Network access control method, firewall and user terminal
The described network access control method uses an anti-collision one-way mapping algorithm to encrypt user identities and access targets, enhancing security and privacy in network access control systems.
Patent Information
- Application Number
- CN202510804406.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-06-16
AI Technical Summary
In the prior art, network access control is not fine and flexible enough, has insufficient security, and has low privacy protection, especially when network spying and attacking, it cannot effectively protect user identity and access targets.
The collision-resistant one-way mapping algorithm and encryption algorithm are adopted to achieve dynamic identification of user identity and dynamic control of access channels through the one-way mapping and encryption of user identifiers and access target information, and prevent illegal access.
It improves the security of network access, prevents the leakage of user identifiers and access target information, realizes dynamic activation and closing of access channels, and ensures the refinement and flexibility of user identity privacy protection and access control.
Smart Images

Figure CN120321046A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technologies, and in particular, to a network access control method, a firewall, and a user terminal. Background Art
[0002] Currently, the basic measure to deal with network espionage and attacks is to use various firewalls, which protect network applications by filtering the source IP (Internet Protocol) addresses of incoming network requests and the like.
[0003] In the related art, an intelligent firewall can "open as needed" for authorized users. Such a solution "actively" isolates network services through the default policy of the firewall, so that the network services are protected from network espionage or attacks. However, for those authorized users, the service will indicate the firewall to release them separately when a specific condition is triggered, and become visible to them and only to them; this approach is like closing the door by default and only opening the door to let the knocker in when hearing a pre-agreed "knocking signal" from outside.
[0004] However, the intelligent firewall in the related art has technical problems such as insufficiently fine and flexible control over inbound and outbound network access, and insufficient security and privacy protection.
[0005] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention
[0006] Embodiments of this application provide a network access control method, a firewall, and a user terminal to at least solve the technical problems of insufficiently fine and flexible control over inbound and outbound network access, and insufficient security and privacy protection.
[0007] According to one aspect of the embodiments of the present application, a network access control method is provided, including: receiving a knocking request message sent by a user terminal located in a first network, where the knocking request message includes: a first user identifier and first access target information. The first user identifier is obtained by performing a one-way mapping on a first timestamp and an original user identifier using a collision-resistant one-way mapping algorithm. The first access target information is obtained by encrypting original access target information using a key corresponding to the original user identifier; determining whether a target user identifier exists in a user database, where the target user identifier is a specific candidate user identifier in the user database. The mapping result obtained by inputting a specific candidate timestamp and the specific candidate user identifier into the one-way mapping algorithm is the same as the first user identifier. The user database includes at least one user registration information, and the user registration information includes: a candidate user identifier and a key corresponding to the candidate user identifier; in the case of determining that the target user identifier exists in the user database, obtaining the key corresponding to the target user identifier, and decrypting the first access target information in the knocking request message using the key to obtain the original access target information; opening a network channel between the source address corresponding to the user terminal and the destination address located in a second network corresponding to the original access target information, so that the user terminal can access an access target located in the second network, where the first network and the second network are two networks isolated by a firewall.
[0008] Optionally, determining whether a target user identifier exists in the user database includes: determining the local timestamp when the knocking request message is received as a second timestamp, and determining a candidate timestamp range according to the second timestamp and a preset allowable error; obtaining candidate timestamps within the candidate timestamp range according to a preset time granularity; inputting the candidate timestamps and candidate user identifiers into the one-way mapping algorithm to obtain a mapping result, where the one-way mapping algorithm includes: a first mapping parameter and a second mapping parameter. The first mapping parameter traverses each candidate timestamp in the candidate timestamp range, and the second mapping parameter traverses each candidate user identifier in the user database; in the case where the mapping result is consistent with the first user identifier, determining the value taken by the first mapping parameter when the mapping result is obtained as the first timestamp in the user terminal, and determining the value taken by the second mapping parameter when the mapping result is obtained as the target user identifier.
[0009] Optionally, the knocking request message further includes: a first timestamp; determining whether there is a target user identifier in the user database further includes: determining the local timestamp when the knocking request message is received as the second timestamp, and determining a candidate timestamp range according to the second timestamp and a preset allowable error; in the case where the first timestamp in the knocking request message is within the candidate timestamp range, inputting the first timestamp and the candidate user identifier into a one-way mapping algorithm to obtain a mapping result, where the one-way mapping algorithm includes: a first mapping parameter and a second mapping parameter, the first mapping parameter takes the first timestamp, and the second mapping parameter traverses each candidate user identifier in the user database; in the case where the mapping result is consistent with the first user identifier, determining the value taken by the second mapping parameter when the mapping result is obtained as the target user identifier.
[0010] Optionally, the first access target information is obtained by encrypting a specific mixing result with a key, and the specific mixing result is determined by the verification information and the original access target information; decrypting the first access target information in the knocking request message with a key includes: obtaining the key corresponding to the target user identifier stored in the user database, and decrypting the first user identifier with the key to obtain a decryption result, where the decryption result includes: a verification part and an access target part; in the case where the verification part in the decryption result is consistent with the verification information used when mixing the original access target information, determining the access target part in the decryption result as the original access target information corresponding to the first access target information.
[0011] Optionally, the method further includes: in response to a registration request message, generating an original user identifier and a key corresponding to the original user identifier; storing the original user identifier and the key in the user database of the firewall as the candidate user identifier and its corresponding key, and storing the original user identifier and the key in a secure storage medium, so that the user can obtain the original user identifier and the key by receiving the secure storage medium.
[0012] According to another aspect of the embodiments of the present application, another network access control method is further provided, including: using a collision-resistant one-way mapping algorithm to perform a one-way mapping on a first timestamp and an original user identifier to obtain a first user identifier; using a key corresponding to the original user identifier to encrypt the original access target information to obtain first access target information; generating a knocking request message based on the first user identifier and the first access target information, and sending the knocking request message to a firewall; when the firewall opens a network channel in accordance with the knocking request, accessing an access target in a second network, where the network channel is a channel between a source address in a first network corresponding to a user terminal opened by the firewall in response to the knocking request message and a destination address in the second network corresponding to the original access target information, and the first network and the second network are two networks isolated by the firewall.
[0013] Optionally, the original access target information includes: a uniform resource identifier in the form of a string; before encrypting the original access target information, it further includes: when the original access target information is in the form of a string, generating a target random number within a preset numerical range, where the target random number is a positive integer; adding a preset character with the number of target random digits to the head or end of the original access target information to obtain new original access target information.
[0014] Optionally, the original access target information further includes: a destination Internet protocol address and a destination protocol port number in binary form; encrypting the original access target information includes: mixing the check information with the original access target information to obtain a specific mixing result; using the key to encrypt the specific mixing result to obtain the first access target information.
[0015] According to yet another aspect of the embodiments of the present application, a firewall is further provided, including: a memory and a processor, where the processor is configured to run a program stored in the memory, and when the program runs, it executes the network access control method.
[0016] According to still another aspect of the embodiments of the present application, a user terminal is further provided, including: a memory and a processor, where the processor is configured to run a program stored in the memory, and when the program runs, it executes the network access control method.
[0017] In the embodiments of the present application, by adopting the above method, through the use of a one-way mapping algorithm and an encryption algorithm, the security of network access is effectively enhanced, and the risk of leakage of user identifiers and access target information during network transmission is avoided. Through the control of the firewall, the dynamic opening and closing of the access channel are realized, and the purpose of effective identity authentication during the knocking process is achieved, effectively preventing illegal access, and thus solving the technical problems of insufficiently fine and flexible access control for inbound and outbound networks and insufficient security and privacy protection. Brief Description of the Drawings
[0018] The drawings described herein are provided to further understand the present application and form a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:
[0019] Figure 1 is a schematic diagram of a method flow for network access control provided according to an embodiment of the present application;
[0020] Figure 2 is a schematic diagram of a method flow for network access control supporting two-way knocking provided according to an embodiment of the present application;
[0021] Figure 3 is a schematic diagram of another method flow for network access control provided according to an embodiment of the present application. Detailed Description of the Embodiments
[0022] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the protection scope of the present application.
[0023] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above drawings are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence. It should be understood that such expressions can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0024] For the convenience of those skilled in the art to better understand the embodiments of the present application, some technical terms or noun explanations related to the embodiments of the present application are now described as follows:
[0025] Firewall: A network security device deployed at the network control boundary for implementing access control. It can parse network traffic at a certain level and decide whether to allow the transmission of network packets according to the security rules configured by the administrator. A firewall is usually regarded as the first line of defense in network security and plays a key role in network security protection.
[0026] In related technologies, traditional static firewalls usually adopt defense strategies of default discard or default allow. However, no matter which approach (default discard / default allow) is adopted, enabling a firewall is only a passive defense measure: Since it is impossible to predict whether each source IP is legitimate or malicious, firewall administrators usually can only configure the firewall accordingly during or after network probing and attacks occur, and the protection effect is relatively lagging and limited.
[0027] To overcome the shortcomings of static firewalls, the intelligent firewall that can "open on demand" for authorized users evolved from traditional static firewalls in related technologies. For those authorized users, the service will instruct the firewall to allow access separately when specific conditions are triggered.
[0028] Taking the Linux and FreeBSD operating systems as examples, knockd is such a special daemon process. It listens for TCP / UDP protocol packets received by the host from the network. When these packets match the pre-configured rules in the form of a specific event sequence, knockd will call the firewall command accordingly to open the firewall that is always closed by default to and only to the source IP that has sent the correct knocking signal.
[0029] However, there are common limitations in the current knocking technologies in related technologies, that is, they only focus on the situation of the knocker outside the door ("knock to come in") and completely ignore the situation of the knocker inside the door ("knock to go out"). It should be noted that knockd in related technologies does not perform identity authentication itself, that is, it operates anonymously. In the scenario of "knock to come in", access can be allowed first and then identity authentication can be carried out, that is, the identity can be checked after coming in.
[0030] However, if the perspective of observation and thinking is switched from an individual to a network service provider (such as an operator), problems will arise. Assume a scenario: When the network in a certain region accesses the external network, it can only access limited targets in the whitelist, and those not in the whitelist are default closed. Then, when an authorized user needs to temporarily access a specific target not in the whitelist (such as https: / / example.com), obviously, the knockd technology in related technologies cannot be applied because what is usually accessed in "knock to come in" is the default target, while the target to be accessed in "knock to go out" cannot be determined in advance; different users will request different targets around the world, and the actual situation can only be known during use.
[0031] Moreover, in the scenario of "knocking out", if the knockd solution in the related art is still used, although the user can "knock open" the firewall and temporarily access a default and fixed target, the defect of the solution is that the external network target usually does not and has no obligation to authenticate the user like the internal network SSH service or webmail, and it is even less likely to feedback relevant records to our operator. Therefore, in this scenario, the external network target will not and cannot help the internal network with any security work (for example, security auditing).
[0032] To solve this reverse knocking problem, one technical route is to modify knockd to authenticate users like the SSH service, such as using username / password, or digital signature technology, etc. However, this will make the solution complex and lose its concealment, and new problems will arise, as follows: The authentication scheme usually involves the user's identity identifier, which will make the two (and multiple) knocking signals of the same user become correlatable, and thus it is easy to combine other information to cause the leakage of the user's identity. For example, an internal network observer may correlate multiple knocking requests sent by the user through the identity identifier, and then infer the user's original identity and even the intention of reverse knocking through social engineering, etc. Therefore, how to make these knocking requests seem independent and irrelevant, that is, to make it impossible for the observer to judge whether they come from the same user is a problem that needs to be solved.
[0033] In summary, from "knocking in" to "knocking out", not only does it face the problem that the destination, that is, the user's access target, cannot be predicted, but also a new pair of contradictions: the network service provider has to authenticate the user's identity (to fundamentally prevent the knocking signal from being misused by unauthorized persons), and at the same time protect the user's identity privacy (to prevent the internal network observer from correlating and tracking the knocking behavior). It can be seen from this: The solution for "knocking out" is significantly higher than that for "knocking in" in terms of requirements and security requirements; what can be used for "knocking out" can necessarily be used for "knocking in", but the reverse is often not feasible.
[0034] To solve the above problems, relevant solutions are provided in the embodiments of the present application, which are described in detail below.
[0035] According to the embodiments of the present application, a method embodiment for network access control is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed by a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0036] The embodiments of the present application provide a network access control method. Figure 1It is a schematic diagram of a method flow for network access control provided according to an embodiment of the present application. As Figure 1 shown, this method is applied to the firewall side and includes the following steps:
[0037] Step S102: Receive a knocking request message sent by a user terminal located in the first network. The knocking request message includes: a first user identifier and first access target information. The first user identifier is obtained by performing a one-way mapping on a first timestamp and an original user identifier using a collision-resistant one-way mapping algorithm. The first access target information is obtained by encrypting the original access target information using a key corresponding to the original user identifier. The original user identifier is a user identifier in plain text form, and the original access target information is access target information in plain text form;
[0038] Step S104: Determine whether a target user identifier exists in the user database. The target user identifier is a specific candidate user identifier in the user database. The mapping result obtained by inputting a specific candidate timestamp and the specific candidate user identifier into the one-way mapping algorithm is the same as the first user identifier. The user database contains at least one user registration information, and the user registration information includes: a candidate user identifier and a key corresponding to the candidate user identifier;
[0039] Step S106: When it is determined that the target user identifier exists in the user database, obtain the key corresponding to the target user identifier, and decrypt the first access target information in the knocking request message using the key to obtain the original access target information;
[0040] Step S108: Open a network channel between the source address corresponding to the user terminal and the destination address located in the second network corresponding to the original access target information, so that the user terminal can access the access target located in the second network. The first network and the second network are two networks isolated by the firewall.
[0041] Through the above steps, by using a one-way mapping algorithm and an encryption algorithm, the security of network access is effectively enhanced, and the risk of leakage of user identifiers and access target information during network transmission is avoided. Through the control of the firewall, the dynamic opening and closing of the access channel are realized, the purpose of effective identity authentication during the knocking process is achieved, illegal access is effectively prevented, and thus the technical problems of insufficient fineness, flexibility in access control for inbound and outbound networks, and insufficient security and privacy protection are solved.
[0042] The network access control method in steps S102 to S108 of the embodiments of the present application will be further introduced below. It should be noted that the solution of the present application can be applied to both the scenario of "knocking to go out" (access from the internal network to the external network) and the scenario of "knocking to come in" (access from the external network to the internal network). Through the foregoing analysis, it can be seen that the solution for "knocking to go out" is significantly higher in requirements and security requirements than the solution for "knocking to come in". What can be used for "knocking to go out" can surely be used for "knocking to come in". Therefore, in the following introduction, the scenario of "knocking to go out" (access from the internal network to the external network) will be mainly used as an example to illustrate this solution, and the application in the scenario of "knocking to come in" (access from the external network to the internal network) will not be elaborated.
[0043] In the embodiments of the present application, it mainly includes an offline stage (user registration) and an online stage (mainly for knocking out, and also applicable to the scenario of knocking in), and at least involves two parties: the authorized user (user terminal side) and the firewall (including its management side).
[0044] Among them, in the offline stage, the user side submits a registration request to the firewall side, specifically as follows.
[0045] In some embodiments of the present application, the method further includes the following steps: in response to the registration request message, generate an original user identifier and a key corresponding to the original user identifier; store the original user identifier and the key as the candidate user identifier and its corresponding key in the user database of the firewall, and store the original user identifier and the key in a secure storage medium, so that the user can obtain the original user identifier and the key by receiving the secure storage medium.
[0046] Specifically, the user submits a registration request message to the firewall management side (i.e., the network service provider). After passing the review, the firewall will allocate an original user identifier u and a key k known only to the user and the firewall to the user side;
[0047] In this embodiment, both u and k are random numbers with sufficient strength (for example, random numbers 128 bits long) and need to be properly protected. On the one hand, they are stored in the user database of the firewall. On the other hand, the firewall management side can store their values (along with the relevant client software) on a secure storage medium similar to an online banking USB key and send it to the user. Subsequently, the user inserts this secure storage medium into its network terminal (such as a laptop) to execute the knocking process. If it is necessary to revoke a certain user for any reason (commonly such as expiration or loss of the security medium), only the corresponding u and k need to be disabled in the user database.
[0048] After completing the registration process in the offline stage, the knocking strategy in the online stage can be implemented. The main process steps in the online stage are as Figure 2As shown, during these steps, the firewall often needs to check the knocking requests. If any check fails, the firewall immediately terminates the process and does not need to make any response to the knocking requests. The following is a specific introduction.
[0049] First, the user-side network terminal (i.e., the user terminal) reads the local timestamp t (i.e., the first timestamp), as well as the original user identifier u and the key k stored on the secure storage medium. Then, using the one-way mapping algorithm, a one-way mapping is performed on the first timestamp t and the original user identifier u to obtain the first user identifier (also known as the pseudonym) p, that is, p = h(t, u), where h is a pre-agreed collision-resistant one-way mapping algorithm (it is easy to calculate the output from the input, but it is infeasible to reverse-engineer the input from the output). And, using the key k, the access target d (i.e., the original access target information) requested by the user side to be opened is encrypted into the first access target information c = E(k, t||d), where || represents bit string concatenation. For example, the concatenation result of the integer x = 0xfa and y = 0xce is x||y = 0xface, where the 0x prefix represents hexadecimal representation; E(k, *) is an encryption algorithm with k as the key and can use authenticated encryption.
[0050] It should be noted that in this embodiment, the first access target information c is obtained by encrypting the result t||d of the first timestamp t (i.e., selecting the first timestamp as the verification information in this embodiment) and the original access target information d. However, the embodiment of the present application does not limit the selection of the verification information and the mixing method of the verification information and the original access target information d. Specifically, the verification information here can be determined by the first timestamp and / or the original user identifier, as well as any other information that can be verified; the mixing method here is not limited to concatenation. The two can be mixed in any mixing method, and the terminal further encrypts the specific mixing result to obtain the first access target information c.
[0051] After that, the user terminal can send a knocking request message to the firewall. The request message includes at least the pseudonym (i.e., the first user identifier) p and the encrypted access target (i.e., the first access target information) c, and the optional item is the local first timestamp t.
[0052] After receiving the knocking request message sent by the user terminal, the firewall needs to first determine whether the knocking request message contains the first timestamp t. If it contains t, the corresponding verification policy is as follows.
[0053] In some embodiments of the present application, the knocking request message further includes: a first timestamp; determining whether there is a target user identifier in the user database further includes: determining the local timestamp when the knocking request message is received as the second timestamp, and determining a candidate timestamp interval according to the second timestamp and a preset allowable error; in the case where the first timestamp in the knocking request message is within the candidate timestamp interval, inputting the first timestamp and the candidate user identifier into a one-way mapping algorithm to obtain a mapping result, where the one-way mapping algorithm includes: a first mapping parameter and a second mapping parameter, the first mapping parameter takes the first timestamp, and the second mapping parameter traverses each candidate user identifier in the user database; in the case where the mapping result is consistent with the first user identifier, determining the value taken by the second mapping parameter when the mapping result is obtained as the target user identifier.
[0054] Specifically, first, the firewall determines the local timestamp (i.e., the second timestamp) T when the knocking request message is received, then determines whether the first timestamp is within the candidate timestamp interval (i.e., whether T - e ≤ t ≤ T + e is satisfied), and determines whether there is an undisabled u' in the user database such that h(t, u') = p (i.e., determines whether there is a target user identifier u'); if both conditions are satisfied, it is determined that the knocking request is fresh and valid, the first timestamp on the user side is t, and the original user identifier is u = u'; otherwise, the check fails. Here, e is the above-mentioned preset allowable error, and its value is an acceptable time error. For the intranet, e is usually very small. For example, when t and T are in milliseconds, e can take 2000 milliseconds.
[0055] If the knocking request received by the firewall does not include the first timestamp t, the firewall executes the following verification policy, which is specifically as follows.
[0056] In some embodiments of the present application, determining whether there is a target user identifier in the user database includes: determining the local timestamp when the knocking request message is received as the second timestamp, and determining a candidate timestamp interval according to the second timestamp and a preset allowable error; obtaining candidate timestamps within the candidate timestamp interval according to a preset time granularity; inputting the candidate timestamps and the candidate user identifier into a one-way mapping algorithm to obtain a mapping result, where the one-way mapping algorithm includes: a first mapping parameter and a second mapping parameter, the first mapping parameter traverses each candidate timestamp in the candidate timestamp interval, and the second mapping parameter traverses each candidate user identifier in the user database; in the case where the mapping result is consistent with the first user identifier, determining the value taken by the first mapping parameter when the mapping result is obtained as the first timestamp in the user terminal, and determining the value taken by the second mapping parameter when the mapping result is obtained as the target user identifier.
[0057] Specifically, if the knocking request received by the firewall does not contain t, the firewall tries every possible candidate timestamp t' from the candidate timestamp interval (i.e., T - e to T + e) according to a preset time granularity, and tries every non-disabled candidate user identifier u' from the database. If a combination of t' and u' can be found such that h(t', u') = p, it is determined that the knocking request is fresh and valid, the user-side timestamp is t = t', and the user identifier is u = u'. Otherwise, the check fails. Here, the meaning of e remains unchanged. For example, when t and T are in seconds, e can be set to 2 seconds.
[0058] In the knocking request message in the embodiment of the present application, without transmitting the first timestamp t, it does not contain any plaintext information. The first user identifier is a result of one-way calculation, and the first access target information c is an encrypted result. In this case, the internal network observer cannot obtain any clues from the knocking request and even has difficulty distinguishing port scanning from this knocking behavior.
[0059] In addition, it should be noted that the embodiment of the present application does not limit the transport layer protocol used for sending the knocking request message itself, and TCP, UDP and other transport layer protocols can be used.
[0060] After the firewall determines the original user identifier u = u' corresponding to the pseudonym p (the first user identifier), the key k corresponding to the original user identifier can be found from the user database, and the key k is used to decrypt the first access target information c in the knocking request message to obtain the original access target information d. The specific steps are as follows.
[0061] In some embodiments of the present application, the first access target information is obtained by encrypting a specific mixed result with a key. The specific mixed result is determined by the check information and the original access target information. Decrypting the first access target information in the knocking request message with the key includes: obtaining the key stored in the user database corresponding to the target user identifier, and decrypting the first user identifier with the key to obtain a decryption result, where the decryption result includes: a check part and an access target part; when the check part in the decryption result is consistent with the check information used when mixing the original access target information, the access target part in the decryption result is determined as the original access target information corresponding to the first access target information.
[0062] Specifically, in this embodiment, taking the verification information to select the first timestamp, and the mixing method of the first timestamp and the original access target information as direct splicing as an example for illustration. In this case, the decryption algorithm D associated with the encryption algorithm E can be used to obtain t||d = D(k, c), where the decryption result includes a verification part and an access target part. If the decryption fails, the check fails. If the t in the verification part obtained by decryption is inconsistent with the above-recognized verification information (i.e., the first timestamp), the check also fails.
[0063] It should be noted that in many encryption modes, even if the ciphertext is tampered with, it can still be successfully decrypted (but the decrypted content has been tampered with). Only by using authenticated encryption can it be detected whether an error occurs during the decryption process, so as to ensure that the original access target information d obtained by decryption is trustworthy.
[0064] Furthermore, the firewall can check whether the original access target information d is a correctly formatted access target. If not, the check fails. For example, the format of the original access target information d can be the destination IP address and destination protocol port number in binary form, or the uniform resource identifier in string form (only accurate to the domain name, without specific path, such as https: / / example.com).
[0065] This application embodiment does not limit which format of the original access target information is specifically selected in practical applications. However, when d is represented in string form, since symmetric encryption may disclose the length of d and thus the knocking request may be associated, the user side needs to perform random padding at the beginning or end of d before the encryption operation of c = E(k, t||d). For example, fill in a random number of English space symbols within a certain range to prevent the internal network observer from inferring the specific length of d based on the length of the first access target information c obtained after encryption. Specifically as follows.
[0066] In some embodiments of this application, the original access target information includes: the uniform resource identifier in string form; before encrypting the original access target information, it further includes: in the case where the original access target information is in string form, generating a target random number within a preset numerical range, where the target random number is a positive integer; adding a preset character with the number of target random digits (for example, English space symbols) at the beginning or end of the original access target information to obtain a new original access target information.
[0067] For example, as Figure 2 shown, Figure 2The original access target information d in it is represented by a uniform resource identifier in string form, and before each execution of the encryption operation E(k,*), a random number of English spaces within a certain range [min,max] needs to be filled at the end of d; in Figure 2 In Figure 2 , the filled string (enclosed in double quotes) is underlined to highlight this filling effect. This way, it does not affect the firewall to extract the target d for which the user requests access, and when d remains unchanged (that is, when the user always requests the same external network target), it can effectively prevent the internal network observer from inferring which knocking requests come from the same user (that is, making associations) based on the length of c. Correspondingly, after the firewall decrypts c, the space string at the end of d also needs to be removed.
[0068] It is easy to understand that when d is the destination IP address and destination protocol port number encoded in binary form, since the IPv4 address is always 4 bytes long and the IPv6 address is always 16 bytes long, the internal network observer cannot effectively associate the knocking requests based on the length of c. At this time, there is no need for additional filling; the first timestamp can be directly mixed with the original access target information to obtain a specific mixing result; and the specific mixing result is encrypted using the key to obtain the first access target information. The user can also disable the IPv4 address and only use the IPv6 address (or disable the IPv6 address and only use the IPv4 address), so as to achieve the effect that the internal network observer cannot obtain any intelligence about d.
[0069] After the firewall determines that the format of the original access target information is correct, it can obtain the source IP of the user and then open the corresponding network channel for this address. The specific steps are as follows.
[0070] In some embodiments of the present application, opening the network channel between the source address corresponding to the user terminal and the destination address corresponding to the original access target information includes the following steps: determining the source address corresponding to the knocking request message and the destination address corresponding to the original access target information; controlling the firewall to open the network channel between the source address and the destination address, and using the network channel to communicate between the source address and the destination address; automatically closing the network channel between the source address and the destination address when the idle duration of the network channel exceeds the preset time threshold or a channel closing request sent by the user terminal is received.
[0071] Specifically, the firewall extracts the source IP of the user from the knock request packet and temporarily enables an outbound release policy for this address to the access target d (the same applies to incoming traffic). When d is a uniform resource identifier in string form and the domain name therein can be resolved to multiple destination IP addresses, the firewall may need to uniformly and temporarily enable policies for the user source IP address to these destination IP addresses. The destination protocol port involved is determined according to the uniform resource identifier of d (for example, https: / / example.com corresponds to the TCP destination port 443, while https: / / example.com:8080 corresponds to the TCP destination port 8080).
[0072] After the authorized user sends a knock request, wait for a moment and then initiate an access to the external network target d. The firewall can also monitor the network data of the authorized user to the target d for which it requests to enable access. If the idle duration exceeds a preset threshold, it is considered that the user's access has ended, and the release policy temporarily enabled for the user before is automatically closed. Alternatively, following the previous steps, the user can actively initiate a request to close the firewall and the firewall will execute it, which will not be elaborated here.
[0073] In addition, the firewall can also record the information on enabling and closing the temporary policy in the log, and the specific steps are as follows.
[0074] In some embodiments of the present application, the method further includes the following steps: recording the log information of the network channel.
[0075] Specifically, the firewall can record the information on enabling and closing the temporary policy (including the firewall-side timestamp T, the user source IP, the user identifier u, the target d, etc.) in the log for future auditing purposes.
[0076] The above process steps in the embodiments of the present application can be mainly applied to the "reverse knock" or "knock out" scenario in network access control. For example, when a certain regional network accesses the external network, due to policies and other reasons, it can only access targets in a specific whitelist, and the default is closed for those not in the whitelist; if an authorized user needs to temporarily access an external network target not in the whitelist, the method in the present application can be used to send a knock request to the intelligent firewall deployed at the network boundary in a concealed form, so that the firewall enables a temporary release policy for the authorized user.
[0077] The following further illustrates the method steps in the embodiments of the present application with specific cases.
[0078] Suppose the metropolitan area network of a certain technology city cannot access the external network by default. When there are special requirements, authorized users are allowed to temporarily access external network targets. The solution in the embodiments of the present application can be applied as a lightweight and sufficiently concealed solution to meet this requirement. Specifically, in this case, d is selected in the form of a string, t and T are selected as UNIX timestamps in milliseconds and saved in 8-byte long integers, e is taken as 2000 milliseconds, both u and k of the user are 128-bit secure random numbers, h is selected as the US national standard SHA-256 and the input parameters (t and u) are concatenated in the form of bit strings, and E is selected as the US national standard AES-128-GCM.
[0079] Suppose a user identifier is u = 0x13ed016a577f16c569f88ce208d3f26b, and his client software selects a fresh (i.e., different each time) random number 14 in the interval [10, 30]. Based on this, the uniform resource identifier he wants to temporarily access, https: / / example.com, is added with 14 spaces to transform into d with a total length of 33 bytes. Thus, t||d is a total of 8 + 33 = 41 bytes, and then it is encrypted into c and sent at 10:44:32.791 seconds on the morning of March 2, 2025, Beijing time, that is, t = 0x19554bdb197. His pseudonym p = h(t, u) = h(t||u) = h(0x0000019554bdb19713ed016a577f16c569f88ce208d3f26b) = 0x6053fd1a094002683d63204eda9cf013d49d66b6b424ba15fcb47854cb437ed4. The knocking request sent by this user contains: 8-byte t, 32-byte p, and 69-byte c. Therefore, the total net payload length of the knocking request is only 8 + 32 + 69 = 109 bytes, and t, p, and c can be completely placed in a UDP packet (or TCP packet) in the agreed order for transmission.
[0080] After the firewall receives the above knocking request, it extracts t and compares it with the local timestamp T. Intuitively, t < T should hold. However, since there may be certain errors between t and T and the standard clock, as long as the difference between t and T is within e = 2000 milliseconds, the firewall can accept it. In actual situations, it is possible that t is slightly faster than the standard clock while T is slightly slower than the standard clock, resulting in the sending timestamp t being even greater than the receiving timestamp T. In this case, the firewall receives the knocking request at 10:44:32.185 seconds of its local time. Since T - 2000 ≤ t ≤ T + 2000, the firewall determines that the request is fresh and valid. Next, the firewall needs to traverse all non-disabled u in the database to find p = h(t||u), where the values of t and p are as above.
[0081] Compared with the anonymized knockd technology in the related art, the knock requests in the solution of this application use cryptographic techniques. The firewall can check the user's identity and then implement effective network access control, especially for temporary outbound access control (including auditing). Unauthorized persons cannot abuse the knock signals through means such as eavesdropping, replay, and forgery to deceive the firewall; the knock requests use pseudonyms to protect the user's original identity from being leaked. Based on this, the firewall can quickly find the user identifier through exhaustive search (or identify that the user does not have a legal identity), but the attacker cannot reveal the user's identity or associate the knock requests sent by the same user multiple times, thus ensuring both the legitimacy of the user's identity and effective protection of the user's privacy; the solution is user-friendly. The user only needs to carry a security medium and can flexibly specify the target for which temporary access is requested; the knock requests in this solution only contain a stateless knock signal, the process is concise and can be implemented based on domestic and foreign standard cryptographic algorithms, reducing the implementation complexity.
[0082] The embodiment of this application also provides another network access control method. Figure 3 It is a schematic diagram of the process flow of another network access control method provided by the embodiment of this application, as Figure 3 shown. This method is applied to the user terminal side and includes the following steps:
[0083] Step S302: Use a collision-resistant one-way mapping algorithm to perform a one-way mapping on the first timestamp and the original user identifier to obtain the first user identifier.
[0084] Step S304: Use the key corresponding to the original user identifier to encrypt the original access target information to obtain the first access target information, where the original access target information is the access target information in plaintext form.
[0085] Step S306: Generate a knock request message based on the first user identifier and the first access target information, and send the knock request message to the firewall.
[0086] Step S308: When the firewall opens the network channel in accordance with the knock request, access the access target in the second network, where the network channel is the channel between the source address in the first network corresponding to the user terminal opened by the firewall in response to the knock request message and the destination address in the second network corresponding to the original access target information. The first network and the second network are two networks isolated by the firewall.
[0087] Optionally, the original access target information includes: a uniform resource identifier in string form; before encrypting the original access target information, it further includes: when the original access target information is in string form, generating a target random number within a preset numerical range, where the target random number is a positive integer; adding a preset character of the target random number of digits at the head or end of the original access target information to obtain a new original access target information.
[0088] Optionally, the original access target information further includes: a destination Internet protocol address and a destination protocol port number in binary form; encrypting the original access target information includes: mixing the check information with the original access target information to obtain a specific mixing result; using a key to encrypt the specific mixing result to obtain a first access target information.
[0089] It should be noted that the network access control device provided in this embodiment is a method embodiment on the user terminal side corresponding to the Figure 1 network access control method shown. Therefore, the relevant explanations of the above network access control method also apply to the embodiments of the present application, and will not be repeated here.
[0090] The embodiments of the present application further provide a firewall, including: a memory and a processor, where the processor is used to run a program stored in the memory. When the program runs, it executes a network access control method: receiving a knocking request message sent by a user terminal located in a first network, where the knocking request message includes: a first user identifier and a first access target information. The first user identifier is obtained by performing a one-way mapping on a first timestamp and an original user identifier using a collision-resistant one-way mapping algorithm. The first access target information is obtained by encrypting the original access target information using a key corresponding to the original user identifier; determining whether there is a target user identifier in the user database, where the target user identifier is a specific candidate user identifier in the user database. The mapping result obtained by inputting a specific candidate timestamp and the specific candidate user identifier into the one-way mapping algorithm is the same as the first user identifier. The user database includes at least one user registration information, and the user registration information includes: a candidate user identifier and a key corresponding to the candidate user identifier; when it is determined that there is a target user identifier in the user database, obtaining the key corresponding to the target user identifier, and using the key to decrypt the first access target information in the knocking request message to obtain the original access target information; opening a network channel between the source address corresponding to the user terminal and the destination address located in a second network corresponding to the original access target information, so that the user terminal can access an access target located in the second network, where the first network and the second network are two networks isolated by the firewall.
[0091] An embodiment of the present application further provides a user terminal, including: using a collision-resistant one-way mapping algorithm to perform a one-way mapping on a first timestamp and an original user identifier to obtain a first user identifier; using a key corresponding to the original user identifier to encrypt the original access target information to obtain a first access target information; generating a knocking request message according to the first user identifier and the first access target information, and sending the knocking request message to a firewall; when the firewall opens a network channel according to the knocking request, accessing an access target in a second network, where the network channel is a channel between a source address in a first network corresponding to the user terminal in response to the knocking request message and a destination address in the second network corresponding to the original access target information, and the first network and the second network are two networks isolated by the firewall.
[0092] An embodiment of the present application further provides a non-volatile storage medium, and the non-volatile storage medium includes a stored computer program. Wherein, the device where the non-volatile storage medium is located executes the following network access control method by running the computer program: receiving a knocking request message sent by a user terminal in a first network, where the knocking request message includes: a first user identifier and a first access target information, the first user identifier is obtained by performing a one-way mapping on a first timestamp and an original user identifier using a collision-resistant one-way mapping algorithm, and the first access target information is obtained by encrypting the original access target information using a key corresponding to the original user identifier; determining whether a target user identifier exists in a user database, where the target user identifier is a specific candidate user identifier in the user database, and the mapping result obtained by inputting a specific candidate timestamp and the specific candidate user identifier into the one-way mapping algorithm is the same as the first user identifier, and the user database includes at least one user registration information, and the user registration information includes: a candidate user identifier, and a key corresponding to the candidate user identifier; when it is determined that the target user identifier exists in the user database, obtaining the key corresponding to the target user identifier, and using the key to decrypt the first access target information in the knocking request message to obtain the original access target information; opening a network channel between the source address corresponding to the user terminal and the destination address in the second network corresponding to the original access target information, so that the user terminal accesses an access target in the second network, where the first network and the second network are two networks isolated by the firewall.
[0093] Alternatively, use a collision-resistant one-way mapping algorithm to perform a one-way mapping on the first timestamp and the original user identifier to obtain a first user identifier; use the key corresponding to the original user identifier to encrypt the original access target information to obtain first access target information; generate a knock request message based on the first user identifier and the first access target information, and send the knock request message to the firewall; when the firewall opens a network channel in accordance with the knock request, access the access target located in the second network, where the network channel is a channel between the source address in the first network corresponding to the user terminal and the destination address in the second network corresponding to the original access target information in response to the knock request message, and the first network and the second network are two networks isolated by the firewall.
[0094] An embodiment of this application also provides a computer program product, including a computer program, which when executed by a processor implements the steps of the network access control method described in each embodiment of this application: receiving a knock request message sent by a user terminal located in the first network, where the knock request message includes: a first user identifier and first access target information, the first user identifier is obtained by performing a one-way mapping on the first timestamp and the original user identifier using a collision-resistant one-way mapping algorithm, and the first access target information is obtained by encrypting the original access target information using the key corresponding to the original user identifier; determining whether a target user identifier exists in the user database, where the target user identifier is a specific candidate user identifier in the user database, and the mapping result obtained by inputting a specific candidate timestamp and the specific candidate user identifier into the one-way mapping algorithm is the same as the first user identifier, and the user database includes at least one user registration information, and the user registration information includes: a candidate user identifier and a key corresponding to the candidate user identifier; when it is determined that a target user identifier exists in the user database, obtaining the key corresponding to the target user identifier, and using the key to decrypt the first access target information in the knock request message to obtain the original access target information; opening a network channel between the source address corresponding to the user terminal and the destination address in the second network corresponding to the original access target information, so that the user terminal can access the access target located in the second network, where the first network and the second network are two networks isolated by the firewall.
[0095] Alternatively, use a collision-resistant one-way mapping algorithm to perform a one-way mapping on the first timestamp and the original user identifier to obtain the first user identifier; use the key corresponding to the original user identifier to encrypt the original access target information to obtain the first access target information; generate a knocking request message based on the first user identifier and the first access target information, and send the knocking request message to the firewall; when the firewall opens the network channel in accordance with the knocking request, access the access target located in the second network, where the network channel is the channel between the source address in the first network corresponding to the user terminal opened by the firewall in response to the knocking request message and the destination address in the second network corresponding to the original access target information, and the first network and the second network are two networks isolated by the firewall.
[0096] The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages and disadvantages of the embodiments.
[0097] In the above embodiments of the present application, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0098] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces. The indirect coupling or communication connection of the units or modules can be in an electrical or other form.
[0099] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0100] In addition, the functional units in the various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0101] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs that can store program codes.
[0102] The above are only the preferred embodiments of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of this application.
Claims
1. A network access control method, characterized in that, Including: Receiving a knocking request message sent by a user terminal located in a first network, where the knocking request message includes: a first user identifier and first access target information. The first user identifier is obtained by performing a one-way mapping on a first timestamp and an original user identifier using a collision-resistant one-way mapping algorithm. The first access target information is obtained by encrypting original access target information using a key corresponding to the original user identifier; Determining whether a target user identifier exists in a user database, where the target user identifier is a specific candidate user identifier in the user database, and the mapping result obtained by inputting a specific candidate timestamp and the specific candidate user identifier into the one-way mapping algorithm is the same as the first user identifier. The user database contains at least one user registration information, and the user registration information includes: the candidate user identifier and the key corresponding to the candidate user identifier; When it is determined that the target user identifier exists in the user database, obtaining the key corresponding to the target user identifier, and using the key to decrypt the first access target information in the knocking request message to obtain the original access target information; Opening a network channel between the source address corresponding to the user terminal and the destination address located in a second network corresponding to the original access target information, so that the user terminal can access an access target located in the second network, where the first network and the second network are two networks isolated by a firewall.
2. The network access control method according to claim 1, wherein Determining whether a target user identifier exists in the user database includes: Determining the local timestamp when the knocking request message is received as a second timestamp, and determining a candidate timestamp interval based on the second timestamp and a preset allowable error; Obtaining candidate timestamps within the candidate timestamp interval according to a preset time granularity; Inputting the candidate timestamp and the candidate user identifier into the one-way mapping algorithm to obtain a mapping result, where the one-way mapping algorithm includes: a first mapping parameter and a second mapping parameter. The first mapping parameter traverses each candidate timestamp in the candidate timestamp interval, and the second mapping parameter traverses each candidate user identifier in the user database; When the mapping result is consistent with the first user identifier, determining the value taken by the first mapping parameter when the mapping result is obtained as the first timestamp in the user terminal, and determining the value taken by the second mapping parameter when the mapping result is obtained as the target user identifier.
3. The network access control method according to claim 1, wherein The knocking request message further includes: the first timestamp; Determining whether a target user identifier exists in the user database further includes: Determining the local timestamp when the knocking request message is received as a second timestamp, and determining a candidate timestamp interval based on the second timestamp and a preset allowable error; When the first timestamp in the knock request message is within the candidate timestamp range, the first timestamp and the candidate user identifier are input into the one-way mapping algorithm to obtain a mapping result. The one-way mapping algorithm includes a first mapping parameter and a second mapping parameter. The first mapping parameter takes the first timestamp, and the second mapping parameter traverses each candidate user identifier in the user database. When the mapping result is consistent with the first user identifier, the value taken by the second mapping parameter when the mapping result is obtained is determined as the target user identifier.
4. The network access control method according to claim 1, wherein The first access target information is obtained by encrypting a specific mixed result with the key, and the specific mixed result is determined by the verification information and the original access target information. Decrypting the first access target information in the knock request message with the key includes: Obtaining the key corresponding to the target user identifier stored in the user database, and decrypting the first user identifier with the key to obtain a decryption result, where the decryption result includes a verification part and an access target part. When the verification part in the decryption result is consistent with the verification information used when mixing the original access target information, the access target part in the decryption result is determined as the original access target information corresponding to the first access target information.
5. The network access control method according to claim 1, characterized in that, The method further includes: In response to a registration request message, generating the original user identifier and a key corresponding to the original user identifier. Storing the original user identifier and the key as a candidate user identifier and its corresponding key in the user database of the firewall, and storing the original user identifier and the key in a secure storage medium so that the user can obtain the original user identifier and the key by receiving the secure storage medium.
6. A network access control method, characterized in that, Includes: Using a collision-resistant one-way mapping algorithm to perform a one-way mapping on the first timestamp and the original user identifier to obtain a first user identifier. Encrypting the original access target information with the key corresponding to the original user identifier to obtain the first access target information. Generating a knock request message based on the first user identifier and the first access target information, and sending the knock request message to the firewall. When the firewall opens a network channel in response to the knock request, accessing the access target in the second network, where the network channel is a channel between the source address in the first network corresponding to the user terminal and the destination address in the second network corresponding to the original access target information opened by the firewall in response to the knock request message, and the first network and the second network are two networks isolated by the firewall.
7. The network access control method according to claim 6, wherein The original access target information includes a uniform resource identifier in string form. Before encrypting the original access target information, it also includes: When the original access target information is in the form of a string, generate a target random number within a preset numerical range, where the target random number is a positive integer; Add a preset character of the target random number digits to the head or end of the original access target information to obtain the new original access target information.
8. The network access control method according to claim 7, wherein The original access target information further includes: a destination Internet protocol address and a destination protocol port number in binary form; encrypting the original access target information includes: Mix the verification information with the original access target information to obtain a specific mixing result; Use the key to encrypt the specific mixing result to obtain the first access target information.
9. A firewall, characterized in that, Including: A memory and a processor, the processor is configured to run a program stored in the memory, where the program, when running, executes the network access control method according to any one of claims 1 to 5.
10. A user terminal, characterized in that, Including: A memory and a processor, the processor is configured to run a program stored in the memory, where the program, when running, executes the network access control method according to any one of claims 6 to 8.
Citation Information
Patent Citations
Data transmission method and device, equipment and storage medium
CN113904826A
Firewall authority management method and device, equipment and storage medium
CN115865437A
Authorization communication method and device, computer equipment and storage medium
CN118300899A
Access control method, access control system, terminal and storage medium
WO2023116791A1