Internet access behavior supervision system and method based on digital certificate
Through the linkage between digital certificate storage cabinet and authentication equipment, combined with identity authentication and communication control, the problem of unauthorized use and impersonation of digital certificates is solved, and the entire process supervision and timely control are realized to ensure data security.
Patent Information
- Application Number
- CN202510665032.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2025-07-11
AI Technical Summary
Existing regulatory schemes cannot identify unauthorized use of digital certificates and other people's impersonation, resulting in leakage or illegal operation of sensitive information, and it is difficult to achieve pre-prevention and in-process control.
User permissions and identity authentication are carried out through the linkage of digital certificate storage cabinets, authentication devices and control gateways, ensuring that only authorized users to obtain and use digital certificates, and immediately cut off communications during abnormal use.
It realizes supervision of the entire process of using digital certificates, prevents unauthorized behaviors and impersonations, timely controls abnormal Internet access behaviors, and ensures data security.
Smart Images

Figure CN120301692A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to an Internet access behavior supervision system and method based on digital certificates. Background Art
[0002] In the field of Internet security, digital certificates, as the core carriers for identity authentication and data encryption, are widely used in scenarios with high security requirements such as finance, government, and enterprises. By encrypting, decrypting digital signatures, and signature authentication for the data exchanged on the Internet, the integrity and security of its information are ensured, so that the data cannot be illegally invaded, tampered with during the data transmission process, or its true content cannot be obtained even if attacked.
[0003] However, the above security measures are based on the encryption attributes of the digital certificates themselves. For the unauthorized use of digital certificates and the situation of others misusing digital certificates, the existing supervision solutions cannot identify them, resulting in the leakage of sensitive information or illegal operations. In addition, the existing supervision solutions generally conduct retroactive investigations based on log records after problems are discovered, and then hold the relevant parties accountable, making it difficult to achieve pre-prevention and in-process control.
[0004] In view of this, the present invention proposes an Internet access behavior supervision system and method based on digital certificates. Summary of the Invention
[0005] The present invention provides an Internet access behavior supervision system and method based on digital certificates to solve the problems that the existing Internet supervision solutions cannot monitor the abnormal use behaviors in the whole process of digital certificate use, easily lead to information leakage or illegal operations, and the control measures are not taken in a timely manner.
[0006] The present invention is achieved through the following technical solutions: In a first aspect of the present invention, an Internet access behavior supervision system based on digital certificates is provided, including: A digital certificate storage cabinet for storing digital certificates; An authentication device for verifying the usage authority of a first user, and when the first user is an authorized user, controlling the opening of the cabinet door of the digital certificate storage cabinet to allow the first user to obtain a digital certificate; A terminal device having at least one browser; the browser is configured to: when a digital certificate is inserted into the terminal device, allow a request message to be sent to a server through a control gateway; the authentication device is further configured to: when a digital certificate is inserted into the terminal device, authenticate a second user and send the authentication result to the control gateway; The control gateway is configured to: forward the request information of the browser if the authentication result indicates that the identity of the second user is the same as that of the first user; otherwise, intercept the request information of the browser; where the first user is the user who obtains the digital certificate, and the second user is the user who uses the digital certificate.
[0007] Through the linkage of the authentication device and the digital certificate storage cabinet, the above Internet behavior supervision system verifies the permissions for users to obtain digital certificates, opens the digital certificate storage cabinet when the verification is passed, and only allows authorized users to obtain digital certificates, preventing unauthorized Internet access; through the linkage of the authentication device and the control gateway, it authenticates the identity of users when using digital certificates. Only when the user using the certificate has the same identity as the authorized user who obtained the digital certificate, the control gateway forwards the request information of the browser. Otherwise, it intercepts the request information, realizing the supervision of the whole process of obtaining and using digital certificates, avoiding unauthorized use and digital certificate fraud, and immediately cutting off the communication between the browser and the server through the control gateway when abnormal use is detected, achieving the prevention and timely control of abnormal Internet behavior.
[0008] In some embodiments, the authentication device includes an image acquisition module, an information storage module, and an analysis module; The image acquisition module is used to acquire first face information and second face information; the first face information is the face information of the first user, and the second face information is the face information of the second user; The information storage module is used to store the face information of the pre-registered authorized users and the first face information; The analysis module is used to compare the first face information with the face information of the authorized users to verify the usage permissions of the first user; and compare the second face information with the first face information to verify the identity of the second user.
[0009] In some embodiments, the image acquisition module is configured to: acquire the first face information when the first user requests Internet access permissions from the terminal device; and acquire the second face information at a preset time interval when a digital certificate is inserted into the terminal device.
[0010] In some embodiments, at least one browser in the terminal device is a dedicated browser, and the dedicated browser is configured to: embed dedicated browser identification information in the request information when sending the request information to the server; The control gateway is further configured to: detect whether the request information contains dedicated browser identification information. If it does, forward the request information; if not, intercept the request information.
[0011] In some embodiments, the Internet behavior supervision system further includes a background management device, which exchanges information with the terminal device and the control gateway through an Ethernet switch; The background management device is configured to, if the request information does not contain dedicated browser identification information, redirect the currently used web page to the dedicated browser.
[0012] In some embodiments, the background management device is further configured to monitor the application programs in the terminal device. If the dedicated browser is not included in the application programs, redirect the currently used web page to the dedicated browser download page to force the download of the dedicated browser.
[0013] In some embodiments, the authentication device is integrated in the terminal device.
[0014] In a second aspect of the present invention, there is provided an Internet behavior supervision method based on a digital certificate, including: Verify the usage permission of a first user. If the first user is an authorized user, control the opening of the cabinet door of the digital certificate storage cabinet to allow the first user to obtain the digital certificate; the first user is the user who requests to obtain the digital certificate; When a digital certificate is inserted into the terminal device, open the browser access permission in the terminal device to allow the browser to send request information to the server through the control gateway; and, Authenticate a second user. If the authentication result shows that the identity of the second user is the same as that of the first user, forward the request information of the browser through the gateway. If not, intercept the request information of the browser; wherein, the second user is the user who uses the digital certificate.
[0015] In some embodiments, the method further includes: detecting whether the request information sent by the browser contains dedicated browser identification information. If it does, forward the request information to the server through the control gateway. If not, intercept the request information through the control gateway.
[0016] In some embodiments, the method further includes: If the request information does not contain dedicated browser identification information, redirect the currently used web page to the dedicated browser; If the application program in the terminal device does not include a dedicated browser, redirect the currently used web page to the dedicated browser download page and force the download of the dedicated browser.
[0017] Compared with the prior art, the present invention has the following advantages and beneficial effects: Through the linkage between the authentication device and the digital certificate storage cabinet, the permission verification of the user's behavior of obtaining digital certificates is carried out to prevent unauthorized user Internet access behavior; through the linkage between the authentication device and the control network, the identity verification of the user's behavior of using digital certificates is carried out to avoid unauthorized use behavior and digital certificate impersonation, and when abnormal use is found, the communication between the browser and the server is immediately cut off through the control gateway, realizing the prevention and timely control of abnormal Internet access behavior; The face recognition method is used for user permission and identity verification, which will not interfere with the user during the Internet access process, and can supervise both the certificate acquisition behavior and the certificate use behavior; By secondary development of the browser kernel, when sending a request message to the server through the dedicated browser, the request message carries the dedicated browser identification information. By parsing the fields in the request message, the Internet access behavior of the user not in accordance with the authorization regulations can be identified, so as to monitor and stop the unauthorized behavior and ensure data security; By capturing and analyzing the traffic data of the browser through the background management device, web page redirection is carried out when the user does not use the dedicated browser or deletes the dedicated browser, realizing the whole-process supervision of Internet access behavior, and timely stopping the abnormal Internet access behavior through the control gateway to reduce losses. Brief Description of the Drawings
[0018] In order to more clearly illustrate the technical solutions of the exemplary embodiments of the present invention, the accompanying drawings required for the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts. In the drawings: Figure 1 is a network system architecture diagram based on BS proposed in an embodiment of the present invention; Figure 2 is a structural schematic diagram of an Internet access behavior supervision system based on digital certificates proposed in an embodiment of the present invention; Figure 3 is a structural block diagram of an authentication device proposed in an embodiment of the present invention; Figure 4 is another structural schematic diagram of an Internet access behavior supervision system based on digital certificates proposed in an embodiment of the present invention; Figure 5 It is a schematic flowchart of a method for supervising Internet access behavior based on digital certificates proposed in an embodiment of the present invention. Detailed implementation manners
[0019] To make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the embodiments and the accompanying drawings. The illustrative embodiments and descriptions thereof of the present invention are only used to explain the present invention and are not intended to limit the present invention.
[0020] It should be noted that the terms "include" and "have" in the specification and claims of the present invention and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily be limited to other steps or units inherent to the process, method, system, product or device.
[0021] The terms used in the various embodiments of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the various embodiments of the present invention. As used herein, the singular forms are also intended to include the plural forms unless the context clearly indicates otherwise. Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those of ordinary skill in the art to which the various embodiments of the present invention belong. The terms (such as those defined in a general-use dictionary) will be interpreted as having the same meaning as the contextual meaning in the relevant technical field and will not be interpreted as having an idealized meaning or an overly formal meaning unless clearly defined in the various embodiments of the present invention.
[0022] The embodiments of the present invention provide an Internet access behavior supervision system and method based on digital certificates, which are applicable to a BS (browser-server) architecture system, and are beneficial to realizing the whole-process supervision of Internet access behavior using digital certificates, and timely discovering and controlling abnormal Internet access behavior.
[0023] The Internet access behavior supervision system of the present invention adopts a BS architecture. Refer to Figure 1As shown, it shows a BS-based network system architecture. The BS architecture mainly uses a web browser as the client. Only by using a browser on the terminal device to access the application system on the server, there is no need to install a dedicated client. Multiple internal network terminal devices and management devices are connected through an Ethernet switch. The Ethernet switch accesses the gateway, which isolates the internal network from the external network, and realizes external communication through a router and a wide area network. The advantages of the BS architecture mode include cross-platform compatibility, zero maintenance of the client, easy upgrade, and low maintenance cost, etc. The update and maintenance work of the BS system is concentrated on the server side. Users do not need to download or install anything. On the client side, users only need a browser to access the application. There is no need to develop dedicated client application programs for different systems. Just develop once and all users can use it. Therefore, the development and maintenance costs are relatively low. Currently, most computer application systems are of the BS architecture. Therefore, the user's Internet access behavior can be controlled and monitored through the browser in the BS architecture.
[0024] See Figure 2 As shown, it shows the system structure of the Internet access behavior supervision system based on digital certificates according to an embodiment of the present invention. The system includes a digital certificate storage cabinet 100, an authentication device 200, a terminal device 300, and a control gateway 400.
[0025] The digital certificate storage cabinet 100 stores multiple digital certificates, which are used to be inserted into the terminal device 300 for the inserted device to access the Internet. The digital certificate can be a hardware certificate such as a USB key, a dongle, a USB KEY, etc.
[0026] The authentication device 200 is used to verify the user's usage permission. That is, the user submits a digital certificate usage application to the system, and the application is forwarded to the authentication device. Then the authentication device verifies whether the user's identity is an authorized user according to the user information. If the permission verification passes, the user is allowed to use the digital certificate, and the system controls the cabinet door of the digital certificate storage cabinet 100 to open for the requesting user to pick up.
[0027] After the digital certificate is taken out, the system locks the cabinet door again and records the current usage information, including the taken-out digital certificate and user information. The user information can be voiceprint, fingerprint, face, etc. information that can uniquely identify the identity. The authorized user pre-enters the identity information in advance to match with the collected information to determine the user's permission. The user can initiate a usage request to any one of the digital certificate storage cabinet 100, the authentication device 200, and the terminal device 300.
[0028] After the authorized user obtains the digital certificate, insert the digital certificate into the digital certificate interface (such as a USB interface) of the terminal device 300. After the digital certificate passes the legality verification, the user can use the browser to access the Internet, that is, the browser is allowed to send request information to the server through the control gateway. The user's Internet access behavior is restricted by the digital certificate. For example, the user can only access the websites and business systems permitted by the digital certificate.
[0029] During the Internet access process, that is, during the process of inserting the digital certificate into the terminal device, the authentication device 200 authenticates the user using the digital certificate. It should be understood that in the case of impersonation, the user using the digital certificate is not the same as the user authorized to obtain the digital certificate. For example, if the previous user forgets to retrieve the digital certificate or the digital certificate is accidentally lost, resulting in impersonation by others, it is difficult to hold the actual operator accountable for traditional supervision schemes that can only track abnormal behaviors through logs. In this implementation, the user who obtains the digital certificate is regarded as the first user, and the user using the digital certificate is regarded as the second user. Therefore, the authentication device authenticates the second user during the usage process to achieve full-process supervision of the acquisition and use of the digital certificate.
[0030] When the digital certificate is removed, the system records the information of the first user. When the authentication device 200 detects that a digital certificate is inserted into the digital certificate interface of the terminal device, it authenticates the second user and sends the authentication result to the control gateway 300. The authentication result includes two types: the identity of the second user is the same as that of the first user and the identity is different. When the identities are the same, the control gateway 300 forwards the request information sent by the browser to the server. When the identities are different, the control gateway 300 intercepts the request information, that is, stops the second user's Internet access behavior to avoid information leakage or illegal operations.
[0031] Through the linkage between the authentication device and the control gateway, unauthorized use behaviors and digital certificate impersonation are avoided. When abnormal use is detected, the communication between the browser and the server is immediately cut off through the control gateway, achieving the prevention and timely control of abnormal Internet access behaviors.
[0032] In some embodiments, as shown in Figure 3 The authentication device 200 includes an image acquisition module 210, an information storage module 220, and an analysis module 230. The image acquisition module 210 is used to acquire the first face information and the second face information. The information storage module 220 is used to store the face information of the authorized user and the first face information pre-recorded. The analysis module 230 is used to compare the first face information with the face information of the authorized user to verify the usage permission of the first user. The analysis module 230 is also used to compare the second face information with the first face information to verify the identity of the second user.
[0033] Wherein the first face information is the face information of the first user, that is, when the image acquisition module 210 receives a request from the first user to obtain a digital certificate, it acquires the face information of the first user, compares it with the face information of the authorized user stored in the information storage module 220, and controls whether to open the cabinet door of the digital certificate storage cabinet according to the comparison result. The second face information is the face information of the second user, that is, when the second user is using the digital certificate to access the Internet, the image acquisition module 210 acquires the face information of the second user, compares it with the first face information of the first user acquired, and controls whether the browser can send request information to the server through the gateway according to the comparison result. In this embodiment, the method of face recognition does not interfere with the user's Internet access behavior, and can supervise both the certificate acquisition behavior and the Internet access behavior.
[0034] In some embodiments, the image acquisition module 210 is configured to: acquire the first face information when the first user requests Internet access permission from the terminal device 300; and acquire the second face information at a preset time interval when a digital certificate is inserted into the digital certificate interface of the terminal device.
[0035] Setting the image acquisition module to perform automatic acquisition under preset trigger conditions can avoid redundant information acquisition and storage, improve the verification response efficiency, save device power consumption and storage resources. Setting a time interval to acquire the face information of the second user can monitor the entire process of Internet access and ensure system security.
[0036] In some embodiments, the authentication device 200 is integrated into the terminal device 300, and each terminal device 300 has an authentication device 200. The image acquisition module in the authentication device 200 uses the acquisition device built into the terminal device 300, and information storage and analysis are realized by means of the storage and processor of the terminal device 300.
[0037] In some embodiments, at least one browser in the terminal device 300 is a dedicated browser. The settings of the dedicated browser restrict the user from accessing the business system through the dedicated browser rather than other browsers, which is convenient for monitoring Internet access data. The dedicated browser is configured to: embed dedicated browser identification information in the request information when sending the request information to the server; the control gateway 400 is configured to: detect whether the request information contains the dedicated browser identification information. If it contains, forward the request information of the browser to the server. If it does not contain, intercept the request information of the browser.
[0038] By secondary development of the browser kernel, a header field uniquely identifying the dedicated browser is added to the HTTP / HTTPS request headers of the professional browser. The value of this field can contain information such as browser version and enterprise identification, which is bound to the source IP address (i.e., the IP of the terminal device) to carry the dedicated browser identification information in the request information sent to the server through the dedicated browser. When the control gateway 400 receives the request information sent from the browser, it determines whether the request information is sent through the dedicated browser based on the dedicated browser identification information therein. If the dedicated browser identification information is not included, the request information is refused to be forwarded, thereby monitoring and preventing users from using the browser in violation of regulations to ensure data security.
[0039] In some embodiments, referring to Figure 4 As shown, the Internet behavior supervision system further includes a background management device 500. The dedicated browser collects business data and sends it to the background management device for unified analysis by the background. The collected data includes, but is not limited to, URLs, queried data, downloaded files, etc. The analysis results can model the usage behavior, and the modeled behaviors can be classified as normal and abnormal. For abnormal behaviors, the background can issue an instruction to limit the user's Internet access through the gateway and disable network access.
[0040] The background management device 500 exchanges information with the terminal device 300 and the control gateway 400 through an Ethernet switch. The control gateway 400 forwards the received and intercepted data to the background management device for unified analysis, and the background management device can also interact with the terminal device 300 within the intranet through the Ethernet switch.
[0041] In some embodiments, the background management device 500 is further configured to: if the request information does not contain the dedicated browser identification information, redirect the currently used web page to the dedicated browser.
[0042] In some embodiments, the background management device 500 is further configured to: monitor the application programs in the terminal device 300. If the application programs do not include the dedicated browser, redirect the currently used web page to the dedicated browser download page to forcibly download the dedicated browser. Once the user privately uninstalls the dedicated browser or uses other browsers, through real-time traffic data analysis by the background through the gateway, as long as it is found by comparison that there is no dedicated browser identification information in the source IP address, a forced redirection is performed.
[0043] An embodiment of the present invention further provides an Internet behavior supervision method based on a digital certificate, as Figure 5 shown, including the following steps.
[0044] (1) Digital certificate acquisition stage: S1-1. Receive a digital certificate acquisition request from a first user; S1-2. Verify the usage permission of the first user. If the first user is an authorized user, control the opening of the cabinet door of the digital certificate storage cabinet to allow the first user to obtain the digital certificate.
[0045] (2) Digital certificate usage stage: S1-3. When it is detected that a digital certificate is inserted into the terminal device, open the browser access permission in the terminal device to allow the browser to send request information to the server through the control gateway; and, S1-4. Authenticate the second user using the digital certificate. If the authentication result shows that the identity of the second user is the same as that of the first user, forward the request information of the browser through the gateway; otherwise, intercept the request information of the browser.
[0046] Among them, step S1-4 authenticates the second user at preset time intervals to achieve full-process monitoring of the Internet access process.
[0047] In some embodiments, the Internet access behavior supervision method based on digital certificates further includes: detecting whether the request information sent by the browser contains dedicated browser identification information. If it does, forward the request information to the server through the control gateway; otherwise, intercept the request information through the control gateway.
[0048] In some embodiments, the Internet access behavior supervision method based on digital certificates further includes: if the request information does not contain dedicated browser identification information, redirect the currently used web page to a dedicated browser; if the dedicated browser is not included in the application programs in the terminal device, redirect the currently used web page to a dedicated browser download page to forcibly download the dedicated browser.
[0049] This implementation realizes full-process supervision of the access behavior of digital certificate users and full-process data collection and analysis of Internet access behavior, collects all data during the entire Internet access behavior period, and through background data analysis and judgment, supervises and timely processes abnormal usage behaviors.
[0050] An embodiment of the present invention further provides an electronic device, which includes a processor and a memory. The number of processors can be one or more. The memory, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules. The processor runs the software programs, instructions, and modules stored in the memory to execute various functional applications and data processing of the electronic device, so as to implement the Internet access behavior supervision method based on digital certificates in any of the above embodiments of the present invention.
[0051] The memory may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created according to the use of the terminal, etc. In addition, the memory may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some instances, the memory may further include a memory remotely disposed relative to the processor, and these remote memories may be connected to the electronic device through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0052] An embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the method for supervising Internet access behavior based on a digital certificate according to any embodiment of the present invention is implemented.
[0053] The computer storage medium of the embodiment of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program may be used by or in combination with an instruction execution system, apparatus, or device.
[0054] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program code is carried. Such a propagated data signal may take various forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable medium may send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device.
[0055] An embodiment of the present invention also provides a computer program product, and when the computer program product runs on a computer, the computer is caused to execute the method for supervising Internet access behavior based on a digital certificate according to any of the above embodiments of the present invention.
[0056] The specific embodiments described above further elaborate on the objective, technical solution and beneficial effects of the present invention. It should be understood that the above description is only the specific embodiments of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. An Internet access behavior supervision system based on digital certificates, characterized in that, Including: A digital certificate storage cabinet for storing digital certificates; An authentication device for verifying the usage permission of a first user, and when the first user is an authorized user, controlling the opening of the cabinet door of the digital certificate storage cabinet to allow the first user to obtain the digital certificate; A terminal device having at least one browser; the browser is configured to: when a digital certificate is inserted into the terminal device, allow a request message to be sent to a server through a control gateway; the authentication device is further configured to: when a digital certificate is inserted into the terminal device, authenticate a second user and send the authentication result to the control gateway; The control gateway is configured to: if the authentication result is that the identity of the second user is the same as that of the first user, forward the request message of the browser; If not, intercept the request message of the browser; wherein, the first user is the user who obtains the digital certificate, and the second user is the user who uses the digital certificate.
2. The Internet behavior supervision system based on digital certificates according to claim 1, characterized in that The authentication device includes an image acquisition module, an information storage module, and an analysis module; The image acquisition module is used to acquire first face information and second face information; the first face information is the face information of the first user, and the second face information is the face information of the second user; The information storage module is used to store the face information of pre-recorded authorized users and the first face information; The analysis module is used to compare the first face information with the face information of the authorized users to verify the usage permission of the first user; and compare the second face information with the first face information to verify the identity of the second user.
3. The Internet behavior supervision system based on digital certificates according to claim 2, characterized in that, The image acquisition module is configured to: When the first user requests Internet access permission from the terminal device, acquire the first face information; and When a digital certificate is inserted into the terminal device, acquire the second face information at a preset time interval.
4. The Internet behavior supervision system based on digital certificates according to claim 1, characterized in that At least one browser in the terminal device is a dedicated browser, and the dedicated browser is configured to: when sending a request message to the server, embed dedicated browser identification information in the request message; The control gateway is further configured to: detect whether the request message contains dedicated browser identification information, if it does, forward the request message; if it does not, intercept the request message.
5. The Internet behavior supervision system based on digital certificates according to claim 4, wherein, The Internet behavior supervision system further includes a background management device, and the background management device performs information interaction with the terminal device and the control gateway through an Ethernet switch; The background management device is used to: if the request message does not contain dedicated browser identification information, redirect the currently used web page to the dedicated browser.
6. The Internet behavior supervision system based on digital certificates according to claim 5, characterized in that, The background management device is further used to: monitor the application programs in the terminal device, if the application programs do not include the dedicated browser, redirect the currently used web page to the dedicated browser download page and force the download of the dedicated browser.
7. The Internet behavior supervision system based on digital certificates according to any one of claims 1-6, characterized in that, The authentication device is integrated in the terminal device.
8. A method for supervising Internet access behaviors based on digital certificates, characterized in that Including: Verify the usage permission of the first user. If the first user is an authorized user, control the opening of the cabinet door of the digital certificate storage cabinet to allow the first user to obtain the digital certificate; The first user is the user who requests to obtain the digital certificate; When a digital certificate is inserted into the terminal device, open the browser access permission in the terminal device to allow the browser to send request information to the server through the control gateway; And, Authenticate the second user. If the authentication result shows that the identity of the second user is the same as that of the first user, forward the request information of the browser through the gateway. If they are inconsistent, intercept the request information of the browser; wherein, the second user is the user who uses the digital certificate.
9. The Internet access behavior supervision method based on digital certificates according to claim 8, wherein, The method further includes: detecting whether the request information sent by the browser contains dedicated browser identification information. If it does, forward the request information to the server through the control gateway. If it does not, intercept the request information through the control gateway.
10. The Internet access behavior supervision method based on digital certificates according to claim 9, wherein, The method further includes: if the request information does not contain dedicated browser identification information, redirect the currently used web page to the dedicated browser; if the dedicated browser is not included in the application programs in the terminal device, redirect the currently used web page to the dedicated browser download page to force the download of the dedicated browser.