 16; Or, A terminal device, and a network device according to any one of claims 9 to 14.

20. A computer-readable storage medium comprising instructions that, when executed on a computer, cause the computer to perform the method according to any one of claims 1 to 6, or cause the computer to perform the method according to any one of claims 7 to 8.

21. A computer program product comprising instructions that, when executed on a computer, cause the computer to perform the method according to any one of claims 1 to 6, or cause the computer to perform the method according to any one of claims 7 to 8.