Security authentication and control method, system, device and equipment
By adjusting the device verification, user identity verification and dynamic accessibility range of nuclear power network terminals, combined with hardware encryption modules and link encryption gateways, the security risks of nuclear power network security systems under multi-terminal access are solved, and high security authentication and control of terminal devices and networks are achieved.
Patent Information
- Application Number
- CN202510665680.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2025-08-26
AI Technical Summary
When existing nuclear power network security systems face a large number of terminal access, single identity authentication information or certificates are easily cracked, resulting in increased security risks and it is difficult to ensure the security of terminal equipment and networks.
By performing device verification and user authentication on the target terminal, the access scope is dynamically adjusted, and access authorization is performed after passing environmental security checks, and terminal security authentication and control are performed in combination with hardware encryption modules and link encryption gateways.
It improves the security of network systems and terminal devices, reduces the certainty of the accessibility range of attackers, promptly detects and prevents dangerous terminals, and reduces the risk of network attacks.
Smart Images

Figure CN120547573A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network technology, and in particular to a security authentication and control method, system, device and equipment. Background Art
[0002] Currently, an increasing number of nuclear power plants are building 5G private networks and the Internet of Things (IoT) to improve production efficiency in the nuclear power sector. To promote the intelligent integration of production and management, support mobile office and digital management, and meet the unique communication requirements of nuclear power plants, such as interference resistance and radiation tolerance, it is essential to connect 5G private networks, the IoT, and office intranets. However, more network access also means more types and numbers of terminals. Existing network security systems require terminals to authenticate their users or verify their certificates before they can access the network.
[0003] However, a single authentication information or certificate may be obtained or cracked by others, which poses a certain security risk. As the number of access terminals increases, the security risk will also increase. Therefore, the existing verification method of the nuclear power network security system is difficult to ensure the security of terminal devices and networks. Summary of the Invention
[0004] To solve the problems in the prior art methods, embodiments of the present invention provide a security authentication and control method, system, device and equipment.
[0005] In a first aspect, an embodiment of the present invention provides a security authentication and management method, including:
[0006] Perform device verification and user authentication on the target terminal to confirm the device type and user identity;
[0007] Determining the accessible range of the target terminal according to the device type and the user identity;
[0008] Wherein, the accessible range is dynamically adjusted;
[0009] Sending a security detection client installation instruction to the target terminal, and performing an environmental security check on the target terminal based on the security detection client;
[0010] When the target terminal passes the environmental security check, access authorization is performed on the target terminal based on the accessible range.
[0011] In the second aspect, an embodiment of the present invention provides a security authentication and control system for implementing the security authentication and control method described in the first aspect, including an access device, a terminal device and a link encryption gateway. The access device is used to perform security authentication on the terminal device and control the network encryption module welded in the hardware circuit of the terminal device, and the link encryption gateway is connected in series in the link layer of the network.
[0012] In a third aspect, an embodiment of the present invention provides an authentication control device for implementing the security authentication and control method described in the first aspect, including:
[0013] Identity authentication module, used to perform device verification and user authentication on the target terminal to confirm the device type and user identity;
[0014] An access range confirmation module, configured to confirm the accessible range of the target terminal based on the device type and the user identity;
[0015] An environment detection module, configured to send a security detection client installation instruction to the target terminal and perform an environment security check on the target terminal based on the security detection client;
[0016] An authorization module is used to authorize access to the target terminal based on the accessible range after the target terminal passes the environmental security check.
[0017] In a fourth aspect, an embodiment of the present invention provides a computer device, comprising a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;
[0018] Memory for storing computer programs;
[0019] The processor is used to implement the steps of the security authentication and control method described in the first aspect when executing the program stored in the memory.
[0020] The embodiment of the present invention provides a security authentication and control method, system, device and equipment, the method comprising: performing device verification and user identity authentication on a target terminal to confirm the device type and user identity; confirming the accessible range of the target terminal based on the device type and the user identity; wherein the accessible range is dynamically adjusted; sending a security detection client installation instruction to the target terminal, performing an environmental security check on the target terminal based on the security detection client; when the target terminal passes the environmental security check, granting access to the target terminal based on the accessible range. Performing device verification and user identity authentication on the target terminal to confirm the device type and user identity, dynamically adjusting the accessible range to achieve dynamic authorization of the target terminal makes it difficult for attackers to confirm the accessible range, thereby promptly discovering dangerous terminals, and after confirming the device type and user identity, forcibly installing the client on the terminal device to perform an environmental check, thereby reducing the risk of the target terminal being attacked, thereby solving the problem of the existing verification method of the nuclear power network security system being difficult to ensure the security of the terminal device and network with a rich authentication and control method. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0022] Figure 1 A flowchart of a security authentication and control method provided by an embodiment of the present invention;
[0023] Figure 2 A sub-flowchart of the security authentication and control method provided in an embodiment of the present invention;
[0024] Figure 3 A sub-flowchart of the security authentication and control method provided in an embodiment of the present invention;
[0025] Figure 4 A sub-flowchart of the security authentication and control method provided in an embodiment of the present invention;
[0026] Figure 5 A sub-flowchart of the security authentication and control method provided in an embodiment of the present invention;
[0027] Figure 6 A sub-flowchart of the security authentication and control method provided in an embodiment of the present invention;
[0028] Figure 7A schematic block diagram of a hardware circuit board before and after a network encryption module is installed in a terminal device in a security authentication and control system provided by an embodiment of the present invention;
[0029] Figure 8 A schematic block diagram of an authentication control device provided in an embodiment of the present invention;
[0030] Figure 9 A schematic block diagram of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0031] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0032] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0033] It should also be understood that the terms used in the present specification are only for the purpose of describing particular embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0034] It should be further understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0035] It should also be noted that, unless otherwise clearly specified and limited, terms such as "installed", "connected", "connected", "fixed", and "set" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integrated connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the internal connection of two elements or the interaction relationship between two elements. When an element is referred to as being "on" or "under" another element, the element can be "directly" or "indirectly" located on the other element, or there may be one or more intervening elements. The terms "first", "second", "third", etc. are only for the convenience of describing the present technical solution, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first", "second", "third", etc. may explicitly or implicitly include one or more of such features. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to the specific circumstances.
[0036] See also Figure 1 An embodiment of the present invention provides a security authentication and control method, which is used to authenticate and control terminal devices accessing a network to ensure the secure operation of the network and the data security of various systems within the network. The method can be applied to the access device or access system of the network. The network can specifically be the office intranet or 5G private network of a nuclear power plant, and the terminal devices can be personal computers, mobile phones, servers, and Internet of Things devices.
[0037] In some embodiments, the security authentication and management method includes steps S10 to S40.
[0038] S10. Perform device verification and user authentication on the target terminal to confirm the device type and user identity.
[0039] In this embodiment, if a terminal device wants to access the network, access systems within the network, and interact with data, it must first undergo security authentication by the access device. This security authentication process includes device verification and user identity verification to confirm the device type of the terminal device and the identity of the user using the terminal device. Device types may include personal computers, mobile phones, servers, and IoT devices. PC types may include desktop computers, laptops, and tablets. IoT device types may include safety-critical equipment, radiation and environmental monitoring equipment, process control automation equipment, equipment health management equipment, personnel and material management equipment, emergency response equipment, and energy management equipment. Server types may include production data center servers and office intranet system servers. The user's identity may include their personal identity information and role information, which may include administrator, operator, maintenance personnel, and visitor. Administrators may include production system administrators and office system administrators.
[0040] The access device can provide multiple authentication methods such as AD authentication, LDAP authentication, CA authentication, and Email authentication. Different specific authentication methods can be selected according to different network and terminal device types to verify the user's identity.
[0041] It should be understood that when verifying the device type of a terminal, the device type may include not only the type of the device itself but also the manufacturer identity of the device.
[0042] See also Figure 2 In a further embodiment, the device verification and user identity verification of the target terminal to confirm the device type and user identity may specifically include steps S101 to S104.
[0043] S101: If a network access request is received from a terminal, the terminal is taken as a target terminal, and a feature fingerprint of a request message of the target terminal is collected.
[0044] In this embodiment, any terminal needs to send an access request message to the access device when it needs to access the network. At this time, the access device identifies the type of the terminal by passively receiving information.
[0045] S102: Confirm the device type of the target terminal through the feature fingerprint and a pre-stored recognition rule library.
[0046] In this embodiment, the identification rule base can be based on a variety of identification methods, such as MAC OUI, HTTP UserAgent, DHCP Option, and mDNS. For example, the first three bytes of the MAC address (MAC OUI) can be used to identify the manufacturer of the terminal. Another example is analyzing the User-Agent field in the HTTP message to identify the terminal type. In this way, this embodiment can identify the device type of the terminal using a variety of identification methods.
[0047] S103: Send a user identity authentication request to the target terminal.
[0048] S104: Confirm the user's identity based on the authentication information input by the user in response to the identity authentication request.
[0049] In this embodiment, after verifying the terminal's device type, a user identity authentication request can be sent to the terminal through various methods, such as AD authentication, LDAP authentication, CA authentication, and email authentication. During this authentication process, both the user's personal identity information and role information can be confirmed. Personal identity information includes their name and age, while role information includes their position and rank within the nuclear power plant system, including visitors outside the nuclear power plant system.
[0050] See also Figure 3 In a further embodiment, the device verification and user identity verification of the target terminal to confirm the device type and user identity may further include steps S105 to S107.
[0051] S105, actively scan the terminal devices within the network coverage; S106, take the scanned terminal device as the target terminal, and send an identification request to the target terminal; S107, confirm the device type of the target terminal based on the feedback information of the target terminal and the pre-stored identification rule library.
[0052] In this embodiment, the access device actively detects and scans terminal devices within the network coverage area to discover and identify them. For example, through SNMP scanning or general scanning, all scanned terminal devices are considered target terminals. Identification requests are actively sent to the terminal devices, and the device type is determined based on the feedback information from the target terminals and a pre-stored identification rule library. It is understood that after actively scanning a terminal device, a user authentication request may also be actively sent to the terminal device to verify the identity of the user.
[0053] It should be noted that, in this embodiment, step S105 is not executed after S104, but is executed synchronously, that is, in this embodiment, the terminal is discovered and identified by means of passive collection and active scanning to assist each other, thereby ensuring that all terminal devices within the network coverage area can achieve the goal of not being able to enter the network if they violate the regulations, and must comply with the regulations when entering the network, avoiding missing terminals due to a single verification method, thereby ensuring the security of the terminal devices and the network.
[0054] S20. Determine an accessible range of the target terminal according to the device type and the user identity; wherein the accessible range is dynamically adjusted.
[0055] In this embodiment, after the target terminal is verified for device type and user identity, the target terminal's accessible range within the network is confirmed based on the device type and user identity, and the accessible range is dynamically adjusted, thereby further improving the security of network system and terminal device management and control. It can be understood that even if an attacker passes device verification and user authentication by some means or by luck, for example, if he steals the identity information and terminal device of a nuclear power plant staff member and wants to obtain certain data or information within the network through the terminal device, because the accessible range changes dynamically, the attacker cannot accurately obtain the accessible range, and it will be easy to trigger operations outside of the authorized permissions during the access process. Therefore, in the subsequent steps, the attacker's dangerous behavior can be detected and the network connection can be disconnected in time. Nuclear power plant staff can understand the dynamic change strategy of the accessible range through offline training and other methods to prevent them from triggering operations outside of their authorized permissions.
[0056] See also Figure 4 In a further embodiment, the accessible range of the target terminal is confirmed according to the device type and the user identity, including sub-steps S201 to S202.
[0057] S201: Traverse a pre-stored mapping matrix of the device type, the user identity, and the accessible range to obtain a preliminary accessible range of the target terminal.
[0058] The accessible scope includes accessible systems, permitted operations, and prohibited operations.
[0059] In this embodiment, the mapping matrix is pre-stored in the access device. Once the access device confirms the device type and user identity of the target terminal, the device type and user identity can be entered into the mapping matrix to obtain a preliminary accessible range. The "unauthorized operations" in the above embodiment can be understood as: accessing a system other than the accessible system, performing an operation other than a permitted operation, or performing an operation other than a prohibited operation.
[0060] For example, the mapping matrix can refer to Table 1:
[0061] Table 1:
[0062] Device Type User ID Allow Operation Prohibited Operations Safety-critical equipment Super Administrator Parameter modification *** Safety-critical equipment Operator Condition Monitoring Parameter modification, firmware update Data-sensitive devices Maintenance personnel Data Export Delete original data …… …… …… …… Third-party devices Visitors Read-only access Write, delete, copy
[0063] S202: Dynamically adjust the preliminary accessible range according to current time information to obtain the accessible range of the target terminal.
[0064] In this embodiment, a method for dynamically adjusting the preliminary accessible range according to the current time is provided.
[0065] For example, if the current time is 8:00-19:00, the super administrator is allowed to modify 80% of the parameters through the safety-critical device. If the current time is 19:01-00:00, the super administrator is allowed to modify 50% of the parameters through the safety-critical device. If the current time is 00:01-07:59, the super administrator is allowed to modify 10% of the parameters through the safety-critical device.
[0066] S30: Send a security detection client installation instruction to the target terminal, and perform an environmental security check on the target terminal based on the security detection client.
[0067] In this embodiment, after the device type of the terminal is identified, a security detection client installation instruction can be sent to the terminal with an interactive interface. After the target terminal receives the installation instruction, its interactive interface will automatically jump to the security detection client installation page. The security detection client can provide the target terminal with more than 50 integrity checks on system configuration security, status security, and operation security, and detect the terminal environment to detect whether it has installed viruses or whether there is a risk of being attacked by viruses. At the same time, it solves the problem that the terminal security baseline configuration is low and may be attacked by malicious intrusions or viruses; thereby avoiding the terminal device itself from being attacked, or avoiding the terminal from being remotely controlled by the attacker through viruses after the device type and user identity are determined, and attacking various systems in the network, stealing, deleting data, etc.
[0068] S40: When the target terminal passes the environmental security check, access authorization is performed on the target terminal based on the accessible range.
[0069] In this embodiment, access authorization is performed on the target terminal based on the accessible scope, that is, the target terminal is granted access rights to the network based on the accessible scope. However, the specific content of the access rights is not sent to the target terminal in the form of text information, etc., that is, when the target terminal performs access behavior, the traffic of the target terminal is tracked, diverted or intercepted based on the accessible scope to prevent attackers from obtaining the accessible scope corresponding to the access rights when stealing or controlling the terminal device.
[0070] In a further embodiment, after the target terminal passes the environmental security check and access is authorized to the target terminal based on the accessible range, steps S50 to S60 are included.
[0071] S50. Track the traffic data of the target terminal in the network, obtain the number of times the target terminal attempts to perform operations outside the accessible range, and obtain the target limit-exceeding attempt number; S60. Dynamically determine the danger level of the target terminal based on the target limit-exceeding attempt number and the safety attempt number.
[0072] The number of security attempts is changed dynamically.
[0073] In this embodiment, the consideration is that when an attacker performs a dangerous operation, if they have passed device verification and user identity authentication, such as by stealing and remotely controlling an already verified terminal, and have also passed the environmental detection of the security detection client in some way, because the access range is not sent to the target terminal in text information and the access range is dynamically adjusted, the attacker cannot accurately obtain the target terminal's access range. Therefore, whether access is performed manually or through a script program, the attacker will inevitably attempt to perform operations outside the access range, such as attempting to access systems outside the access range or delete or modify data outside the access range. When the number of target over-limit attempts reaches a certain danger level, the target terminal is disconnected from the network. The danger level is converted from the target over-limit attempt number and the number of security attempts using a certain formula. The number of security attempts changes dynamically. Even if the attacker accidentally obtains a certain value for the number of security attempts, he or she cannot accurately attempt to access the target terminal within the limit. This can further reduce the risk of attack on the terminal and the system within the network.
[0074] See also Figure 5 In a further embodiment, the dynamic determination of the danger level of the target terminal based on the target over-limit attempt number and the safety attempt number includes sub-steps S601 to S604.
[0075] S601. Acquire multiple terminals in the network that have the same access permission level as the target terminal as reference terminals; S602. Acquire the number of times each of the reference terminals attempts to perform operations outside the accessible range during the same period to obtain multiple reference over-limit attempt numbers; S603. Convert the multiple reference over-limit attempt numbers as the safety attempt numbers; S604. Calculate the ratio of the target over-limit attempt number to the safety attempt number to obtain the danger level of the target terminal.
[0076] In this embodiment, a method for dynamically changing the number of security attempts is provided. Since in the present invention, the staff of the nuclear power plant obtains the accessible range of the terminal through offline training, and the accessible range is also dynamically adjusted, under certain circumstances, individual staff of the nuclear power plant may also attempt to perform operations outside the accessible range during a certain period. Therefore, when a terminal with a certain access right level, i.e., a target terminal, is accessing, multiple terminals with the same access right level are obtained as reference terminals, and the number of times each reference terminal attempts to perform operations outside the accessible range during the same period is obtained to obtain multiple reference over-limit attempts. For example, there are a total of N reference terminals. Within one hour, the over-limit attempts of the N reference terminals are T1, T2...T respectively. N , then the number of reference over-limit attempts are T1, T2...T N , where T1, T2, ..., T N is an integer greater than or equal to 0, and T1, T2, ... N After a certain formula, it is converted into the number of safe attempts T 安 , calculate the number of target overrun attempts T 目 With T 安 The ratio of the target terminal to the danger level D is obtained. 危 , that is, D 危 =T 目 / T 安 Understandably, due to T 安 In dynamic changes, so D 危 The number of attempts to access the network is also changing dynamically, making it difficult for attackers to determine whether their operations will reach a dangerous level. This is especially true since attackers often use scripts to conduct attacks, and their access times can be very high within a certain period of time. Therefore, their excessive attempts can easily reach a dangerous level. This method can quickly detect dangerous operations performed by terminals that have undergone device and user authentication, thereby initiating appropriate security measures, such as immediately disconnecting the target terminal from the network.
[0077] Specifically, the hazard level D 危 Set the gradient, for example, set D1 = 100%, D2 = 150%, when D 危 When it is greater than or equal to D1 and less than D2, then strengthen D 危 The corresponding target terminal is continuously monitored to detect whether it has any unexpected dangerous behavior that exceeds the limit. If it has any unexpected dangerous behavior that exceeds the limit, its connection with the network will be immediately disconnected. If it has no unexpected dangerous behavior that exceeds the limit, it will be continuously monitored. 危 If it is greater than D2, it will be disconnected from the network immediately.
[0078] See also Figure 6In a further embodiment, the multiple reference over-limit attempts are converted into the safety attempts, including sub-steps S6031 to S6032.
[0079] S6031. Obtain a plurality of reference over-limit attempt times; S6032. Calculate an average value of a plurality of target over-limit attempt times, and use the average value as the safety attempt time.
[0080] In this embodiment, Among them, T 安 is the number of security attempts, k is the reference terminal number, T k is the number of overrun attempts for any reference, and N is the number of reference terminals.
[0081] An embodiment of the present invention also provides a security authentication and control system for implementing the security authentication and control method described in the above embodiment, including an access device, a terminal device and a link encryption gateway. The access device is used to perform security authentication on the terminal device and control the network encryption module welded in the hardware circuit of the terminal device, and the link encryption gateway is connected in series in the link layer of the network.
[0082] In this embodiment, the security authentication and control method can be applied to the access device. Figure 7 , Figure 7 A schematic block diagram of the hardware circuit board before and after the network encryption module is set for the terminal device in the security authentication control system provided in the embodiment of the present invention. The network encryption module is a highly integrated hardware module, which contains an MCU, a security chip, a PHY network chip, and a tailored micro operating system and network encryption service firmware (supporting the national secret SSL protocol and the national secret IPSec protocol, etc.). The network encryption module can be easily welded and integrated into the motherboard, network card, and bottom board of various terminal devices such as various Internet of Things devices, edge computing devices or other computer devices. It only needs to be simply connected in series to the original network transmission line to quickly realize the encrypted transmission of device network data (need to be used together with the encryption gateway of the data center / server side). The network encryption module also has the characteristics of small size and low power consumption.
[0083] The network encryption module supports the national encryption standard SM2 / SM3 / SM4 algorithms; supports the national encryption standard IPSec protocol to achieve encrypted tunnel communication, with network encryption throughput reaching 50Mbps; supports both quantum key and classical key sources; supports calling the built-in cryptographic chip; supports offline injection and online interaction of quantum keys; supports the construction of classical or quantum encryption tunnels between the encryption module and the central-side encryption gateway; supports national encryption standards: complies with GM / T 0022-2014 IPSec VPN technical specifications and GM / T 0024-2014 SSLVPN technical specifications; the link encryption gateway supports multiple modes such as routing and bridging.
[0084] The Link Encryption Gateway is a transparent encryption device that operates at the network link layer, providing real-time and reliable encryption of data packets. It encrypts all application packets passing through the device and supports packet protocol analysis and filtering. The device is extremely simple to deploy and can be directly connected to the network, eliminating the need to assign an IP address or configure routing information for the Link Encryption Gateway. Instead of using traditional computer architecture, operating systems, or standard file systems, the Link Encryption Gateway integrates the network port with a dedicated SoC cryptographic chip directly within the hardware circuitry. This allows network packets to be immediately transmitted to the cryptographic chip for encryption after being received by the network port.
[0085] This network encryption module is designed to be integrated into the existing hardware circuitry of terminal devices, automatically implementing link encryption. It collaborates with the link encryption gateway to achieve automatic encrypted transmission of data between the terminal device and the detection platform, improving the confidentiality and integrity of data transmission. It also verifies the trusted identity of the terminal device at the hardware level, ensuring secure access to the terminal device. This, combined with the security authentication and control methods provided in the aforementioned embodiments, collaborates from both the virtual network and physical hardware perspectives to ensure secure access to the terminal device and network, as well as secure data transmission. This significantly reduces security risks compared to existing nuclear power network security systems.
[0086] See also Figure 8 The embodiment of the present invention further provides an authentication control device for implementing the security authentication and control method described in the above embodiment. The authentication control device includes:
[0087] The identity authentication module 1 is used to perform device authentication and user identity authentication on the target terminal to confirm the device type and user identity.
[0088] The access range confirmation module 2 is used to confirm the accessible range of the target terminal according to the device type and the user identity; wherein the accessible range is dynamically adjusted.
[0089] The environment detection module 3 is used to send a security detection client installation instruction to the target terminal and perform an environment security check on the target terminal based on the security detection client.
[0090] The authorization module 4 is configured to authorize access to the target terminal based on the accessible range after the target terminal passes the environmental security check.
[0091] See also Figure 8 In a further embodiment, the authentication control device further includes:
[0092] The tracking module 5 is used to track the traffic data of the target terminal in the network, obtain the number of times the target terminal attempts to perform operations outside the accessible range, and obtain the target over-limit attempt number.
[0093] The dynamic judgment module 6 is used to dynamically judge the danger level of the target terminal based on the target over-limit attempt number and the safety attempt number; wherein the safety attempt number is dynamically changed.
[0094] The above authentication control device can be implemented in the form of a computer program. The computer program can be used in Figure 9 Runs on the computer equipment shown.
[0095] See also Figure 9 , Figure 9 It is a schematic block diagram of a computer device provided by an embodiment of the present invention.
[0096] See Figure 9 The computer device 500 includes a processor 502 , a memory, and a network interface 505 connected via a communication bus 501 , wherein the memory may include a storage medium 503 and an internal memory 504 .
[0097] The storage medium 503 may store an operating system 5031 and a computer program 5032. When the computer program 5032 is executed, the processor 502 may execute a security authentication and control method. The storage medium 503 may be a volatile storage medium or a non-volatile storage medium.
[0098] The processor 502 is used to provide computing and control capabilities to support the operation of the entire computer device 500.
[0099] The internal memory 504 provides an environment for the operation of the computer program 5032 in the storage medium 503. When the computer program 5032 is executed by the processor 502, the processor 502 can execute the security authentication and control method.
[0100] The network interface 505 is used for network communication, such as providing data information transmission. Those skilled in the art will understand that Figure 9 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution of the present invention and does not constitute a limitation on the computer device 500 to which the solution of the present invention is applied. The specific computer device 500 may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0101] The processor 502 is configured to execute a computer program 5032 stored in the memory to implement corresponding functions in the above-mentioned security authentication and control method.
[0102] Those skilled in the art will understand that Figure 9 The embodiment of the computer device shown in the figure does not constitute a limitation on the specific composition of the computer device. In other embodiments, the computer device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently. For example, in some embodiments, the computer device may only include a memory and a processor. In such an embodiment, the structure and function of the memory and processor are the same as those in the figure. Figure 9 The embodiments shown are consistent and will not be described again here.
[0103] It should be understood that in the embodiment of the present invention, the processor 502 may be a central processing unit (CPU), and the processor 502 may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0104] In another embodiment of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium may be volatile or non-volatile. The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps included in the above-described security authentication and control method.
[0105] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described equipment, devices and units can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented with electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0106] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, or units with the same function may be combined into one unit. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interfaces, devices or units, or may be an electrical, mechanical or other form of connection.
[0107] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the objectives of the embodiments of the present invention.
[0108] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0109] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a computer-readable storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned computer-readable storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a magnetic disk, or an optical disk.
[0110] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and such modifications or substitutions are intended to be within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.
Claims
1. A security authentication and control method, characterized in that: include: S10, performing device verification and user authentication on the target terminal to confirm the device type and user identity; S20. Determine the accessible range of the target terminal based on the device type and the user identity; Wherein, the accessible range is dynamically adjusted; S30, sending a security detection client installation instruction to the target terminal, and performing an environmental security check on the target terminal based on the security detection client; S40: When the target terminal passes the environmental security check, access authorization is performed on the target terminal based on the accessible range.
2. The security authentication and control method according to claim 1, characterized in that: After the target terminal passes the environmental security check and access is authorized to the target terminal based on the accessible range, the method includes: S50: Track traffic data of the target terminal in the network, obtain the number of times the target terminal attempts to perform operations outside the accessible range, and obtain the target limit-exceeded attempt count; S60: Dynamically determine the danger level of the target terminal based on the target limit-exceeding attempt number and the safety attempt number; The number of security attempts is changed dynamically.
3. The security authentication and control method according to claim 2, characterized in that: The dynamically determining the danger level of the target terminal based on the target limit exceeding attempt number and the safety attempt number includes: S601: Acquire multiple terminals in the network that have the same access authority level as the target terminal as reference terminals; S602: Obtain the number of times each reference terminal attempts to perform operations outside the accessible range during the same period, and obtain multiple reference limit-exceeded attempt numbers; S603: Convert the multiple reference over-limit attempt times into the safety attempt times; S604: Calculate the ratio of the target limit-exceeding attempt number to the safety attempt number to obtain the danger level of the target terminal.
4. The security authentication and control method according to claim 3, characterized in that: Converting the plurality of reference over-limit attempts into the safety attempts includes: S6031, obtaining a plurality of reference limit-exceeding attempts, S6032. Calculate an average of multiple target limit exceeding attempts, and use the average as the safety attempt number.
5. The security authentication and control method according to claim 1, characterized in that: The device verification and user identity verification of the target terminal to confirm the device type and user identity includes: S101: If a network access request is received from a terminal, the terminal is regarded as a target terminal, and a characteristic fingerprint of the request message of the target terminal is collected; S102: Confirm the device type of the target terminal by using the feature fingerprint and a pre-stored recognition rule library; S103, sending a user identity authentication request to the target terminal; S104: Confirm the user's identity based on the authentication information input by the user in response to the identity authentication request.
6. The security authentication and control method according to claim 5, characterized in that: The device verification and user identity verification of the target terminal to confirm the device type and user identity also include: S105, actively scanning terminal devices within the network coverage area; S106: Use the scanned terminal device as a target terminal and send an identification request to the target terminal; S107: Confirm the device type of the target terminal according to the feedback information of the target terminal and a pre-stored identification rule library.
7. The security authentication and control method according to claim 1, characterized in that: Determining the accessible range of the target terminal according to the device type and the user identity includes: S201, traverse the pre-stored mapping matrix of the device type, the user identity and the accessible range to obtain a preliminary accessible range of the target terminal; The accessible scope includes accessible systems, permitted operations, and prohibited operations; S202: Dynamically adjust the preliminary accessible range according to current time information to obtain the accessible range of the target terminal.
8. A security authentication and control system for implementing the security authentication and control method according to any one of claims 1 to 7, characterized in that: It includes an access device, a terminal device and a link encryption gateway. The access device is used to perform security authentication on the terminal device and control the welding network encryption module in the hardware circuit of the terminal device. The link encryption gateway is serially connected in the link layer of the network.
9. An authentication and control device for implementing the security authentication and control method according to any one of claims 1 to 7, characterized in that: include: Identity authentication module, used to perform device verification and user authentication on the target terminal to confirm the device type and user identity; An access range confirmation module, configured to confirm the accessible range of the target terminal based on the device type and the user identity; An environment detection module, configured to send a security detection client installation instruction to the target terminal and perform an environment security check on the target terminal based on the security detection client; An authorization module is used to authorize access to the target terminal based on the accessible range after the target terminal passes the environmental security check.
10. A computer device, characterized in that: The device includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; Memory for storing computer programs; A processor is configured to implement the steps of the security authentication and control method according to any one of claims 1 to 7 when executing a program stored in a memory.