Network access method and device based on static access binding

By generating static access binding access control rules by switches, security vulnerabilities and delay problems caused by relying on centralized management platforms in the existing technology are solved, and terminal access control with millisecond response is realized, which improves network security and reliability.

CN120358071APending Publication Date: 2025-07-22HANGZHOU DPTECH TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510680152.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing network access control architecture relies on a centralized management platform, which leads to the inability to identify illegal terminals in a timely manner when the platform fails or attacks, and there are security vulnerabilities and processing delays, affecting network security and reliability.

Method used

The network access method of static access binding is adopted. The switch obtains configuration information files from the management platform, generates access control rules, and realizes millisecond-level response terminal access control when it is separated from the centralized management platform. Illegal terminal access is prevented through binding of IP addresses, MAC addresses and access ports.

Benefits of technology

It realizes rapid identification and blocking of illegal traffic when departing from the centralized management platform, improves network security and reliability, reduces processing delays, and enhances system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358071A_ABST
    Figure CN120358071A_ABST
Patent Text Reader

Abstract

The invention relates to a network access method and device based on static access binding. The method comprises the following steps: a switch obtains a configuration information file from a management platform, wherein the configuration information file comprises static access binding information of terminal equipment; the switch issues the configuration information file to an equipment kernel; generating an access control rule based on the terminal access information in the configuration information file; the switch receives the access flow; and the switch performs network access judgment on the access flow according to the access control rule. According to the network access method and device based on static access binding, terminal access control of millisecond-level response can be realized under the condition of being separated from a centralized management platform, illegal traffic is effectively prevented from entering, and the effect speed and the system reliability are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer information processing, and more particularly, to a network access method and device based on static access binding. Background Art

[0002] With the continuous expansion of the network scale and the continuous escalation of security threats, terminal access control has become an important part of network security. To ensure the legitimacy of access devices, switches usually have the ability to trace terminals, which is used to identify and record the information of terminal devices connected to their ports. The current mainstream switches implement the terminal tracing function through the following several methods: one is based on the chip mechanism, when the switching chip receives the first packet with an unknown MAC address, it sends it to the CPU for processing; the second is to sample the packets (such as a 10% sampling rate) and send some packets to the CPU for parsing; the third is to copy all ARP packets through the access control rules and send them for processing. After the packet reaches the CPU, the device will parse its layer 2 and layer 3 information, extract the MAC address, IP address and access port of the terminal, etc., and report the formed triple data to the unified management platform UMC for subsequent policy judgment.

[0003] In the existing network access control architecture, dynamic access binding is a centralized management solution based on the UMC platform. This solution reports terminal information through the terminal tracing function of the switch, and the UMC platform completes the closed-loop process of unified judgment and issuing control instructions. When an illegal or conflicting terminal access is detected, the UMC platform sends a blocking packet carrying the terminal characteristics to the switch, and the switch generates an access control rule accordingly to discard the terminal traffic. This mechanism realizes the automatic identification and interception of illegal terminals and is widely used in campus networks and enterprise network environments that require centralized policy control.

[0004] Although the dynamic access binding solution has the ability of centralized management and control, it still has the following obvious defects in high-security and low-latency application scenarios:

[0005] Dependence on the online status of the UMC platform: When the UMC platform goes offline due to a fault or being attacked, the switch will not be able to report terminal information and will not be able to receive blocking policies, resulting in illegal terminals being able to access the network without being identified and processed, forming a serious security vulnerability.

[0006] There is a delay in the processing flow: Dynamic access binding depends on the interaction process of "report - judge - issue - execute", and there is a processing delay during the period from terminal access to completion of blocking. During this time window, illegal terminals may have damaged network resources, affecting the overall protection ability.

[0007] Therefore, a new network access method and device based on static access binding are needed.

[0008] The above information disclosed in the background section is only used to enhance the understanding of the background of the present application. Therefore, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0009] In view of this, the present application provides a network access method and device based on static access binding, which can achieve millisecond-level response terminal access control without a centralized management platform, effectively defend against illegal traffic from entering, and improve the response speed and system reliability.

[0010] Other features and advantages of the present application will become apparent through the following detailed description, or be learned in part through the practice of the present application.

[0011] According to an aspect of the present application, a network access method based on static access binding is proposed. The method includes: a switch obtains a configuration information file from a management platform, and the configuration information file contains static access binding information of terminal devices; the switch distributes the configuration information file to a device kernel; generates an access control rule based on the terminal access information in the configuration information file; the switch receives access traffic; the switch performs network access judgment on the access traffic according to the access control rule.

[0012] In an exemplary embodiment of the present application, the switch obtains a configuration information file from a management platform, including: the switch enables the static access binding function; the switch sends a binding information request message to the management platform; the management platform generates a return message according to the binding information request message; the switch obtains the configuration information file according to the return message sent by the management platform.

[0013] In an exemplary embodiment of the present application, the management platform generates a return message according to the binding information request message, including: the management platform extracts switch information according to the binding information request message; generates configuration data according to the switch information; determines the binding mode and rule information of the switch; generates the return file through the configuration data, binding mode, and rule information.

[0014] In an exemplary embodiment of the present application, generating the return file through the configuration information, binding mode, and rule information includes: generating a configuration information file through the configuration data, binding mode, and rule information; hosting the configuration information file in a page URL; generating the return file through the page URL.

[0015] In an exemplary embodiment of the present application, the switch obtains a configuration information file according to the feedback message sent by the management platform, including: the switch parses the page URL from the feedback message sent by the management platform; and obtains the configuration information file from the page URL through the wget command.

[0016] In an exemplary embodiment of the present application, the switch distributes the configuration information file to the device kernel, including: the switch parses the configuration information file through a user-mode process and distributes it to the device kernel.

[0017] In an exemplary embodiment of the present application, generating an access control rule based on the terminal access information in the configuration information file includes: generating an ARP user binding whitelist pass-through access control rule based on the terminal access information in the configuration information file; and / or generating an ARP all-drop packet access control rule based on the terminal access information in the configuration information file; and / or generating an IPv4 user binding whitelist pass-through access control rule based on the terminal access information in the configuration information file; and / or generating an IPv4 all-drop packet access control rule based on the terminal access information in the configuration information file.

[0018] In an exemplary embodiment of the present application, it further includes: during the system restart process of the switch, retaining the configuration information file; during the system initialization stage of the switch, before the port forwarding function is enabled, distributing the configuration information file to the kernel to generate an access control rule; and after the access control rule is generated, enabling the traffic forwarding function.

[0019] In an exemplary embodiment of the present application, it includes: the management platform generates updated configuration information; the management platform sends the updated configuration file to the switch through the uplink port; the switch regenerates and updates the access control rule based on the updated configuration file.

[0020] According to an aspect of the present application, a network access device based on static access binding is proposed. The device includes: an information module for the switch to obtain a configuration information file from the management platform, where the configuration information file contains static access binding information of terminal devices; a distribution module for the switch to distribute the configuration information file to the device kernel; a rule module for generating an access control rule based on the terminal access information in the configuration information file; a traffic module for the switch to receive access traffic; and a judgment module for the switch to perform network access judgment on the access traffic according to the access control rule.

[0021] According to one aspect of the present application, an electronic device is provided, which includes: one or more processors; a storage device for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described above.

[0022] According to one aspect of the present application, a computer-readable medium is provided, on which a computer program is stored, and when the program is executed by a processor, the method as described above is implemented.

[0023] Based on the network access method and device with static access binding of the present application, the switch obtains a configuration information file from the management platform, and the configuration information file contains the static access binding information of the terminal device; the switch distributes the configuration information file to the device kernel; generates an access control rule based on the terminal access information in the configuration information file; the switch receives access traffic; the switch performs network access judgment on the access traffic according to the access control rule, which can realize millisecond-level response terminal access control without a centralized management platform, effectively defend against illegal traffic from entering, and improve the response speed and system reliability.

[0024] It should be understood that the above general description and the following detailed description are only exemplary and do not limit the present application. Brief Description of the Drawings

[0025] By referring to the drawings and describing their exemplary embodiments in detail, the above and other objectives, features, and advantages of the present application will become more obvious. The following described drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0026] Figure 1 It is a system block diagram of a network access method based on static access binding shown according to an exemplary embodiment.

[0027] Figure 2 It is a flowchart of a network access method based on static access binding shown according to an exemplary embodiment.

[0028] Figure 3 It is a schematic diagram of a network access method based on static access binding shown according to another exemplary embodiment.

[0029] Figure 4 It is a flowchart of a network access method based on static access binding shown according to another exemplary embodiment.

[0030] Figure 5Schematic diagram of a network access method based on static access binding shown according to another exemplary embodiment.

[0031] Figure 6 Block diagram of a network access device based on static access binding shown according to an exemplary embodiment.

[0032] Figure 7 Block diagram of an electronic device shown according to an exemplary embodiment.

[0033] Figure 8 Block diagram of a computer-readable medium shown according to an exemplary embodiment. Detailed implementation manners

[0034] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this application will be thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art. Like reference numerals in the figures denote like or similar parts, and thus their repetitive description will be omitted.

[0035] In addition, the described features, structures or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present application. However, those skilled in the art will realize that the technical solutions of the present application can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, well-known methods, devices, implementations or operations are not shown or described in detail to avoid obscuring aspects of the present application.

[0036] The block diagrams shown in the drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0037] The flowcharts shown in the drawings are merely illustrative and do not necessarily include all the content and operations / steps, nor are they necessarily executed in the order described. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to the actual situation.

[0038] It should be understood that although terms such as first, second, and third may be used herein to describe various components, these components should not be limited by these terms. These terms are used to distinguish one component from another. Thus, the first component discussed below may be referred to as the second component without departing from the teachings of the concept of this application. As used herein, the term "and / or" includes any one of the associated listed items and all combinations of one or more of them.

[0039] Those skilled in the art can understand that the drawings are only schematic diagrams of exemplary embodiments, and the modules or processes in the drawings are not necessarily essential for implementing this application, so they cannot be used to limit the protection scope of this application.

[0040] The technical abbreviations involved in this application are explained as follows:

[0041] ACL (Access Control List): Refers to a network traffic filtering mechanism used to control the forwarding or discarding of data packets. ACL can check the data traffic entering or leaving the switch interface according to the set rules to determine whether to allow the data packet to pass.

[0042] UMC (Unified Management Console): Refers to a centralized management platform that provides a unified management interface for IT resources such as network devices, servers, and storage devices. Through UMC, administrators can conveniently perform operations such as device configuration, monitoring, troubleshooting, and policy management, thereby improving management efficiency and resource utilization.

[0043] ARP (Address Resolution Protocol) packet is a network protocol data packet used to resolve the mapping of IP addresses to physical addresses (MAC addresses) in a local area network. When a host needs to communicate with another host within the same network through an IP address, it will first obtain the MAC address of the target host through the ARP protocol so as to send the data packet to the correct physical address.

[0044] Aiming at the deficiencies of the dynamic access binding method in the prior art, this application proposes a static access binding method that does not need to rely on real-time communication between the UMC platform and the access switch. The aim is to implement strict access control over the terminal devices connected to the switch starting from the switch startup. By binding the IP address, MAC address, and access port, it can effectively prevent the destruction of the network by illegal terminals accessing, and at the same time prevent the behavior of the devices connected under the switch from privately changing the IP address or changing the access location. Through the above measures, the technology of this application achieves the purpose of building a more stable and secure access layer network.

[0045] The content of the present application will be described in detail below with reference to specific embodiments.

[0046] Figure 1 It is a system block diagram of a network access method and device based on static access binding shown according to an exemplary embodiment.

[0047] As Figure 1 shown, the system architecture 10 may include terminal devices 101, 102, 103, a network 104, switches 105, and a management platform 106. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the switches 105, and between the switches 105 and the management platform 106. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0048] Users can use the terminal devices 101, 102, 103 to interact with other terminals through the switches 105 to receive or send messages, etc. The terminal devices 101, 102, 103 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.

[0049] The switch 105 can perform network access judgment on the information sent by users using the terminal devices 101, 102, 103. The switch 105 performs network access judgment on the access traffic according to the access control rules, and decides whether to allow or block the access traffic according to the judgment result.

[0050] The switch 105 can obtain a configuration information file from, for example, the management platform 106, and the configuration information file contains the static access binding information of the terminal device; the switch 105 can, for example, send the configuration information file to the device kernel; the switch 105 can, for example, generate access control rules based on the terminal access information in the configuration information file; the switch 105 can, for example, receive access traffic from the terminal devices 101, 102, 103; the switch 105 can, for example, perform network access judgment on the access traffic according to the access control rules.

[0051] It should be noted that the network access method based on static access binding provided by the embodiments of the present application can be executed by the switch 105. Correspondingly, the network access device based on static access binding can be set in the switch 105.

[0052] Figure 2 It is a flowchart of a network access method based on static access binding shown according to an exemplary embodiment. The network access method 20 based on static access binding includes at least steps S202 to S210.

[0053] AsFigure 2 As shown, in S202, the switch obtains the configuration information file from the management platform, and the configuration information file contains the static access binding information of the terminal device. The static binding information is used to specify the access behavior of legal terminal devices, and generally includes but is not limited to fields such as the MAC address, IP address, VLAN ID, access port number, and access time policy of the terminal.

[0054] In one embodiment, the management platform extracts switch information according to the binding information request message; generates configuration data according to the switch information; determines the binding mode and rule information of the switch; and generates the return file through the configuration data, binding mode, and rule information. The specific content will be Figure 4 described in detail in the embodiment shown.

[0055] In S204, the switch distributes the configuration information file to the device kernel. The switch parses the configuration information file through a user-mode process and distributes it to the device kernel.

[0056] In a specific embodiment, for example, after the switch receives the configuration information file, the user-mode management process is responsible for parsing the content of the file and organizing the parsing result into a policy configuration structure that can be recognized by the device kernel. Subsequently, the switch passes this structure to the kernel space through the kernel interface to ensure that the access control policy can take effect in the forwarding path of the switching chip, thereby realizing the linkage control of the data plane and the control plane.

[0057] After the switch obtains the configuration file, it parses its content through a user-mode process, including but not limited to the following information: the issued blocking mode and judgment conditions, and the number of user bindings. If the number of bound users exceeds the maximum limit allowed by the device, the switch will generate a log record of the excessive bound users. After completing the parsing of the configuration information, the configuration information is distributed to the device kernel through a system call for subsequent processing.

[0058] In S206, access control rules are generated based on the terminal access information in the configuration information file. The switch kernel dynamically generates multiple access control rules (ACLs) according to the terminal access information specified in the configuration information file. These rules cover multiple protocol levels to ensure strict terminal identity filtering from the access link. Specifically, it includes but is not limited to the following types of access control rules:

[0059] ARP user binding whitelist pass-through rule: Only allow ARP packets sent from the specified IP-MAC pair in the configuration information file through a specific port;

[0060] ARP all-drop packet rule: For terminals not in the static binding list, all their ARP packets will be discarded to prevent ARP spoofing;

[0061] IPv4 user binding whitelist pass-through rule: Allow terminals on the whitelist to initiate legitimate IPv4 communications at the configured IP address on specific ports;

[0062] IPv4 full packet loss rule: Intercept the IPv4 data stream of all unbound devices to further enhance the protection against illegal access.

[0063] More specifically, the above ACLs are matched in sequence to enable normal communication of bound terminals and block the traffic of illegal terminals:

[0064] For a legally bound terminal, the ARP packets it sends can be normally forwarded after matching the ARP whitelist ACL corresponding to the source MAC address; and after the source MAC address, source IP address, and access port match the IPv4 whitelist ACL, the IPv4 packets can also be normally forwarded.

[0065] For an illegal terminal, its ARP packets cannot match the ARP whitelist ACL and will finally match the ARP full packet loss ACL, and the packets will be discarded, thus forming a block. Similarly, when the IPv4 packets cannot match the IPv4 whitelist ACL, they will finally match the IPv4 full packet loss ACL and will also be discarded, thus achieving the block.

[0066] In S208, the switch receives the access traffic.

[0067] In S210, the switch makes a network access judgment on the access traffic according to the access control rules.

[0068] Figure 3 is a schematic diagram of a network access method based on static access binding shown in another exemplary embodiment. As Figure 3 shown, the switch makes item-by-item matching for each received traffic data and performs a network access judgment according to the data plane access control rules issued to the kernel. The terminal traffic that conforms to the binding policy will be normally forwarded, while the packets that do not conform to the binding rules will be directly discarded or redirected to the management module for auditing, thus achieving fine-grained control and quasi-real-time defense of the access behavior.

[0069] According to the network access method based on static access binding of the present application, the switch obtains a configuration information file from the management platform, and the configuration information file contains the static access binding information of the terminal device; the switch distributes the configuration information file to the device kernel; generates an access control rule based on the terminal access information in the configuration information file; the switch receives access traffic; the switch performs network access judgment on the access traffic according to the access control rule, which can achieve millisecond-level response terminal access control without a centralized management platform, effectively prevent illegal traffic from entering, and improve the response speed and system reliability.

[0070] It should be clearly understood that the present application describes how to form and use specific examples, but the principles of the present application are not limited to any details of these examples. On the contrary, based on the teachings of the content disclosed in the present application, these principles can be applied to many other embodiments.

[0071] In one embodiment, it further includes: during the system restart process of the switch, the configuration information file is retained; during the system initialization stage of the switch, before the port forwarding function is enabled, the configuration information file is distributed to the kernel to generate an access control rule; after the access control rule is generated, the traffic forwarding function is enabled.

[0072] In practical applications, during the device restart process, the locally stored static access binding configuration file will be retained. During the system initialization stage, when the port traffic forwarding function has not been enabled, the device will directly distribute the configuration file to the kernel to regenerate the above four types of ACLs. After the ACLs are generated, the traffic forwarding function is enabled, so as to ensure that the traffic of illegal terminals still cannot pass during the device startup process.

[0073] In one embodiment, it further includes: the management platform generates updated configuration information; the management platform sends the updated configuration file to the switch through the uplink port; the switch regenerates and updates the access control rule based on the updated configuration file.

[0074] In practical applications, when the static access binding configuration needs to be updated, since the uplink port connected to the UMC platform does not enable the static access binding function, all packets can be freely sent and received. The UMC platform can send a new configuration file to the switch through the uplink port. When the switch receives the new configuration, the kernel will regenerate the whitelist linked list according to the new file, clear the old whitelist member ACLs, and distribute the new whitelist member ACLs.

[0075] During this process, the ARP full-drop packet ACL and the IPv4 full-drop packet ACL remain unchanged, ensuring that the traffic of illegal terminals is still blocked and no security risks are generated due to configuration updates.

[0076] Combined withFigure 4 Flowchart of Figure 5 and schematic diagram of Figure 2 Detailed description of "The switch obtains the configuration information file from the management platform" in the process shown in

[0077] As Figure 4 shown, in S402, the switch enables the static access binding function. This function is used to implement the network access control policy based on the preset terminal access information. When this function is activated, the switch will enter the static binding working mode, and no longer rely on the real-time determination of the external management platform, but independently execute the access control based on the pre-configured data.

[0078] In S404, the switch sends a binding information request message to the management platform. The switch actively sends a binding information request message to the management platform to obtain the corresponding static binding configuration. The request message can carry information including but not limited to the device identifier of the switch (such as device serial number or MAC address), software version, network area identifier where it is located, current port status, etc., which is convenient for the management platform to generate personalized configurations.

[0079] In S406, the management platform generates a return message according to the binding information request message. The management platform can extract the switch information according to the binding information request message; generate configuration data according to the switch information; determine the binding mode and rule information of the switch; generate the return file through the configuration data, binding mode, and rule information.

[0080] More specifically, a configuration information file can be generated through the configuration data, binding mode, and rule information; the configuration information file can be hosted in the page URL; the return file can be generated through the page URL.

[0081] In actual applications, when the switch enables the static access binding function, the switch will send a binding information request message to the UMC platform. After receiving the request message, the UMC platform generates a configuration information file containing the terminals already bound to the switch according to the switch that sent the request, and at the same time attaches content such as the binding mode and rule information. Subsequently, the UMC platform hosts the file in a URL of its own page and returns the URL information to the switch through the message.

[0082] In S408, the switch obtains the configuration information file according to the feedback message sent by the management platform. The switch parses the page URL from the feedback message sent by the management platform; and obtains the configuration information file from the page URL through the wget command. After receiving the feedback message, the switch parses the URL information therein, and obtains the configuration information file from the URL through the wget command, and saves it in the local storage. Thus, the configuration process of static access binding is completed.

[0083] This application provides a technical solution for uniformly distributing the whitelist access policy to the local switch through the UMC management platform, and the switch independently judges traffic access, which has the following beneficial effects:

[0084] 1. Efficient whitelist access mechanism: Through the whitelist policy, only the terminals authorized by the administrator are allowed to pass the traffic detection of the switch, thereby effectively preventing the illegal traffic of unbound terminals from entering the network and improving network security.

[0085] 2. Centralized management: The terminal binding operation is centralized in the UMC management platform, and there is no need to separately configure the whitelist on each switch, thereby simplifying the configuration process, improving the management efficiency, and reducing the risk of human operation errors.

[0086] 3. Configuration persistence and security: This solution supports the persistent storage of configurations, and can complete the distribution of the whitelist ACL and the blocking ACL in advance when the device restarts, ensuring that access control can be completed before the switch is initialized and the traffic is released, effectively avoiding potential security hazards during the restart process.

[0087] Those skilled in the art can understand that all or part of the steps of implementing the above embodiments are implemented as a computer program executed by the CPU. When the computer program is executed by the CPU, the above functions defined by the above method provided by this application are executed. The program can be stored in a computer-readable storage medium, and the storage medium can be a read-only memory, a disk or an optical disc, etc.

[0088] In addition, it should be noted that the above drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of this application, rather than for limiting purposes. It is easy to understand that the processes shown in the above drawings do not indicate or limit the time sequence of these processes. Additionally, it is also easy to understand that these processes can be executed synchronously or asynchronously in, for example, multiple modules.

[0089] The following is an embodiment of the device of this application, which can be used to execute the method embodiment of this application. For details not disclosed in the device embodiment of this application, please refer to the method embodiment of this application.

[0090] Figure 6It is a block diagram of a network access device based on static access binding shown according to another exemplary embodiment. As Figure 6 shown, the network access device 60 based on static access binding includes: an information module 602, a distribution module 604, a rule module 606, a traffic module 608, and a judgment module 610.

[0091] The information module 602 is used for the switch to obtain a configuration information file from the management platform, and the configuration information file contains the static access binding information of the terminal device; the information module 602 is also used for the switch to turn on the static access binding function; the switch sends a binding information request message to the management platform; the management platform generates a return message according to the binding information request message; the switch obtains the configuration information file according to the return message sent by the management platform.

[0092] The distribution module 604 is used for the switch to distribute the configuration information file to the device kernel; the distribution module 604 is also used for the switch to parse the configuration information file through the user-mode process and distribute it to the device kernel.

[0093] The rule module 606 is used to generate access control rules based on the terminal access information in the configuration information file; the rule module 606 is also used to generate an ARP user binding whitelist pass-through access control rule based on the terminal access information in the configuration information file; and / or generate an ARP full packet drop access control rule based on the terminal access information in the configuration information file; and / or generate an IPv4 user binding whitelist pass-through access control rule based on the terminal access information in the configuration information file; and / or generate an IPv4 full packet drop access control rule based on the terminal access information in the configuration information file.

[0094] The traffic module 608 is used for the switch to receive access traffic;

[0095] The judgment module 610 is used for the switch to perform network access judgment on the access traffic according to the access control rules.

[0096] According to the network access device based on static access binding of the present application, by the switch obtaining a configuration information file from the management platform, the configuration information file contains the static access binding information of the terminal device; the switch distributes the configuration information file to the device kernel; generating access control rules based on the terminal access information in the configuration information file; the switch receives access traffic; the switch performs network access judgment on the access traffic according to the access control rules, it is possible to achieve millisecond-level response terminal access control without a centralized management platform, effectively defend against illegal traffic from entering, and improve the response speed and system reliability.

[0097] Figure 7It is a block diagram of an electronic device shown according to an exemplary embodiment.

[0098] Reference will be made below Figure 7 to describe the electronic device 700 according to this embodiment of the present application. Figure 7 The electronic device 700 shown is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present application.

[0099] As Figure 7 shown, the electronic device 700 is presented in the form of a general-purpose computing device. The components of the electronic device 700 may include, but are not limited to: at least one processing unit 710, at least one storage unit 720, a bus 730 connecting different system components (including the storage unit 720 and the processing unit 710), a display unit 740, etc.

[0100] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 710, so that the processing unit 710 executes the steps according to various exemplary embodiments of the present application described in this specification. For example, the processing unit 710 can execute as Figure 2 , Figure 3 , Figure 4 shown in the steps.

[0101] The storage unit 720 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 7201 and / or a cache storage unit 7202, and may further include a read-only storage unit (ROM) 7203.

[0102] The storage unit 720 may further include a program / utility 7204 having a set (at least one) of program modules 7205. Such program modules 7205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0103] The bus 730 may represent one or more of several types of bus structures, including a storage unit bus or a storage unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any bus structure in a variety of bus structures.

[0104] The electronic device 700 can also communicate with one or more external devices 700' (such as a keyboard, a pointing device, a Bluetooth device, etc.), enabling communication with devices that allow a user to interact with the electronic device 700, and / or communication with any device (such as a router, a modem, etc.) through which the electronic device 700 can communicate with one or more other computing devices. Such communication can be carried out through the input / output (I / O) interface 750. Moreover, the electronic device 700 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 760. The network adapter 760 can communicate with other modules of the electronic device 700 through the bus 730. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the electronic device 700, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0105] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented through software, or can be implemented through a combination of software and necessary hardware. Therefore, as Figure 8 shown, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, or a network device, etc.) to execute the above method according to the embodiments of the present application.

[0106] The software product can adopt any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can, for example, but not be limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0107] The computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable storage medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0108] The program code for performing the operations of this application may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as a stand-alone software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0109] The above computer-readable medium carries one or more programs, and when the one or more programs are executed by a device, the computer-readable medium realizes the following functions: the switch obtains a configuration information file from the management platform, and the configuration information file contains static access binding information of the terminal device; the switch distributes the configuration information file to the device kernel; generates an access control rule based on the terminal access information in the configuration information file; the switch receives access traffic; the switch performs network access judgment on the access traffic according to the access control rule.

[0110] Those skilled in the art can understand that the above-mentioned modules can be distributed in the device according to the description of the embodiments, or can be correspondingly changed and distributed in one or more devices that are uniquely different from this embodiment. The modules of the above embodiments can be combined into one module, or can be further split into multiple sub-modules.

[0111] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software or in the form of software combined with necessary hardware. Therefore, the technical solution according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on the network, including several instructions to enable a computing device (such as a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.

[0112] The exemplary embodiments of the present application have been specifically illustrated and described above. It should be understood that the present application is not limited to the detailed structures, setting manners, or implementation methods described herein; on the contrary, the present application is intended to cover various modifications and equivalent settings included within the spirit and scope of the appended claims.

Claims

1. A network access method based on static access binding, characterized in that Including: The switch obtains a configuration information file from the management platform, and the configuration information file contains static access binding information of terminal devices; The switch distributes the configuration information file to the device kernel; Generate access control rules based on the terminal access information in the configuration information file; The switch receives access traffic; The switch performs network access judgment on the access traffic according to the access control rules.

2. The method according to claim 1, wherein The switch obtains a configuration information file from the management platform, including: The switch enables the static access binding function; The switch sends a binding information request message to the management platform; The management platform generates a return message according to the binding information request message; The switch obtains the configuration information file according to the return message sent by the management platform.

3. The method according to claim 2, wherein The management platform generates a return message according to the binding information request message, including: The management platform extracts switch information from the binding information request message; Generate configuration data according to the switch information; Determine the binding mode and rule information of the switch; Generate the return file through the configuration data, binding mode, and rule information.

4. The method according to claim 3, wherein Generate the return file through the configuration information, binding mode, and rule information, including: Generate a configuration information file through the configuration data, binding mode, and rule information; Host the configuration information file in the page URL; Generate the return file through the page URL.

5. The method according to claim 2, wherein The switch obtains the configuration information file according to the return message sent by the management platform, including: The switch parses the page URL from the return message sent by the management platform; Obtain the configuration information file from the page URL through the wget command.

6. The method according to claim 1, characterized in that The switch distributes the configuration information file to the device kernel, including: The switch parses the configuration information file through a user-mode process and distributes it to the device kernel.

7. The method according to claim 1, characterized in that, Generate access control rules based on the terminal access information in the configuration information file, including: Generate an ARP user binding whitelist pass-through access control rule based on the terminal access information in the configuration information file; and / or Generate an ARP full packet drop access control rule based on the terminal access information in the configuration information file; and / or Generate an IPv4 user binding whitelist pass-through access control rule based on the terminal access information in the configuration information file; and / or Generate an IPv4 full packet drop access control rule based on the terminal access information in the configuration information file.

8. The method according to claim 1, wherein Also including: During the system restart process of the switch, retain the configuration information file; During the system initialization stage of the switch, before the port forwarding function is enabled, distribute the configuration information file to the kernel to generate access control rules; After the access control rules are generated, enable the traffic forwarding function.

9. The method according to claim 1, characterized in that, Including: The management platform generates updated configuration information; The management platform sends the updated configuration file to the switch through the uplink port; The switch regenerates and updates the access control rules based on the updated configuration file.

10. A network access device based on static access binding, characterized in that, Including: An information module for the switch to obtain a configuration information file from the management platform, and the configuration information file contains static access binding information of terminal devices; A distribution module, which is used for the switch to distribute the configuration information file to the device kernel; A rule module, which is used to generate access control rules based on the terminal access information in the configuration information file; A traffic module, which is used for the switch to receive access traffic; A judgment module, which is used for the switch to perform network access judgment on the access traffic according to the access control rules.