Secure networking method, system and device and storage medium
By introducing a management and control system to authenticate user terminals, a single authentication process enables mutual trust among multiple devices, resolving the issue of repeated authentication when switching user access devices and improving networking efficiency and security.
Patent Information
- Application Number
- CN202510318160.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-12-12
AI Technical Summary
In existing technologies, user terminals need to be re-authenticated when switching user access pre-devices, which leads to duplicate authentication issues, affects user experience, and poses security risks.
A management and control system is introduced to perform the first authentication process on the user terminal and generate authentication pass information to send to the user's network access front-end equipment group. This enables one-time authentication and mutual trust among multiple devices, avoiding duplicate authentication. The management and control system also uniformly configures the user's network access front-end equipment.
It improves networking efficiency, avoids duplicate authentication issues, and enhances security by preventing incorrect configurations from a single device from being synchronized to other devices through unified configuration.
Smart Images

Figure CN121125142A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network networking technology, and in particular to a secure networking method, system, device, and storage medium. Background Technology
[0002] Networking refers to network construction technologies used to enable interconnected communication and data sharing among devices. With the development of network technology, more and more devices need to connect to networks, especially for the Internet of Things (IoT). Networking provides the foundation for intelligent management of massive numbers of devices. Terminals need to be networked through Customer Premise Equipment (CPE) to connect to the network.
[0003] In existing technologies, each user's network access front-end device independently authenticates and manages the terminal. When a terminal switches user access front-end devices, re-authentication is required, leading to duplicate authentication issues that negatively impact user experience and network efficiency. Furthermore, since the user access front-end device is located on the user's side, users can configure it themselves and share it with other devices. If the user access front-end device is configured with incorrect processing rules, such as if the device is hijacked, the incorrect configuration can be synchronized to shared devices, creating a security vulnerability. Summary of the Invention
[0004] This invention provides a secure networking method, system, device, and storage medium to solve the problems of duplicate authentication and security defects caused by misconfiguration in the networking process of the prior art.
[0005] This invention provides a secure networking method for use in a management and control system, comprising: In response to a network access authentication request from a user terminal, the user terminal is subjected to a first authentication process based on the network access authentication request. Once it is determined that the user terminal is allowed to access the network, authentication pass information is generated based on the terminal identifier of the user terminal; The authentication pass information is sent to the user network access front-end equipment group corresponding to the user terminal; The network access authentication request is generated by redirection information sent from the user's network access front-end device to the user terminal; the user's network access front-end device group includes at least one user's network access front-end device, and the authentication pass information is used to instruct the user's network access front-end device group to configure the processing rules for the user terminal's network access.
[0006] According to the present invention, a secure networking method for a management and control system further includes, before responding to the network access authentication request from a user terminal: Establish a communication connection with the message server; Obtain the device identifier of the user's pre-network access device; The device identifier is processed according to a preset encryption algorithm to obtain and store the first device authentication information; The first device authentication information is provided to the message server for a second authentication process, and the message server is used to enable the authenticated user's network access front-end device to establish a management communication connection with the management and control system.
[0007] According to the present invention, a secure networking method for a control system further includes: Based on the authentication record information, the terminal identifier whose authentication has expired is identified as the first offline identifier, and the authentication record information is formed by the first authentication process; In response to operational information, determine the second offline identifier; Based on the first offline identifier or the second offline identifier, generate terminal offline information; Send the terminal offline information to the user network access front-end device group corresponding to the offline identifier; The terminal offline information is used to instruct the user network access front-end equipment group to cancel the corresponding user terminal's network access.
[0008] According to the present invention, a secure networking method for a control system further includes: Obtain the device operation information and terminal operation information uploaded by the user's network access pre-processor; Based on the device operation information, analyze the user network access front-end device to identify the user network access front-end device that is operating abnormally, and generate abnormal device information; Based on the terminal operation information, the user terminal is analyzed to identify user terminals that are malfunctioning, and abnormal terminal information is generated.
[0009] According to the present invention, a secure networking method for a management and control system is provided, which, after performing a first authentication process on the user terminal based on the network access authentication request, further includes: If it is determined that the user terminal is not allowed to access the network, an authentication error message is sent to the user terminal. After sending the authentication pass information to the user access front-end equipment group corresponding to the user terminal, the method further includes: Send test link information to the user terminal; The test link information is used to instruct the user terminal to perform a network connectivity test.
[0010] This invention also provides a secure networking method, applied to a user network access front-end device, comprising: In response to a network connection request from a user terminal, a first terminal identifier is determined based on the network connection request; Based on the local network policy, determine the first processing rule corresponding to the first terminal identifier; Once the first processing rule is determined to be a redirection rule, redirection information is returned to the user terminal. The first processing rule is determined to be a forwarding rule, and the network connection request is forwarded according to the forwarding rule; In response to the authentication pass information of the control system, the second terminal identifier and the corresponding second processing rule are determined according to the authentication pass information, and the second processing rule is added to the local network policy; The redirection information is used to instruct the client to send a network access authentication request to the management system, so that the management system can execute the aforementioned secure networking method applied to the management system.
[0011] According to the present invention, a secure networking method for a user network access front-end device is provided, which further includes, before responding to the network connection request of the user terminal: Based on the local device identifier and processed using a preset encryption algorithm, a second device authentication information is generated. The second device authentication information is sent to the message server, which then performs a second authentication process to establish a management communication connection between the local device and the control system.
[0012] According to the present invention, a secure networking method for user network access front-end equipment is provided, further comprising: In response to terminal offline information, the user terminal that needs to be offline is selected as the target terminal for offline. According to the local network policy, the third processing rule corresponding to the offline target terminal is modified into a redirection rule.
[0013] According to the present invention, a secure networking method for user network access front-end equipment is provided, further comprising: Execute periodically according to a preset cycle: Based on the operating status, generate device operating information; based on the connected user terminal, generate terminal operating information. The device operation information and the terminal operation information are uploaded to the management and control system; The device operation information is used by the management and control system to identify user network access front-end devices that are malfunctioning, and the terminal operation information is used by the management and control system to identify user terminals that are malfunctioning.
[0014] The present invention also provides a secure networking system, comprising: The control system is used to manage the networking process. At least one group of user network access front-end equipment, the user network access front-end equipment group including at least one user network access front-end device, the user network access front-end device being used to manage user terminal network access; A message server is used to enable the authenticated user's network access front-end device to establish a management communication connection with the control system; The control system executes the aforementioned secure networking method applied to the control system, and the user network access front-end device executes the aforementioned secure networking method applied to the user network access front-end device.
[0015] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement a secure networking method as described above.
[0016] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a secure networking method as described above.
[0017] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements a secure networking method as described above.
[0018] The present invention provides a secure networking method, system, device, and storage medium, which has at least the following beneficial effects: By setting up a management and control system, when a user terminal needs to connect to the network, it sends a request to the user's network access front-end device. For user terminals accessing the network for the first time, the user's network access front-end device sends redirection information, prompting the user terminal to send a network access authentication request to the management and control system. The management and control system responds to the user terminal's network access authentication request, performs a first authentication process on the user terminal, and if authentication is successful, allows the user terminal to access the network. It then generates authentication pass information and sends it to the user's corresponding user's network access front-end device group, i.e., the group to which the user terminal is connected, so that each user's network access front-end device in the same group is configured with corresponding processing rules for that user terminal. Therefore, when a user terminal switches user access front-end devices within the same user access front-end device group, there is no need for re-authentication. The switched user access front-end device will use the same processing rules as before the switch to allow the user terminal to connect to the network, realizing the function of one-time authentication and mutual trust among multiple devices. This is beneficial to improving networking efficiency and avoiding the problem of duplicate authentication. At the same time, the configuration of user access front-end devices by the management and control system can prevent the misconfiguration of a single device from being synchronized to other devices, which is beneficial to improving security and realizing secure networking. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0020] Figure 1 This is a flowchart illustrating a secure networking method for a management and control system provided by the present invention.
[0021] Figure 2 This is a flowchart illustrating a secure networking method for user network access front-end devices provided by the present invention.
[0022] Figure 3 This is an interactive schematic diagram of a secure networking method provided by the present invention.
[0023] Figure 4 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0024] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0025] The following is combined with Figure 1 and Figure 3 This invention describes a secure networking method applied to a management and control system, comprising: S100: In response to the network access authentication request from the user terminal, perform a first authentication process on the user terminal according to the network access authentication request; S110: Determine that the user terminal is allowed to access the network, and generate authentication pass information based on the terminal identifier of the user terminal; S120: Send the authentication pass information to the user network access front-end equipment group corresponding to the user terminal; The network access authentication request is generated by redirection information sent from the user's network access front-end device to the user terminal; the user's network access front-end device group includes at least one user's network access front-end device, and the authentication pass information is used to instruct the user's network access front-end device group to configure the processing rules for the user terminal's network access.
[0026] By setting up a management and control system, when a user terminal needs to connect to the network, it sends a request to the user's network access front-end device. For user terminals accessing the network for the first time, the front-end device sends a redirection message, prompting the user terminal to send a network access authentication request to the management and control system. In response to the user terminal's authentication request, the management and control system performs initial authentication processing. If authentication is successful, allowing the user terminal to access the network, it generates authentication pass information and sends it to the corresponding user's network access front-end device group—the group to which the user terminal belongs. This ensures that each user's network access front-end device within the same group is configured with the corresponding processing rules for that user terminal.
[0027] Therefore, when a user terminal switches user access front-end devices within the same user access front-end device group, there is no need for re-authentication. The switched user access front-end device will use the same processing rules as before the switch to allow the user terminal to connect to the network, realizing the function of one-time authentication and mutual trust among multiple devices. This is beneficial to improving networking efficiency and avoiding the problem of duplicate authentication. At the same time, the configuration of user access front-end devices by the management and control system can prevent the misconfiguration of a single device from being synchronized to other devices, which is beneficial to improving security and realizing secure networking.
[0028] The control system performs the first authentication process on the user terminal based on the network access authentication request. During the authentication process, the authentication method can be based on the network access authentication request, such as account password authentication, IP address authentication, MAC address authentication, SMS verification, etc. The system will then allow the user terminal to access the network if the authentication requirements are met.
[0029] The user network access front-end device can specifically be a router, optical modem, or other device that enables user terminals to connect to the network. In some embodiments of the present invention, the user network access front-end device may include a 5G chip to convert the 5G signal transmitted by the base station into a broadband or Wi-Fi signal, i.e., as a 5G CPE or other implementation.
[0030] The management and control system can determine the user's network access front-end device connected to the user terminal based on information such as the network access authentication request and the user terminal's IP address, and then determine the corresponding user network access front-end device group. In some embodiments of the present invention, the user network access front-end device group can be divided according to region, device purpose, etc., to determine the user network access front-end devices included in each group. Grouping user network access front-end devices helps to make management and control more organized, and at the same time achieves the effect of differentiated management and control.
[0031] The authentication pass information is sent to the user's network access front-end equipment group. The authentication pass information may include information such as terminal identifier and management policy. The management policy may include, for example, the management system restricts the user terminal's access from the source address, destination address, access protocol, etc., and configures the user terminal's dynamic and static network speed limits, so as to realize the management and control of the user terminal.
[0032] The authentication information causes the user's network access front-end device in the same group to configure the same processing rules for the same user terminal. The processing rules may include forwarding rules, network speed limits, access restrictions, and other rules.
[0033] With increasing demands for network control, the lack of verification processes for user access devices is failing to meet security requirements. Therefore, [reference needed]. Figure 3 In some embodiments of a secure networking method for a management and control system according to the present invention, before step S100, the method further includes: Establish a communication connection with the message server; Obtain the device identifier of the user's pre-network access device; The device identifier is processed according to a preset encryption algorithm to obtain and store the first device authentication information; The first device authentication information is used to provide the message server for second authentication processing, and the message server is used to enable the verified user's network access front-end device to establish a management communication connection with the management and control system.
[0034] After startup, the control system establishes a connection with the message server and obtains the device identifier of the registered user's network access front-end device. The device identifier is then processed by a preset encryption algorithm to form the first device authentication information and stored.
[0035] After the user's pre-connection device is started, it needs to connect to the network under the control of the management system. Therefore, a management communication connection needs to be established. The user's pre-connection device sends the second device authentication information to the message server so that the message server can perform the second authentication process. The message server obtains the list of first device authentication information from the management system and compares it with the second device authentication information. If there is first device authentication information that is the same as the second device authentication information, it means that the user's pre-connection device is a registered and legitimate device. The message server then establishes a management communication connection between the user's pre-connection device and the management system.
[0036] Therefore, user-entry pre-devices must establish a control communication connection through authentication before being allowed to access the network. This verifies the user-entry pre-devices, further enhancing access security and meeting control requirements. Simultaneously, the message server prevents unregistered user-entry pre-devices from affecting the control system, improving the reliability and stability of the control system's operation.
[0037] It is understandable that the first authentication process refers to the authentication process of the user terminal by the control system, while the second authentication process refers to the authentication process of the user's network access front-end device by the control system through the message server. The first device authentication information is generated by the control system itself, and the second device authentication information is generated by the user's network access front-end device itself. Communication between the control system and the user's network access front-end device can be achieved through the message server.
[0038] In some embodiments of the present invention, the management and control system can generate first device authentication information based on the registered user's pre-network access device list information; alternatively, the administrator can operate the management and control system to generate the first device authentication information by inputting a device identifier.
[0039] In some embodiments of the present invention, the message server can be an EMQX server. EMQX is a unified IoT messaging solution based on the MQTT (Message Queuing Telemetry Transport) open standard, enabling communication between devices. MQTT is a message protocol based on the publish / subscribe paradigm under the ISO standard, operating on the TCP / IP protocol suite. Data transmission between the user's network access front-end device and the management system can be based on the MQTTs protocol, where MQTTs is a secure transmission protocol version of MQTT.
[0040] refer to Figure 3 In some embodiments of a secure networking method for a management and control system according to the present invention, the method further includes: Based on the authentication record information, the terminal identifier whose authentication has expired is identified as the first offline identifier, and the authentication record information is formed by the first authentication process; In response to operational information, determine the second offline identifier; Based on the first offline identifier or the second offline identifier, generate terminal offline information; Send the terminal offline information to the user network access front-end device group corresponding to the offline identifier; The terminal offline information is used to instruct the user network access front-end equipment group to cancel the corresponding user terminal's network access.
[0041] After a preset period of authentication, user terminals need to be re-authenticated to ensure security. To this end, when the management system performs the initial authentication process on a user terminal, it generates a corresponding authentication record. These authentication records for each user terminal form authentication record information. Based on this information, the management system can determine the authentication time of the user terminal and, based on the duration of the authentication period, identify user terminals whose authentication has expired.
[0042] User terminals whose authentication has expired need to be re-authenticated. The terminal identifier of the expired user terminal is used as the first offline identifier. Subsequently, terminal offline information is generated based on the first offline identifier and sent to the corresponding user network access front-end equipment group. This allows the user network access front-end equipment group to cancel the network access of the expired user terminal, causing the user terminal to send a network access authentication request to the management and control system again for re-authentication.
[0043] Aside from expired authentication, administrators can take specified user terminals offline as needed. In cases such as abnormally operating user terminals, the management system responds to the administrator's operation information, determines a second offline identifier, and then generates terminal offline information to send to the corresponding user network access front-end device group, thus taking the specified user terminal offline, i.e. canceling the specified user terminal's network access.
[0044] This allows for the control of user terminals going offline, which helps improve the security and reliability of the network.
[0045] In some embodiments of the present invention, the management and control system can mark user terminals that have passed the first authentication process as online, and mark user terminals that have automatically disconnected from the network, been forcibly disconnected due to authentication expiration, or been designated to be disconnected as offline, so as to facilitate the management and control of user terminals.
[0046] In some embodiments of a secure networking method for a management and control system according to the present invention, the method further includes: Obtain the device operation information and terminal operation information uploaded by the user's network access pre-processor; Based on the device operation information, analyze the user network access front-end device to identify the user network access front-end device that is operating abnormally, and generate abnormal device information; Based on the terminal operation information, the user terminal is analyzed to identify user terminals that are malfunctioning, and abnormal terminal information is generated.
[0047] The control system acquires device operation information and terminal operation information uploaded by each user's network access front-end device. Device operation information represents the operational status of the user's network access front-end device itself, while terminal operation information represents the operational status of the user terminals connected to the user's network access front-end device. Based on the device operation information, the control system analyzes abnormal user network access front-end devices and generates abnormal device information. Similarly, based on the terminal operation information, it analyzes abnormal user terminals and generates abnormal terminal information. In this way, the control system can independently analyze and identify abnormal user network access front-end devices and user terminals, which facilitates the timely detection of potential security risks and allows for prompt responses, further enhancing network security.
[0048] In some embodiments of the present invention, identifying abnormally functioning devices or terminals can be done by analyzing and identifying CPU usage, memory usage, process startup status, and file content.
[0049] After generating abnormal device and terminal information, pre-defined anomaly handling strategies can be implemented to process abnormal user network access front-end devices and user terminals, such as forcibly disconnecting them, to avoid affecting other normally operating devices and terminals. The abnormal device and terminal information also provides administrators with the information basis for developing emergency response plans.
[0050] In some embodiments of the present invention, the control system can also automatically analyze and take offline user terminals that are malfunctioning. Specifically, this may include: determining the corresponding terminal identifier as a third offline identifier based on the abnormal terminal information; generating terminal offline information based on the third offline identifier; and sending the terminal offline information to the user network access front-end device group corresponding to the offline identifier.
[0051] In some embodiments of the present invention, the control system determines the base station identifier connected to the user terminal based on the terminal operation information, and then locates the user terminal. Accordingly, for dynamic usage scenarios such as public transportation, it can analyze whether the base station connected to the user terminal exceeds all base stations on a specified line, and thus identify abnormally operating user terminals; for static usage scenarios such as shopping malls, it can identify whether the base station connected to the user terminal has changed, and thus identify abnormally operating user terminals.
[0052] refer to Figure 3 In some embodiments of a secure networking method for a management and control system according to the present invention, after S100, the method further includes: If it is determined that the user terminal is not allowed to access the network, an authentication error message is sent to the user terminal. Following S130, the following is also included: Send test link information to the user terminal; The test link information is used to instruct the user terminal to perform a network connectivity test.
[0053] The control system performs the first authentication process on the user terminal. If the authentication fails, it sends an authentication error message to the user terminal so that the user terminal is aware of the authentication failure and can then resend the network access authentication request. This helps users to be informed of network access authentication failure in a timely manner and improves the user experience.
[0054] If the initial authentication process is successful, the control system sends authentication approval information to the corresponding user's network access pre-processing equipment group, and then sends test link information to the user terminal to allow the user terminal to perform a network connectivity test, thereby determining whether the user's network access was successful. This facilitates the determination of the user's network access status and allows for timely response in the event of network connectivity failure, i.e., network access failure.
[0055] The following describes a secure networking system for user network access front-end devices provided by the present invention. The secure networking system described below for user network access front-end devices and the secure networking method described above for management and control systems can be referred to in correspondence.
[0056] refer to Figure 2 and Figure 3 The present invention also provides a secure networking method, applied to a user network access front-end device, comprising: S201: In response to a network connection request from a user terminal, determine a first terminal identifier based on the network connection request; S210: Determine the first processing rule corresponding to the first terminal identifier according to the local network policy; S220: Determine that the first processing rule is a redirection rule, and return redirection information to the user terminal; S230: Determine that the first processing rule is a forwarding rule, and forward the network connection request according to the forwarding rule; S202: In response to the authentication pass information of the control system, determine the second terminal identifier and the corresponding second processing rule according to the authentication pass information, and add the second processing rule to the local network policy; The redirection information is used to instruct the client to send a network access authentication request to the management system, so that the management system can execute the aforementioned secure networking method applied to the management system.
[0057] On the user's network access front end, when a user terminal connects to the network, it sends a network connection request to the user's network access front end device. The user's network access front end device responds to the network connection request and determines the first terminal identifier, and obtains the corresponding first processing rule in the local network policy based on the first terminal identifier.
[0058] When the first processing rule is a redirection rule, it means that the user terminal is making its first connection or that its authentication has expired and needs to be re-authenticated. Redirection information is returned to the user terminal so that it can send an access authentication request to the management system for authentication processing. When the first processing rule is a forwarding rule, it means that the user terminal has already been authenticated by the management system. In some cases, it may be a user switching from a user access front-end device in the same group. Therefore, the network connection request of the user terminal is forwarded normally based on the forwarding rule so that the user terminal can access the target node in the network.
[0059] The user terminal authenticates with the management and control system. After successful authentication, the management and control system sends authentication success information to the user's network access front-end device. The user's network access front-end device responds to the authentication success information, determines the second terminal identifier and second processing rule of the authenticated user terminal, and adds the second processing rule to the local network policy to allow the user terminal to connect to the network.
[0060] Therefore, the user access front-end equipment, in conjunction with the management and control system, verifies user terminals, which helps to further improve access security, meet management and control requirements, and prevents misconfigurations of a single device from being synchronized to other devices, thus improving security and enabling secure networking. Furthermore, user access front-end equipment within the same group uses the same processing rules for the same user terminal, eliminating the need for re-authentication when a user terminal switches connected to a different front-end equipment. This achieves a single authentication with mutual trust among multiple devices, improving networking efficiency and avoiding duplicate authentication issues.
[0061] In some embodiments of the present invention, if the user's network access pre-processing device does not match the corresponding first processing rule in the local network policy based on the first terminal identifier, it defaults to the redirection rule, that is, the user terminal that connects for the first time needs to be redirected to the management and control system for authentication.
[0062] In some embodiments of the present invention, the user network access front-end device can be implemented by running a client agent program to achieve the above-mentioned secure networking method applied to the user network access front-end device.
[0063] In some embodiments of the present invention, the user access front-end device sends redirection information to the user terminal. During the first authentication process of the user terminal based on the redirection information to the management and control system, the user terminal can choose to perform authentication methods, such as account authentication, IP address authentication, MAC address authentication, SMS verification, etc., and send the corresponding information to the management and control system.
[0064] In some embodiments of a secure networking method of the present invention applied to a user network access front-end device, before step S201, the method further includes: Based on the local device identifier and processed using a preset encryption algorithm, a second device authentication information is generated. The second device authentication information is sent to the message server, which then performs a second authentication process to establish a management communication connection between the local device and the control system.
[0065] Before a user joins the network, the pre-connection device processes its own device identifier using a preset encryption algorithm to generate secondary device authentication information. This secondary authentication information is then sent to the message server for further authentication, completing the authentication process. Upon successful authentication, a management communication connection is established with the control system. Therefore, user pre-connection devices must be authenticated before networking, which helps to further improve access security and meet control requirements.
[0066] It is understandable that the preset encryption algorithm used by the control system for device identification is the same as the preset encryption algorithm used by the user's pre-network access device for its own device identification.
[0067] refer to Figure 3 In some embodiments of a secure networking method of the present invention applied to a user network access front-end device, the method further includes: In response to terminal offline information, the user terminal that needs to be offline is selected as the target terminal for offline. According to the local network policy, the third processing rule corresponding to the offline target terminal is modified into a redirection rule.
[0068] In response to the terminal offline information sent by the management and control system, the user's pre-registration device identifies the user terminal to be offline as the target offline terminal. In the local network policy, it modifies the third processing rule corresponding to the target offline terminal into a redirection rule. This prevents the target offline terminal from reconnecting to the network. When it sends a network connection request to the user's pre-registration device, a redirection authentication process is triggered, requiring authentication by the management and control system before it can reconnect to the network.
[0069] It should be noted that the first, second, and third processing rules are essentially processing rules in the local network policy, but they are used to facilitate the description and differentiation of different scenarios.
[0070] In some embodiments of a secure networking method of the present invention applied to a user network access front-end device, it further includes: Execute periodically according to a preset cycle: Based on the operating status, generate device operating information; based on the connected user terminal, generate terminal operating information. The device operation information and the terminal operation information are uploaded to the management and control system; The device operation information is used by the management and control system to identify user network access front-end devices that are malfunctioning, and the terminal operation information is used by the management and control system to identify user terminals that are malfunctioning.
[0071] By periodically uploading device and terminal operation information, the user network access front-end equipment provides a basis for the management and control system to analyze and identify abnormally operating devices or terminals. This enables the management and control system to monitor and control the user network access front-end equipment and user terminal equipment, which helps to improve the security and stability of the network.
[0072] In some embodiments of the present invention, device operation information may include information such as CPU usage, memory usage, process startup status, and file content, while terminal operation information may include information such as connection duration, network access records, port connection status, and connected base station.
[0073] The following describes a secure networking system provided by the present invention. The secure networking system described below and the secure networking method described above can be referred to in correspondence.
[0074] refer to Figure 3 The present invention also provides a secure networking system, comprising: The control system is used to manage the networking process. At least one group of user network access front-end equipment, the user network access front-end equipment group including at least one user network access front-end device, the user network access front-end device being used to manage user terminal network access; A message server is used to enable the authenticated user's network access front-end device to establish a management communication connection with the control system; The control system executes the aforementioned secure networking method applied to the control system, and the user network access front-end device executes the aforementioned secure networking method applied to the user network access front-end device.
[0075] refer to Figure 3 The workflow of a secure networking system provided by this invention is as follows: Registration phase: After the control system starts up, it establishes a communication connection with the message server (EMQX service), controls the system to generate first device authentication information, and provides the information basis for the message server to perform second authentication processing. After the user's pre-entry device in each user pre-entry device group starts up, it sends its own generated second device authentication information to the message server for second authentication processing. The message server compares the second device authentication information with each first device authentication information. If a matching first device authentication information is found, authentication is passed, and a control communication connection is established between the user's pre-entry device and the control system.
[0076] User terminal network access control phase: The user terminal sends a network connection request to the user access front-end device. The user access front-end device authenticates the user terminal, that is, it confirms the processing rule corresponding to the user terminal from the local network policy. During the initial connection, the user access front-end device returns redirection information, instructing the user terminal to generate an access authentication request and submit it to the management system for authentication processing. The management system performs the first authentication process based on the access authentication request. If it determines that the user terminal is allowed to access the network, it generates authentication pass information and sends it to the corresponding user access front-end device group, thereby allowing the user terminal to access the network and achieving the function of one-time authentication and mutual trust among multiple devices. This achieves user terminal access authentication management.
[0077] When a user terminal's authentication expires or a specific user terminal needs to be taken offline, the management system generates a terminal offline message and sends it to the corresponding user's network access front-end device, causing the target user terminal to go offline. This achieves user terminal offline management.
[0078] Operation monitoring and control phase: User pre-connection terminals periodically send equipment operation information and terminal operation information to the management and control system. Based on the equipment operation information, the management and control system analyzes and identifies abnormal user pre-connection devices to promptly detect abnormal operation. Based on the terminal operation information, the management and control system analyzes and identifies abnormal user terminals to promptly detect abnormal operation. Based on the terminal operation information and the base station identifier connected to the user terminal, such as MCC / MNC / LAC / CID, the management and control system locates the user terminal. Furthermore, it can combine the user terminal's application scenario, such as the dynamic usage scenario of public transportation or the static usage scenario of shopping malls and supermarkets, to identify abnormal user terminals.
[0079] Therefore, the secure networking system provided by this invention, through the establishment of a management and control system, requires user terminals to be authenticated by the management and control system when joining the network, thereby ensuring network security. It also enables one-time authentication and mutual trust among multiple devices. That is, after a user terminal is authenticated by the management and control system, when switching to other connected devices within the same user access front-end device group, re-authentication is not required. The switched user access front-end device will use the same processing rules as before the switch to allow the user terminal to connect to the network, which improves networking efficiency and avoids the problem of duplicate authentication. Simultaneously, the configuration of the user access front-end devices is uniformly distributed by the management and control system, avoiding the drawback of requiring configuration adjustments on the connected devices, and preventing configuration anomalies in other devices after one device is hijacked, further enhancing network security. Furthermore, the management and control system monitors and controls the user access front-end devices and user terminals to promptly identify malfunctioning devices and terminals, facilitating timely handling and further improving network security.
[0080] Figure 4 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 4 As shown, the electronic device may include a processor 810, a communications interface 820, a memory 830, and a communication bus 840. The processor 810, communications interface 820, and memory 830 communicate with each other via the communication bus 840. The processor 810 can call logical instructions stored in the memory 830 to execute the aforementioned secure networking method.
[0081] The electronic device provided by this invention can be implemented as part of a control system, or as a user network access front-end device.
[0082] Furthermore, the logical instructions in the aforementioned memory 830 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0083] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute a secure networking method provided by the above methods.
[0084] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform a secure networking method provided by the methods described above.
[0085] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0086] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0087] In the description of this invention, it should be understood that the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.
[0088] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0089] All actions involving the acquisition of signals, information, or data in this application are carried out in accordance with the relevant data protection laws and policies of the country where the application is located, and with the authorization of the owner of the relevant device.
[0090] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A secure networking method, characterized in that, Applied to management and control systems, including: In response to a network access authentication request from a user terminal, the user terminal is subjected to a first authentication process based on the network access authentication request. Once it is determined that the user terminal is allowed to access the network, authentication pass information is generated based on the terminal identifier of the user terminal; The authentication pass information is sent to the user network access front-end equipment group corresponding to the user terminal; The network access authentication request is generated by redirection information sent from the user's network access front-end device to the user terminal; the user's network access front-end device group includes at least one user's network access front-end device, and the authentication pass information is used to instruct the user's network access front-end device group to configure the processing rules for the user terminal's network access.
2. The secure networking method according to claim 1, characterized in that, Prior to the network access authentication request in response to the user terminal, the method further includes: Establish a communication connection with the message server; Obtain the device identifier of the user's pre-network access device; The device identifier is processed according to a preset encryption algorithm to obtain and store the first device authentication information; The first device authentication information is provided to the message server for a second authentication process, and the message server is used to enable the authenticated user's network access front-end device to establish a management communication connection with the management and control system.
3. The secure networking method according to claim 1, characterized in that, Also includes: Based on the authentication record information, the terminal identifier whose authentication has expired is identified as the first offline identifier, and the authentication record information is formed by the first authentication process; In response to operational information, determine the second offline identifier; Based on the first offline identifier or the second offline identifier, generate terminal offline information; Send the terminal offline information to the user network access front-end device group corresponding to the offline identifier; The terminal offline information is used to instruct the user network access front-end equipment group to cancel the corresponding user terminal's network access.
4. The secure networking method according to claim 1, characterized in that, Also includes: Obtain the device operation information and terminal operation information uploaded by the user's network access pre-processor; Based on the device operation information, analyze the user network access front-end device to identify the user network access front-end device that is operating abnormally, and generate abnormal device information; Based on the terminal operation information, the user terminal is analyzed to identify user terminals that are malfunctioning, and abnormal terminal information is generated.
5. A secure networking method according to claim 1, characterized in that, After performing the first authentication process on the user terminal according to the network access authentication request, the method further includes: If it is determined that the user terminal is not allowed to access the network, an authentication error message is sent to the user terminal. After sending the authentication pass information to the user access front-end equipment group corresponding to the user terminal, the method further includes: Send test link information to the user terminal; The test link information is used to instruct the user terminal to perform a network connectivity test.
6. A secure networking method, characterized in that, Applications to user network access front-end equipment include: In response to a network connection request from a user terminal, a first terminal identifier is determined based on the network connection request; Based on the local network policy, determine the first processing rule corresponding to the first terminal identifier; Once the first processing rule is determined to be a redirection rule, redirection information is returned to the user terminal. The first processing rule is determined to be a forwarding rule, and the network connection request is forwarded according to the forwarding rule; In response to the authentication pass information of the control system, the second terminal identifier and the corresponding second processing rule are determined according to the authentication pass information, and the second processing rule is added to the local network policy; The redirection information is used to instruct the client to send a network access authentication request to the management system, so that the management system can execute a secure networking method as described in any one of claims 1 to 5.
7. A secure networking method according to claim 6, characterized in that, Prior to responding to the network connection request from the user terminal, the method further includes: Based on the local device identifier and processed using a preset encryption algorithm, a second device authentication information is generated. The second device authentication information is sent to the message server, which then performs a second authentication process to establish a management communication connection between the local device and the control system.
8. A secure networking method according to claim 6, characterized in that, Also includes: In response to terminal offline information, the user terminal that needs to be offline is selected as the target terminal for offline. According to the local network policy, the third processing rule corresponding to the offline target terminal is modified into a redirection rule.
9. A secure networking method according to claim 6, characterized in that, Also includes: Execute periodically according to a preset cycle: Based on the operating status, generate device operating information; based on the connected user terminal, generate terminal operating information. The device operation information and the terminal operation information are uploaded to the management and control system; The device operation information is used by the management and control system to identify user network access front-end devices that are malfunctioning, and the terminal operation information is used by the management and control system to identify user terminals that are malfunctioning.
10. A secure networking system, characterized in that, include: The control system is used to manage the networking process. At least one group of user network access front-end equipment, the user network access front-end equipment group including at least one user network access front-end device, the user network access front-end device being used to manage user terminal network access; A message server is used to enable the authenticated user's network access front-end device to establish a management communication connection with the control system; The control system executes a secure networking method as described in any one of claims 1 to 5, and the user access front-end device executes a secure networking method as described in any one of claims 4 to 9.
11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements a secure networking method as described in any one of claims 1 to 9.
12. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements a secure networking method as described in any one of claims 1 to 9.
13. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements a secure networking method as described in any one of claims 1 to 9.