Intranet application access method and device based on connector

By deploying a two-way encrypted tunnel between the connector and the gateway in the enterprise intranet, the low security problem of enterprise intranet application access is solved, and safe and convenient intranet access is achieved.

CN120811641APending Publication Date: 2025-10-17BEIJING XUENUO TECH CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510910528.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

In the prior art, enterprise intranet application access has the problem of low security, which is caused by opening ports on the firewall and leads to scanning risks and inconvenience in using VPN.

Method used

Build a two-way encrypted tunnel between the connector and the gateway, obtain the browser access request, and use the gateway to determine whether the access object is an intranet business system. If so, send the request to the connector through the two-way encrypted tunnel. The connector forwards the request to the intranet business system and sends the response data packet back to the gateway through the two-way encrypted tunnel, and finally forwards it to the browser.

Benefits of technology

It achieves secure access to intranet applications, prevents scanning by scanning software such as nmap, avoids opening firewall entrances, and improves security and convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811641A_ABST
    Figure CN120811641A_ABST
Patent Text Reader

Abstract

The invention provides a connector-based intranet application access method and device, and the method comprises the steps: constructing a bidirectional encryption tunnel between a connector and a gateway, and obtaining an access request sent by a browser; judging whether an access object of the access request is an intranet service system based on a gateway; if yes, the gateway sends a request message of a browser to the connector through the bidirectional encryption tunnel; and the connector forwards the request message to the intranet service system and sends a response data packet returned by the intranet service system to the gateway through the bidirectional encryption tunnel, so that the gateway forwards the response data packet to the browser, and the response data packet is forwarded to the browser by establishing the bidirectional encryption tunnel between the gateway and the connector. Therefore, the access requests of the intranet applications are transmitted through the bidirectional encryption tunnel, and the secure access to the intranet applications is realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of network security, and particularly relates to an in-network application access method and device based on a connector. BACKGROUND

[0002] In the network environment of an enterprise, some ports need to be opened on the boundary firewall of the enterprise in-network to allow the connection and traffic initiated on the public network to enter the enterprise in-network and access the application in the enterprise in-network.

[0003] Generally, an enterprise opens the in-network business by opening the ports on the firewall to allow the request from the public network to access the in-network business. The port scanning program such as nmap can scan some information of the application in the in-network of the company, thereby implementing the intrusion operation.

[0004] Some enterprises use some in-network load balancing as a front access point and place the application behind the load balancing. The request on the public network first reaches the load balancing, and then the load balancing forwards to the in-network business.

[0005] Some enterprises with high security level requirements use vpn to solve the problem of in-network application access. The user wants to access the business system in the in-network of the company, needs to open the vpn client first and connect the vpn server of the company. After the connection is successful, the business system in the in-network of the company is accessed.

[0006] However, the above-mentioned methods have certain defects. The method of opening the entrance on the firewall cannot prevent the scanning of nmap and the like. Using the scanning software such as nmap, the information related to the business system, such as which server is used, can be scanned through the externally opened entrance on the firewall. Using the load balancing as the front access point also needs to open the entrance of the load balancing on the firewall, and cannot prevent the scanning of nmap and the like. Using vpn also has the same problem. After using vpn, the security of vpn access needs to be considered to prevent the leakage of vpn connection configuration, cause random vpn connection, and also bring inconvenience in use. SUMMARY

[0007] In order to overcome the defects of the prior art, the application provides an in-network application access method and device based on a connector to solve the problem of low security in accessing the in-network application in the prior art.

[0008] One embodiment of the application provides an in-network application access method based on a connector, comprising the following steps:

[0009] A bidirectional encryption tunnel between the connector and the gateway is constructed, and an access request sent by a browser is acquired;

[0010] determining, by the gateway, whether the access object of the access request is an intranet service system;

[0011] If yes, the gateway sends the request message of the browser to the connector through the bidirectional encryption tunnel;

[0012] The connector forwards the request message to the intranet service system, and sends the response data packet returned by the intranet service system to the gateway through the bidirectional encryption tunnel, so that the gateway forwards the response data packet to the browser.

[0013] In one of the embodiments, the bidirectional encryption tunnel between the connector and the gateway is constructed, comprising:

[0014] The gateway is arranged in a public network or a DMZ network area of an enterprise, an intranet network area is created on the gateway, and the connector is created under the intranet network area;

[0015] The bidirectional encryption tunnel based on TLS between the gateway and the connector is constructed.

[0016] In one of the embodiments, the gateway determines whether the access object of the access request is an intranet service system, comprising:

[0017] The data packet in the access request is obtained, and the data packet is parsed to obtain the request address in the data packet;

[0018] The access object is determined based on the request address, and it is determined whether the access object is the intranet service system.

[0019] In one of the embodiments, if yes, the gateway sends the request message of the browser to the connector through the bidirectional encryption tunnel, comprising:

[0020] If yes, the gateway sends a notification message to any connected connector in the intranet network area through the bidirectional encryption tunnel, and establishes a connection between the connector and the intranet service system based on the notification message;

[0021] The gateway sends the request message to the connector through the bidirectional encryption tunnel.

[0022] In one of the embodiments, the connection between the connector and the intranet service system is established based on the notification message, comprising:

[0023] The gateway sends the notification message to the connector through the bidirectional encryption tunnel;

[0024] The connector receives the notification message, and establishes a connection between the connector and the intranet service system.

[0025] After the connection between the connector and the intranet service system is completed, the connector sends a response message to the gateway through the bidirectional encryption tunnel, to prompt the gateway that the connection between the connector and the intranet service system has been established.

[0026] In one embodiment, the connector forwards the request message to the intranet service system, and sends the response data packet returned by the intranet service system to the gateway through the bidirectional encryption tunnel, so that the gateway forwards the response data packet to the browser, including:

[0027] The request message is forwarded to the intranet service system through the connector, and the intranet service system processes the request message and obtains the response data packet;

[0028] The intranet service system sends the response data packet to the connector;

[0029] The connector forwards the response data packet to the gateway through the bidirectional encryption tunnel;

[0030] The gateway sends the response data packet to the browser after receiving the response data packet, to complete the access to the intranet application.

[0031] In one embodiment, the method further includes:

[0032] If the access object of the access request is not an intranet service system, the access object is directly accessed.

[0033] One embodiment of the application further provides a gateway-based Web application proxy device, including:

[0034] A construction module is configured to construct a bidirectional encryption tunnel between a connector and a gateway, and acquire an access request sent by a browser;

[0035] A judgment module is configured to judge, based on the gateway, whether an access object of the access request is an intranet service system;

[0036] A sending module is configured to, if yes, send a request message of the browser to the connector through the bidirectional encryption tunnel;

[0037] A response module is configured to forward the request message to the intranet service system by the connector, and send the response data packet returned by the intranet service system to the gateway through the bidirectional encryption tunnel, so that the gateway forwards the response data packet to the browser.

[0038] One of the embodiments of the present application further provides a readable storage medium, the readable storage medium storing a computer program, the computer program including program instructions, the program instructions being executed by a processor of an electronic device to make the processor execute the steps of the connector-based intranet application access method.

[0039] One of the embodiments of the present application further provides an electronic device, including a processor and a memory, the memory being configured to store computer program codes, the computer program codes including computer instructions, when the processor executes the computer instructions, the electronic device executes the steps of the connector-based intranet application access method.

[0040] By applying the above technical solution, a connector-based intranet application access method is provided, including constructing a bidirectional encryption tunnel between a connector and a gateway, and obtaining an access request sent by a browser; judging whether an access object of the access request is an intranet service system based on the gateway; if yes, sending a request message of the browser to the connector through the bidirectional encryption tunnel by the gateway; forwarding the request message to the intranet service system by the connector, and sending a response data packet returned by the intranet service system to the gateway through the bidirectional encryption tunnel, so that the gateway forwards the response data packet to the browser, by establishing the bidirectional encryption tunnel between the gateway and the connector, the access request of the intranet application is transmitted through the bidirectional encryption tunnel, and the secure access of the intranet application is realized. BRIEF DESCRIPTION OF DRAWINGS

[0041] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from the structures shown in the drawings without creative labor.

[0042] Figure 1 is a flowchart of the method of the present application;

[0043] Figure 2 is a structural schematic diagram of the device of the present application;

[0044] Figure 3 is a structural schematic diagram of the electronic device of the present application. DETAILED DESCRIPTION

[0045] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative effort belong to the scope of protection of the present application.

[0046] It should be noted that if the embodiments of the present application involve directional indications (such as up, down, left, right, front, back, etc.), the directional indications are only used to explain the relative positional relationship, movement condition, etc. between components in a certain posture, and if the certain posture changes, the directional indications also change accordingly.

[0047] In addition, if the embodiments of the present application involve descriptions such as "first", "second", etc., the descriptions of "first", "second", etc. are only for description purposes, and cannot be understood as indicating or implying the relative importance of the indicated technical features or implicitly indicating the number of the indicated technical features. Therefore, the features limited by "first", "second" can explicitly or implicitly include at least one of the features. In addition, "and / or" or "and / or" appearing throughout the text means that the three parallel schemes are included, for example, "A and / or B" includes A scheme, or B scheme, or A and B simultaneously satisfy the scheme. In addition, the technical solutions of each embodiment can be combined with each other, but it must be based on the fact that a person of ordinary skill in the art can realize it, and when the combination of technical solutions appears contradictory or unachievable, it should be considered that the combination of technical solutions does not exist, and is not within the scope of protection claimed by the present application.

[0048] As Figure 1 One of the embodiments of the present application provides a connector-based intranet application access method, comprising the following steps:

[0049] S100, a bidirectional encryption tunnel between the connector and the gateway is constructed, and an access request sent by a browser is acquired.

[0050] Specifically, the intranet application accessed by the browser actually refers to that the browser accesses the domain name of the intranet application, the tunnel refers to a transmission layer connection protocol based on TCP or UDP, and the bidirectional encryption tunnel refers to a tunnel that can perform data transmission in both directions, and the connector refers to tunnel establishment software deployed in an enterprise intranet.

[0051] S200, determining whether an access object of the access request is an intranet business system based on the gateway.

[0052] Specifically, the access request sent by the browser first reaches the gateway, and it is judged by the gateway whether the access object of the access request is the intranet business system. The purpose of this step is to ensure that the access object is the intranet business system, and only when the access object is the intranet business system, the subsequent steps are executed. This is because the present application mainly solves the security problem of the browser when accessing the intranet application, so it is first ensured that the browser accesses the intranet application.

[0053] S300, if yes, the gateway sends the request message of the browser to the connector through the bidirectional encryption tunnel.

[0054] Specifically, if the access object is a bidirectional encryption tunnel, the request message is sent by the gateway to the connector through the bidirectional encryption tunnel between the gateway and the connector at this time. Therefore, the bidirectional encryption tunnel is adopted in the present application for data interaction between the gateway and the connector.

[0055] S400, the connector forwards the request message to the intranet business system, and sends the response data packet returned by the intranet business system to the gateway through the bidirectional encryption tunnel, so that the gateway forwards the response data packet to the browser.

[0056] Specifically, after the connector receives the request message, the request message is forwarded to the intranet business system, and the intranet business system sends the response data packet to the gateway through the bidirectional encryption tunnel. Further, the gateway forwards the response data packet to the browser, and at this time, one access to the intranet application is completed.

[0057] In one embodiment, the bidirectional encryption tunnel between the connector and the gateway is constructed, comprising:

[0058] The gateway is arranged in the public network or the DMZ network area of the enterprise, the intranet network area is created on the gateway, and the connector is created under the intranet network area;

[0059] The bidirectional encryption tunnel based on TLS between the gateway and the connector is constructed.

[0060] Specifically, this step is the core step and premise of the present application. In the present application, the bidirectional encryption tunnel between the connector and the gateway is constructed, and when the intranet application is accessed, the access information and the return information are transmitted through the bidirectional encryption tunnel. No entrance needs to be opened on the intranet firewall, direct access to the intranet business system is avoided, and the access security is ensured.

[0061] Specifically, first, all entrances on the firewall of the enterprise intranet are closed, and all requests from the public network are not allowed to access the intranet application.

[0062] Deploy a gateway in a public network or a DMZ network area of an enterprise, create an intranet network area on the gateway, and create a connector under the intranet network area.

[0063] Copy the installation command of the connector, deploy the connector in the intranet, and the connector will actively establish a TLS-based bidirectional encryption tunnel with the gateway after successful deployment.

[0064] Configure an application to be accessed in the extranet on the gateway, and set the network area to the intranet network area.

[0065] In one embodiment, when the target object is a Web application, the gateway determines whether the access object of the access request is an intranet business system, including:

[0066] Obtain the data packet in the access request and parse the data packet to obtain the request address in the data packet;

[0067] Determine the access object based on the request address, and determine whether the access object is the intranet business system.

[0068] Specifically, the access request carries a data packet, and the request address of the access request can be obtained by parsing the data packet. The access object of the access request can be known through the request address, and whether it is an intranet business system can be determined through the obtained access object.

[0069] In some embodiments, if yes, the gateway sends a request message of the browser to the connector through the bidirectional encryption tunnel, including:

[0070] If yes, the gateway sends a notification message to any connected connector in the intranet network area through the bidirectional encryption tunnel, and establishes a connection between the connector and the intranet business system based on the notification message;

[0071] The gateway sends the request message to the connector through the bidirectional encryption tunnel.

[0072] Specifically, if it is an intranet business system, a connected connector under the intranet network area is randomly selected. If there is only one connected connector, the connector is directly selected, and a notification message is sent to the connector through the gateway. After receiving the notification message, the connector establishes a connection with the intranet business system to perform further intranet access processes.

[0073] In some embodiments, the connection between the connector and the intranet business system is established based on the notification message, including:

[0074] The gateway sends the notification message to the connector through the bidirectional encryption tunnel.

[0075] The connector receives the notification message, and establishes a connection between the connector and the intranet service system;

[0076] After the connection between the connector and the intranet service system is established, the connector sends a response message to the gateway through the bidirectional encryption tunnel, to prompt the gateway that the connection between the connector and the intranet service system has been established.

[0077] In this embodiment, the specific process of establishing the connection between the connector and the intranet service system is as follows: first, the gateway sends a notification message to the connector, the connector receives the notification message and attempts to establish a connection with the intranet service system, and after the connection is successfully established, the connector sends a response message to the gateway. The response message is used to notify the gateway that the connection between the connector and the intranet service system has been successfully established.

[0078] In some embodiments, the connector forwards the request message to the intranet service system, and sends the response data packet returned by the intranet service system to the gateway through the bidirectional encryption tunnel, so that the gateway forwards the response data packet to the browser, including:

[0079] The request message is forwarded to the intranet service system through the connector, the intranet service system processes the request message, and obtains the response data packet;

[0080] The intranet service system sends the response data packet to the connector;

[0081] The connector forwards the response data packet to the gateway through the bidirectional encryption tunnel;

[0082] The gateway sends the response data packet to the browser after receiving the response data packet, to complete the access to the intranet application.

[0083] Specifically, after receiving the response message, the gateway sends the request message of the client to the connector through the tunnel, the connector receives the request message and sends the data packet to the intranet service system through the connection created with the intranet service system. The intranet service system receives and processes the request, and sends the response data packet to the connector. The connector sends the response data packet to the gateway through the encryption tunnel. Finally, the gateway sends the response data packet to the browser to complete the request.

[0084] In some embodiments, the method further includes:

[0085] If the access object of the access request is not the intranet service system, the access object is directly accessed.

[0086] Specifically, when the access object of the access request is not the intranet business system, the access object is directly accessed without performing subsequent steps.

[0087] The above technical solution proposes an intranet application access method and device based on a connector, which includes constructing a bidirectional encryption tunnel between a connector and a gateway and obtaining an access request sent by a browser; determining whether an access object of the access request is an intranet business system based on the gateway; if yes, sending a request message of the browser to the connector through the bidirectional encryption tunnel by the gateway; forwarding the request message to the intranet business system by the connector and sending a response data packet returned by the intranet business system to the gateway through the bidirectional encryption tunnel, so that the gateway forwards the response data packet to the browser. Through the construction of the bidirectional encryption tunnel between the gateway and the connector, the access request for the intranet application is transmitted through the bidirectional encryption tunnel, and the secure access to the intranet application is realized.

[0088] One of the embodiments of the present application further provides a gateway-based Web application proxy device, such as Figure 2 , which includes:

[0089] A construction module 100 is configured to construct a bidirectional encryption tunnel between a connector and a gateway and obtain an access request sent by a browser.

[0090] A determination module 200 is configured to determine whether an access object of the access request is an intranet business system based on the gateway.

[0091] A sending module 300 is configured to send a request message of the browser to the connector through the bidirectional encryption tunnel by the gateway if the access object is the intranet business system.

[0092] A response module 400 is configured to forward the request message to the intranet business system by the connector and send a response data packet returned by the intranet business system to the gateway through the bidirectional encryption tunnel, so that the gateway forwards the response data packet to the browser.

[0093] The present application has the following advantages:

[0094] (1) The complete closure of the enterprise intranet is realized, and the scanning of the nmap scanning software is fundamentally eliminated.

[0095] (2) The request for accessing the intranet converges to the gateway, and is then sent to the application in the intranet through the reverse encryption tunnel created by the connector. In this way, the intranet business system can be more securely accessed.

[0096] (3) The connector matches the gateway, and load balancing of the intranet service system can be realized without other load balancing.

[0097] (4) The gateway and the connector can pass through multiple regional intranets, the connector is deployed in different regional intranets, finally, access entrances of the multiple regional intranets are converged, and the security of the intranet of the enterprise is increased.

[0098] (5) The TLS bidirectional encryption tunnel is created between the connector and the gateway, and hacker behaviors such as packet capture are eliminated.

[0099] In conclusion, the connector program is deployed in the intranet of the enterprise, the encrypted reverse tunnel is established to the gateway on the public network or the gateway deployed in the DMZ network area of the enterprise intranet, the entrance on the intranet firewall is no longer opened, the data packet of the request for the intranet application can be normally sent to the application in the intranet through the encrypted tunnel of the reverse connection of the connector to the gateway, and the request for the intranet application is completed.

[0100] One of the embodiments of the present application further provides a readable storage medium, the readable storage medium stores a computer program, the computer program includes program instructions, and the program instructions make the processor execute the steps of the connector-based intranet application access method when the processor executes the computer instructions.

[0101] One of the embodiments of the present application further provides an electronic device, including a processor and a memory, the memory is used for storing computer program code, the computer program code includes computer instructions, and the electronic device executes the steps of the connector-based intranet application access method when the processor executes the computer instructions.

[0102] Please refer to Figure 3 , Figure 3 A hardware structure schematic diagram of an electronic device provided by the embodiment of the present application.

[0103] The electronic device 2 includes a processor 21, a memory 22, an input device 23 and an output device 24. The processor 21, the memory 22, the input device 23 and the output device 24 are coupled through a connector, the connector includes various interfaces, transmission lines or buses and the like, and the embodiment of the present application is not limited to this. It should be understood that in various embodiments of the present application, coupling means mutual contact in a specific way, including direct connection or indirect connection through other devices, for example, various interfaces, transmission lines, buses and the like can be connected.

[0104] The processor 21 can be one or more central processing units (CPUs). When the processor 21 is a CPU, the CPU can be a single core processor or a multi core processor. Alternatively, the processor 21 can be a processor group composed of multiple CPUs, and the multiple processors are coupled with each other through one or more buses. Alternatively, the processor can also be other types of processors, and the embodiments of the present application do not make any limitation.

[0105] The memory 22 can be used to store computer program instructions, and various computer program codes for implementing the solutions of the present application. Alternatively, the memory includes, but is not limited to, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read only memory (EPROM), or a compact disc read-only memory (CD-ROM), which is used for storing relevant instructions and data.

[0106] The input device 23 is used to input data and / or signals, and the output device 24 is used to output data and / or signals. The output device 24 and the input device 23 can be independent devices, or can be an integral device.

[0107] It can be understood that, in the embodiments of the present application, the memory 22 can be used to store not only relevant instructions, but also data stored in the memory, and the embodiments of the present application do not make any limitation on the data stored in the memory.

[0108] It can be understood that, Figure 3 Only a simplified design of an electronic device is shown. In actual applications, the electronic device can also include other necessary elements, including but not limited to any number of input / output devices, processors, memories, etc., and all video analysis devices that can implement the embodiments of the present application are within the protection scope of the present application.

[0109] Those skilled in the art can understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solutions. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0110] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiment, which will not be repeated here. Those skilled in the art can also clearly understand that each embodiment of the present application describes each with emphasis, and for the convenience and brevity of description, the same or similar parts in different embodiments can not be repeated, and therefore, the parts not described or not described in detail in an embodiment can be referred to the description of other embodiments.

[0111] In several embodiments provided by the present application, it should be understood that the disclosed system, device and method can be implemented by other ways. For example, the device embodiments described above are only schematic, and for the convenience of description, the division of the units is only a logical function division, and there can be another division way in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection between the units can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.

[0112] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0113] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically independently, or two or more units can be integrated in one unit.

[0114] In the above embodiments, all or part of the processes can be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the processes can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes described in the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in or transmitted by a computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center through a wired (such as a coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that includes one or more available media sets. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a digital versatile disc (DVD)), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0115] Those of ordinary skill in the art can understand that all or part of the processes in the above embodiments can be implemented by a computer program that can be stored in a computer-readable storage medium and can include the processes of the above embodiments when executed.

[0116] The above description is only preferred embodiments of the present application, and does not limit the patent scope of the present application. Any equivalent structural transformation made in the content of the present application, or direct / indirect application in other related technical fields, is included in the patent protection scope of the present application.

Claims

1. A connector-based intranet application access method, characterized in that: The following steps are involved: Build a two-way encrypted tunnel between the connector and the gateway, and obtain the access request sent by the browser; Determining, based on the gateway, whether the access object of the access request is an intranet business system; If so, the gateway sends the browser's request message to the connector through the bidirectional encrypted tunnel; The connector forwards the request message to the intranet business system, and sends the response data packet returned by the intranet business system to the gateway through the bidirectional encrypted tunnel, so that the gateway forwards the response data packet to the browser.

2. The connector-based intranet application access method according to claim 1, wherein: Build a bidirectional encrypted tunnel between the connector and the gateway, including: Setting up the gateway in the public network or the enterprise's DMZ network zone, creating an intranet network zone on the gateway, and creating a connector under the intranet network zone; A TLS-based bidirectional encrypted tunnel is established between the gateway and the connector.

3. The connector-based intranet application access method according to claim 2, wherein: The gateway determines whether the access object of the access request is an intranet business system, including: Obtaining a data packet in the access request, and parsing the data packet to obtain a request address in the data packet; The access object is determined based on the request address, and it is determined whether the access object is the intranet business system.

4. The connector-based intranet application access method according to claim 3, wherein: If yes, the gateway sends the browser's request message to the connector through the bidirectional encrypted tunnel, including: If so, the gateway sends a notification message to any connected connector in the intranet network area through the bidirectional encrypted tunnel, and establishes a connection between the connector and the intranet business system based on the notification message; The gateway sends the request message to the connector through the bidirectional encrypted tunnel.

5. The connector-based intranet application access method according to claim 4, wherein: Establishing a connection between the connector and the intranet business system based on the notification message includes: The gateway sends the notification message to the connector through the bidirectional encrypted tunnel; After receiving the notification message, the connector establishes a connection between the connector and the intranet business system; After completing the connection between the connector and the intranet business system, the connector sends a response message to the gateway through the bidirectional encrypted tunnel to prompt the gateway that the connection between the connector and the intranet business system has been established.

6. The connector-based intranet application access method according to claim 1, wherein: The connector forwards the request message to the intranet business system, and sends the response data packet returned by the intranet business system to the gateway through the bidirectional encrypted tunnel, so that the gateway forwards the response data packet to the browser, including: Forwarding the request message to the intranet business system through the connector, the intranet business system processes the request message and obtains the response data packet; The intranet business system sends the response data packet to the connector; The connector forwards the response data packet to the gateway through the bidirectional encrypted tunnel; After receiving the response data packet, the gateway sends the response data packet to the browser to complete the access to the intranet application.

7. The connector-based intranet application access method according to claim 1, wherein: The method further comprises: If the access object of the access request is not an intranet business system, the access object is directly accessed.

8. A gateway-based Web application proxy device, characterized in that: include: A construction module is used to build a two-way encrypted tunnel between the connector and the gateway and obtain the access request sent by the browser; A judgment module, configured to judge whether the access object of the access request is an intranet business system based on the gateway; a sending module, configured to, if yes, cause the gateway to send the browser's request message to the connector through the bidirectional encrypted tunnel; The response module is used for the connector to forward the request message to the intranet business system, and send the response data packet returned by the intranet business system to the gateway through the bidirectional encrypted tunnel, so that the gateway forwards the response data packet to the browser.

9. An electronic device comprising: A processor and a memory, characterized in that the memory is used to store computer program code, the computer program code includes computer instructions, and when the processor executes the computer instructions, the electronic device executes the steps of the connector-based intranet application access method as described in any one of claims 1-7.

10. A readable storage medium having a computer program stored therein, characterized in that: The computer program includes program instructions, and when the program instructions are executed by a processor of an electronic device, the processor is caused to execute the steps of the connector-based intranet application access method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Enterprise intranet access method based on reverse connection and application layer tunnel

    CN108600204A

  • Network access method and device

    CN113347206A

  • Access control method, device and equipment and readable storage medium

    CN113824791A

  • Data access method, data access system, computer equipment and storage medium

    CN114448700A

  • Security access control system and method

    CN114615328A