Network resource access method and device, processor and electronic equipment

By receiving the identification information of the terminal device and determining its binding result with the target account, the problem of unauthorized devices accessing the internal network is solved based on multi-factor authentication, thereby improving network security.

CN121283701APending Publication Date: 2026-01-06CHINA FAW CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511374276.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-24
Publication Date
2026-01-06

AI Technical Summary

Technical Problem

Existing access control methods are too simplistic in verifying terminal devices, allowing unauthorized devices to access the internal network and private resources, resulting in low internal network security.

Method used

By receiving the identification information of the terminal device, the binding result between it and the target account is determined, and the access permissions are determined based on the identification information of the target account, thus realizing multi-factor authentication to prevent unauthorized devices from accessing the device.

Benefits of technology

This effectively prevents unauthorized devices from accessing the internal network and private resources, thus improving the security of the internal network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121283701A_ABST
    Figure CN121283701A_ABST
Patent Text Reader

Abstract

The invention discloses a network resource access method and device, a processor and electronic equipment, and the method comprises the steps: responding to an access request of terminal equipment for private resources in a network, receiving first identification information of the terminal equipment, and enabling the first identification information to be used for identifying the terminal equipment; based on the first identification information, determining a binding result between the terminal device and a target account, the target account being an account used for logging in the terminal device, and the binding result being used for representing whether the terminal device and the target account are successfully bound; and in response to the binding result indicating that the terminal equipment is successfully bound with the target account, access permission information of the terminal equipment is determined based on second identification information of the target account, the second identification information is used for identifying the target account, and the access permission information is used for indicating whether the terminal equipment has the permission of requesting to access the private resource or not. According to the invention, the technical problem of low security of internal network access is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicles, and more specifically, to a method, apparatus, processor, and electronic device for accessing network resources. Background Technology

[0002] Currently, in order to prevent security risks such as data leakage and unauthorized access caused by unauthorized terminal devices illegally accessing the internal network, it is necessary to establish a strict terminal access control mechanism.

[0003] However, existing access control methods are too simple and weak in verifying terminal devices, which poses a risk that unauthorized terminal devices can also access the internal network and access private resources, resulting in low security for accessing the internal network.

[0004] There is currently no effective solution to the aforementioned technical problems of low security when accessing internal networks. Summary of the Invention

[0005] This invention provides a method, apparatus, processor, and electronic device for accessing network resources, to at least address the technical problem of low security when accessing internal networks.

[0006] According to one aspect of the present invention, a method for accessing network resources is provided. The method includes: in response to a terminal device's request to access private resources in the network, receiving first identification information of the terminal device, wherein the first identification information is used to identify the terminal device; determining a binding result between the terminal device and a target account based on the first identification information, wherein the target account is an account used to log in to the terminal device, and the binding result is used to indicate whether the terminal device and the target account are successfully bound; in response to the binding result indicating that the terminal device and the target account are successfully bound, determining access permission information of the terminal device based on second identification information of the target account, wherein the second identification information is used to identify the target account, and the access permission information is used to indicate whether the terminal device has permission to request access to private resources.

[0007] Optionally, determining the binding result between the terminal device and the target account based on the first identification information includes: determining the information relationship between the first identification information and the second identification information; and determining the binding result based on the information relationship.

[0008] Optionally, the binding result is determined based on the information relationship, including: in response to the information relationship indicating that the first identification information and the second identification information have a binding relationship, the binding result is determined to indicate that the terminal device and the target account are successfully bound; in response to the information relationship indicating that the first identification information and the second identification information do not have a binding relationship, the binding result is determined to indicate that the terminal device and the target account have failed to bind.

[0009] Optionally, in response to the binding result indicating that the terminal device and the target account are successfully bound, the access permission information of the terminal device is determined based on the second identification information of the target account, including: in response to the binding result indicating that the terminal device and the target account are successfully bound, the second identification information is verified to obtain a verification result, wherein the verification result is used to indicate the relationship between the target account and normal accounts and abnormal accounts; in response to the verification result indicating that the target account is a normal account, the access permission information is determined to indicate that the terminal device has the permission to request access to private resources; in response to the verification result indicating that the target account is an abnormal account, the access permission information is determined to indicate that the terminal device does not have the permission to request access to private resources.

[0010] Optionally, the method further includes: in response to access permission information indicating that the terminal device has permission to request access to private resources, sending a verification password to the handheld device associated with the target account, wherein the target account is used on the terminal device to access the private resources by means of the verification password.

[0011] Optionally, the method further includes: in response to the access permission information indicating that the terminal device does not have permission to request access to private resources, allowing the terminal device to access public resources in the network.

[0012] According to one aspect of the present invention, a network resource access device is provided. The device may include: a receiving unit, configured to receive first identification information of a terminal device in response to a terminal device's request to access private resources in a network, wherein the first identification information is used to identify the terminal device; a first determining unit, configured to determine a binding result between the terminal device and a target account based on the first identification information, wherein the target account is an account used to log in to the terminal device, and the binding result is used to indicate whether the terminal device and the target account are successfully bound; and a second determining unit, configured to determine access permission information of the terminal device based on second identification information of the target account in response to the binding result indicating that the terminal device and the target account are successfully bound, wherein the second identification information is used to identify the target account, and the access permission information is used to indicate whether the terminal device has permission to request access to private resources.

[0013] According to another aspect of the present invention, a processor is also provided. The processor is used to run a program, wherein the program, when run by the processor, executes the network resource access method of the present invention.

[0014] According to another aspect of the embodiments of the present invention, an electronic device is also provided, comprising: a memory storing an executable program; and a processor for running the program, wherein the program executes the network resource access methods of various embodiments of the present invention during runtime.

[0015] According to another aspect of the present invention, a computer-readable storage medium is also provided. The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device where the computer-readable storage medium is located to perform the network resource access method of the present invention.

[0016] According to another aspect of the present invention, a computer program product is also provided, the computer program product including a computer program, wherein the computer program, when executed by a processor, implements the network resource access method of the present invention.

[0017] According to another aspect of the present invention, a computer program product is also provided, including a non-volatile computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the network resource access method of the present invention.

[0018] According to another aspect of the present invention, the present application also provides a computer program that, when executed by a processor, implements the network resource access method described in the present invention embodiments.

[0019] In this embodiment of the invention, when accessing network resources, in response to a terminal device's request to access private resources in the network, the system receives first identification information of the terminal device; based on the first identification information, it determines the binding result between the terminal device and the target account; in response to the binding result indicating successful binding between the terminal device and the target account, it determines the terminal device's access permission information based on the second identification information of the target account. Because this embodiment of the invention, when determining the binding result between the terminal device and the target account based on the first identification information, indicating successful binding between the terminal device and the target account, can determine the terminal device's access permission information based on the second identification information of the target account, it achieves the goal of avoiding the risk of unauthorized terminal devices accessing the internal network and private resources, thereby solving the technical problem of low security when accessing the internal network and thus achieving the technical effect of improving the security of accessing the internal network. Attached Figure Description

[0020] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0021] Figure 1 This is a flowchart of a method for accessing network resources according to an embodiment of the present invention;

[0022] Figure 2 This is a flowchart of a terminal access method based on multi-factor authentication according to an embodiment of the present invention;

[0023] Figure 3 This is a schematic diagram of a network resource access device according to an embodiment of the present invention;

[0024] Figure 4 This is a schematic diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0025] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0026] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0027] According to an embodiment of the present invention, a method for accessing network resources is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0028] Figure 1 This is a flowchart of a method for accessing network resources according to an embodiment of the present invention, such as... Figure 1 As shown, the method may include the following steps:

[0029] Step S101: In response to the terminal device's request to access private resources in the network, the first identification information of the terminal device is received, wherein the first identification information is used to identify the terminal device.

[0030] In the technical solution provided by step S101 of the present invention, the first identification information can be used to identify the terminal device. The terminal device can also be referred to as a legitimate terminal device, and can include desktop computers, tablet computers, and laptop computers, etc. For example, if the terminal device is a desktop computer, the first identification information can be the desktop computer's serial number (SN); if the terminal device is a tablet computer, the first identification information can be the tablet computer's International Mobile Equipment Identity (IMEI); if the terminal device is a laptop computer, the first identification information can be the laptop computer's Media Access Control Address (MAC). These are merely illustrative examples and not specific limitations.

[0031] In this embodiment, the aforementioned private resources can be used to represent resources accessed by a specific account or terminal device. These private resources may include sensitive information on the network, such as a company's financial data and employee information; this is merely an example and not a specific limitation.

[0032] In this embodiment, in response to a terminal device's request to access private resources in the network, the first identification information of the terminal device is received. Optionally, this embodiment detects whether there is an access request for private resources in the network. If an access request for the private resources by the terminal device is detected, the first identification information of the terminal device is received, thereby achieving the purpose of determining the identity of the terminal device.

[0033] Optionally, if no access request from the terminal device to the aforementioned private resource is detected, the detection of whether there is an access request to the aforementioned private resource continues until an access request from the terminal device to the aforementioned private resource is detected, and then the first identification information of the terminal device is received.

[0034] Step S102: Based on the first identification information, determine the binding result between the terminal device and the target account, wherein the target account is the account used to log in to the terminal device, and the binding result is used to indicate whether the terminal device and the target account are successfully bound.

[0035] In the technical solution provided by step S102 of the present invention, the target account can be an account used to log in to the terminal device. For example, the target account can be represented by any of the following forms: email address, mobile phone number, and "username + suffix", etc., which are only examples and are not specifically limited.

[0036] In this embodiment, the binding result can be used to indicate whether the terminal device and the target account have been successfully bound. For example, the binding result can also be called binding information; the binding result can indicate that the terminal device and the target account have been successfully bound, or that the binding has failed. This is only an example and is not specifically limited.

[0037] In this embodiment, after receiving the first identification information of the terminal device in response to the terminal device's request to access private resources in the network, the binding result between the terminal device and the target account is determined based on the first identification information. Optionally, this embodiment receives the second identification information of the target account in addition to the first identification information of the terminal device; based on the received first and second identification information, the binding result between the terminal device and the target account can be determined, thereby achieving the purpose of determining whether the terminal device and the target account are successfully bound.

[0038] Optionally, based on the received first and second identification information, the binding result between the terminal device and the target account can be determined. For example, by performing a binding relationship query on the first and second identification information, the information relationship between the first and second identification information can be obtained; based on the information relationship, the binding result between the terminal device and the target account can be determined.

[0039] Step S103: In response to the binding result indicating that the terminal device and the target account are successfully bound, the access permission information of the terminal device is determined based on the second identification information of the target account. The second identification information is used to identify the target account, and the access permission information is used to indicate whether the terminal device has the permission to request access to private resources.

[0040] In the technical solution provided by step S103 of the present invention, the second identification information can be used to identify the target account. For example, if the target account is in the format of an email address, the second identification information can be the email address; if the target account is in the format of a mobile phone number, the second identification information can be all the digits of the mobile phone number or the last four digits of the mobile phone number; if the target account is in the format of "username + suffix", the second identification information can be the full pinyin of the username + suffix. This is only an example and is not specifically limited.

[0041] In this embodiment, the access permission information described above can be used to indicate whether the terminal device has permission to request access to private resources. For example, the access permission information can be used to indicate that the terminal device has permission to request access to private resources, or it can be used to indicate that the terminal device does not have permission to request access to private resources. This is only an example and is not a specific limitation.

[0042] In this embodiment, after determining the binding result between the terminal device and the target account based on the first identification information, in response to the binding result indicating that the terminal device and the target account are successfully bound, the access permission information of the terminal device is determined based on the second identification information of the target account. Optionally, in this embodiment, based on the determined binding result, if the binding result indicates that the terminal device and the target account are successfully bound, the second identification information of the target account is verified to obtain a verification result. The verification result can be used to indicate the relationship between the target account and normal accounts and abnormal accounts. According to the verification result, the access permission information of the terminal device can be determined, thereby achieving the purpose of determining whether the terminal device has the permission to request access to private resources.

[0043] In steps S101 to S103 of this application, when accessing network resources, in response to a terminal device's request to access private resources in the network, the system receives first identification information of the terminal device; based on the first identification information, it determines the binding result between the terminal device and the target account; and in response to the binding result indicating successful binding between the terminal device and the target account, it determines the terminal device's access permission information based on the second identification information of the target account. Because this embodiment of the invention, when determining the binding result between the terminal device and the target account based on the first identification information, indicating successful binding between the terminal device and the target account, can determine the terminal device's access permission information based on the second identification information of the target account, it achieves the goal of avoiding the risk of unauthorized terminal devices accessing the internal network and private resources, thereby solving the technical problem of low security when accessing the internal network and thus achieving the technical effect of improving the security of accessing the internal network.

[0044] The method described in this embodiment will be further described below.

[0045] As an optional embodiment, step S102, determining the binding result between the terminal device and the target account based on the first identification information, includes: determining the information relationship between the first identification information and the second identification information; and determining the binding result based on the information relationship.

[0046] In this embodiment, after receiving the first identification information of the terminal device in response to the terminal device's request to access private resources in the network, the information relationship between the first identification information and the second identification information is determined; based on the information relationship, the binding result is determined. Optionally, in addition to receiving the first identification information of the terminal device, this embodiment can also receive the second identification information of the target account; by querying the binding relationship between the received first and second identification information, the information relationship between the first and second identification information can be obtained; based on the obtained information relationship, the binding result between the terminal device and the target account can be determined, thereby achieving the purpose of determining whether the terminal device and the target account are successfully bound, thus realizing the technical effect of improving the security of device verification.

[0047] Optionally, a binding relationship query can be performed on the received first identifier information and second identifier information to obtain the information relationship between them. For example, the binding relationship database can be searched to determine whether a binding relationship exists between the first identifier information and the second identifier information. If a binding relationship is found, it can be determined that the first identifier information and the second identifier information are bound together; if no binding relationship is found, it can be determined that the first identifier information and the second identifier information are not bound together.

[0048] It should be noted that the aforementioned binding relationship database may include the binding relationships between the identification information of different terminal devices and the identification information of different accounts. Furthermore, the binding relationship database can be updated according to a preset update cycle. For example, the update cycle may be, but is not limited to, daily, weekly, monthly, and quarterly cycles; this is merely an example and not a specific limitation.

[0049] The steps for determining the binding result based on information relationships in this embodiment will be further described below.

[0050] As an optional implementation method, determining the binding result based on the information relationship includes: in response to the information relationship indicating that the first identification information and the second identification information have a binding relationship, determining the binding result indicates that the terminal device and the target account are successfully bound; in response to the information relationship indicating that the first identification information and the second identification information do not have a binding relationship, determining the binding result indicates that the terminal device and the target account have failed to bind.

[0051] In this embodiment, after determining the information relationship between the first identification information and the second identification information, in response to the information relationship indicating that the first identification information and the second identification information are bound together, the binding result is determined to indicate that the terminal device and the target account are successfully bound. Optionally, based on the determined information relationship, if the information relationship indicates that the first identification information and the second identification information are bound together, the binding result can be determined to indicate that the terminal device and the target account are successfully bound, thereby achieving the purpose of determining that the terminal device and the target account are successfully bound, and thus realizing the technical effect of improving the security of device verification.

[0052] In this embodiment, after determining the information relationship between the first identification information and the second identification information, in response to the information relationship indicating that the first identification information and the second identification information are not bound together, the binding result is determined to indicate that the terminal device has failed to bind with the target account. Optionally, based on the determined information relationship, if the aforementioned information relationship indicates that the first identification information and the second identification information are not bound together, the binding result can be determined to indicate that the terminal device has failed to bind with the target account. This achieves the purpose of determining that the terminal device has failed to bind with the target account, thereby realizing the technical effect of improving the security of device verification.

[0053] The following section further describes the steps of responding to the binding result in this embodiment, indicating that the terminal device has been successfully bound to the target account, and determining the access permission information of the terminal device based on the second identification information of the target account.

[0054] As an optional embodiment, step S103, in response to the binding result indicating that the terminal device and the target account are successfully bound, determines the access permission information of the terminal device based on the second identification information of the target account, including: in response to the binding result indicating that the terminal device and the target account are successfully bound, verifying the second identification information to obtain a verification result, wherein the verification result is used to indicate the relationship between the target account and normal accounts and abnormal accounts; in response to the verification result indicating that the target account is a normal account, determining the access permission information indicates that the terminal device has the permission to request access to private resources; in response to the verification result indicating that the target account is an abnormal account, determining the access permission information indicates that the terminal device does not have the permission to request access to private resources.

[0055] In this embodiment, the verification result can be used to represent the relationship between the target account and normal or abnormal accounts. For example, the verification result can be used to indicate that the target account is a normal account or an abnormal account; this is only an example and is not a specific limitation.

[0056] In this embodiment, the above verification can be user identity verification of the second identification information. For example, if the second identification information is all the digits of a mobile phone number, then the above verification can be user identity verification of the mobile phone number. This is only an example and is not specifically limited.

[0057] In this embodiment, after determining the binding result between the terminal device and the target account based on the first identification information, in response to the binding result indicating that the terminal device and the target account are successfully bound, the second identification information is verified to obtain a verification result. Optionally, in this embodiment, based on determining the binding result between the terminal device and the target account, if the binding result indicates that the terminal device and the target account are successfully bound, the second identification information is used for identity verification to obtain a verification result, thereby achieving the purpose of determining the relationship between the target account and normal and abnormal accounts.

[0058] In this embodiment, in response to the binding result indicating that the terminal device and the target account are successfully bound, the second identification information is verified. After obtaining the verification result, in response to the verification result indicating that the target account is a normal account, the access permission information is determined to indicate that the terminal device has the permission to request access to private resources. Optionally, based on the verification result, if the verification result indicates that the target account is a normal account, then the access permission information of the terminal device can be determined to indicate that the terminal device has the permission to request access to private resources. This achieves the purpose of determining that the terminal device has the permission to request access to private resources, thereby realizing the technical effect of improving the security of accessing the internal network.

[0059] In this embodiment, in response to the binding result indicating that the terminal device and the target account are successfully bound, the second identification information is verified. After obtaining the verification result, in response to the verification result indicating that the target account is an abnormal account, the access permission information is determined to indicate that the terminal device does not have the permission to request access to private resources. Optionally, based on the verification result, if the verification result indicates that the target account is an abnormal account, this embodiment can determine that the terminal device's access permission information indicates that the terminal device does not have the permission to request access to private resources. This achieves the purpose of determining that the terminal device does not have the permission to request access to private resources, thereby realizing the technical effect of improving the security of accessing the internal network.

[0060] The following section further describes the method for accessing the network resources described in this embodiment.

[0061] As an optional embodiment, the method further includes: in response to access permission information indicating that the terminal device has permission to request access to private resources, sending a verification password to a handheld device associated with the target account, wherein the target account is used to access the private resources on the terminal device by means of the verification password.

[0062] In this embodiment, the handheld device may include smartphones, smartwatches, and tablet computers (PADs), etc.

[0063] In this embodiment, the verification password can be a dynamic password.

[0064] In this embodiment, the target account can be used on a terminal device to access private resources by verifying a password.

[0065] In this embodiment, in response to access permission information indicating that the terminal device has permission to request access to private resources, a verification password is sent to the handheld device associated with the target account. Optionally, this embodiment, upon determining that the access permission information indicates that the terminal device has permission to request access to private resources, sends a verification password to the handheld device associated with the target account, enabling the target account to access private resources in the network by entering the verification password on the terminal device. This achieves the goal of preventing unauthorized terminal devices from accessing the internal network and private resources, thereby improving the technical effect of enhancing the security of accessing the internal network.

[0066] The following section further describes the method for accessing the network resources described in this embodiment.

[0067] As an optional embodiment, the method further includes: in response to the access permission information indicating that the terminal device does not have permission to request access to private resources, allowing the terminal device to access public resources in the network.

[0068] In this embodiment, the aforementioned public resources can be used to represent resources shared and accessed by multiple accounts or terminal devices. For example, the aforementioned public resources may include: open services on the network, publicly available information, and data resources that are accessible to users within a certain range, etc., which are only illustrative examples and are not specifically limited.

[0069] In this embodiment, in response to the access permission information indicating that the terminal device does not have permission to request access to private resources, the terminal device is allowed to access public resources on the network. Optionally, this embodiment, when determining that the access permission information indicates that the terminal device does not have permission to request access to private resources, allows the terminal device to access public resources on the network, for example, allowing a desktop computer to access public resources on the network. This achieves the goal of avoiding the risk of unauthorized terminal devices accessing the internal network and private resources, thereby achieving the technical effect of improving the security of accessing the internal network.

[0070] For example, a large enterprise implemented the multi-factor authentication-based endpoint access method described in this application to protect its sensitive data and network resources from unauthorized access. The specific implementation process is as follows:

[0071] Obtaining a unique identifier for the terminal device: Enterprises generate a first identifier for the terminal device through a custom algorithm by installing specific software on all computers assigned to employees, such as an encrypted hash value.

[0072] User-Device Binding: When a terminal device is first issued to an employee, the employee needs to log in using their corporate account and authenticate themselves (by entering a password or using two-factor authentication, such as SMS verification code or fingerprint authentication). After authentication is completed, the terminal device's unique identifier can be bound to the employee's account on the company's internal network access control platform.

[0073] Network access control: When a terminal device attempts to access the corporate intranet, the network system (e.g., a switch or router) initiates the 802.1x protocol, requiring the terminal device to authenticate. The terminal device will send its unique identifier to the network access control platform for verification.

[0074] Terminal device verification: After receiving the unique identifier of a device, the network access control platform checks whether it is bound to any enterprise account. If no binding information is found for the device identifier, the network access control platform will deny network access to the device and mark it as an unauthorized device. If the device identifier is bound to one or more accounts, the network access control platform will further verify whether the identity of the user currently attempting to log in matches the bound account. If they match, the verification is successful; otherwise, access is denied.

[0075] Dynamic password issuance: After verifying the legitimacy of the device and the user, the network access control platform will generate a dynamic password and send it to the user through a secure channel (e.g., encrypted email or secure messaging service).

[0076] Access Control Completed: The user enters a dynamic password on their terminal device to complete the final authentication step. Upon successful authentication, the network access control platform sends corresponding verification rules to the network device, allowing the terminal device to access specific resources on the enterprise intranet.

[0077] Full lifecycle monitoring: The network access control platform also monitors terminal devices throughout their entire lifecycle, from issuance, use, maintenance, to disposal, to ensure that network access permissions can be adjusted or revoked in a timely manner in cases such as loss of terminal devices or employee departure.

[0078] In this embodiment of the invention, when accessing network resources, in response to a terminal device's request to access private resources in the network, the system receives first identification information of the terminal device; based on the first identification information, it determines the binding result between the terminal device and the target account; in response to the binding result indicating successful binding between the terminal device and the target account, it determines the terminal device's access permission information based on the second identification information of the target account. Because this embodiment of the invention, when determining the binding result between the terminal device and the target account based on the first identification information, indicating successful binding between the terminal device and the target account, can determine the terminal device's access permission information based on the second identification information of the target account, it achieves the goal of avoiding the risk of unauthorized terminal devices accessing the internal network and private resources, thereby solving the technical problem of low security when accessing the internal network and thus achieving the technical effect of improving the security of accessing the internal network.

[0079] The technical solutions of the embodiments of the present invention will be illustrated below with reference to preferred embodiments.

[0080] Currently, in order to prevent security risks such as data leakage and unauthorized access caused by unauthorized terminal devices illegally accessing the internal network, it is necessary to establish a strict terminal access control mechanism.

[0081] However, existing access control methods are too simple and weak in verifying terminal devices, which poses a risk that unauthorized terminal devices can also access the internal network and access private resources, resulting in low security for accessing the internal network.

[0082] To address the aforementioned technical problems, this invention proposes a method for accessing network resources. Based on first identification information, if the binding result between the terminal device and the target account indicates successful binding, then based on the second identification information of the target account, the access permission information of the terminal device can be determined. This achieves the goal of preventing unauthorized terminal devices from accessing the internal network and private resources, thereby solving the technical problem of low security when accessing the internal network and ultimately improving the security of accessing the internal network.

[0083] In this embodiment, by executing a terminal access method based on multi-factor authentication, the access permissions of the terminal device can be determined based on the second identifier information of the target account. For example, Figure 2 This is a flowchart of a terminal access method based on multi-factor authentication according to an embodiment of the present invention, such as... Figure 2 As shown, the method may include:

[0084] Step S201: Issue the legitimacy terminal device.

[0085] After the legitimate terminal devices are issued, step S202 is entered, where a unique code for the terminal device is generated according to the generation algorithm. The unique code can be used to uniquely identify the terminal device.

[0086] In the technical solution provided by step S202 of the present invention, an algorithm is designed to obtain the unique identifier of the terminal device, and a script file for binding the terminal device and the user is provided; when the desktop issues assets, the script file is executed to associate the device and the user, and the ledger data is saved to the verification platform. For example, the verification platform can also be called the network access control platform, which can be referred to as platform A.

[0087] Optionally, the free Internet Protocol (IP) mode can be adopted, which allows the terminal device to obtain an IP address and have limited access to public resources on the network before successful authentication when accessing the network.

[0088] After generating a unique code for the terminal device according to the algorithm, step S203 is initiated, invoking the verification platform to verify that the terminal device is a valid device.

[0089] In the technical solution provided by step S203 of the present invention, before authentication, the terminal device and the verification platform can interact through the network to verify whether the terminal device is a valid device.

[0090] After calling the verification platform to verify that the terminal device is a valid device, proceed to step S204 to verify that the user identity associated with the terminal device is a valid identity.

[0091] In the technical solution provided by step S204 of the present invention, under the premise that the terminal device is a valid device, the user identity associated with the terminal device is verified as a valid identity.

[0092] For example, when the verification platform receives a request to query the unique identifier of a terminal device, it makes a judgment and processes the result as follows: If the first identifier information and the second identifier information are not bound together, it will indicate that the terminal device is not registered on platform A and is an invalid device; if the first identifier information and the second identifier information are bound together, the terminal device verification passes, and the user identity verification is performed according to the information returned by platform A. If the verification passes, a dynamic password is issued to the user, completing the dual verification of access and issuing the policy.

[0093] After verifying that the user identity associated with the terminal device is valid, proceed to step S205, enter the dynamic verification code, and when the verification code is successfully authenticated, allow the terminal to access the network.

[0094] In the technical solution provided in step S205 of the present invention, the user associated with the terminal device is authorized to access private resources in the network by issuing an Access Control List (ACL) through the switch.

[0095] For example, a large enterprise implemented the multi-factor authentication-based endpoint access method described in this application to protect its sensitive data and network resources from unauthorized access. The specific implementation process is as follows:

[0096] Obtaining a unique identifier for a terminal device: Enterprises install specific software on all computers assigned to employees. This software can collect information such as the device's MAC address and hard drive serial number, and generate a comprehensive and unique identifier for the device using an enterprise-defined algorithm, such as an encrypted hash value.

[0097] User-Device Binding: When a device is first issued to an employee, the employee needs to log in using their corporate account and authenticate themselves (by entering a password or using two-factor authentication, such as SMS verification code or fingerprint authentication). After authentication is completed, the unique identifier of the terminal device can be bound to the employee's account on the company's internal network access control platform.

[0098] Network access control: When a terminal device attempts to access the corporate intranet, the network system (e.g., a switch or router) initiates the 802.1x protocol, requiring the terminal device to authenticate. The terminal device will send its unique identifier to the network access control platform for verification.

[0099] Terminal device verification: After receiving the unique identifier of a device, the network access control platform checks whether it is bound to any enterprise account. If no binding information is found for the device identifier, the network access control platform will deny network access to the device and mark it as an unauthorized device. If the device identifier is bound to one or more accounts, the network access control platform will further verify whether the identity of the user currently attempting to log in matches the bound account. If they match, the verification is successful; otherwise, access is denied.

[0100] Dynamic password issuance: After verifying the legitimacy of the device and the user, the network access control platform will generate a dynamic password and send it to the user through a secure channel (e.g., encrypted email or secure messaging service).

[0101] Access Control Completed: The user enters a dynamic password on their terminal device to complete the final authentication step. Upon successful authentication, the network access control platform issues corresponding ACL rules to the network device, allowing the terminal device to access specific resources on the enterprise intranet.

[0102] Full lifecycle monitoring: The network access control platform also monitors terminal devices throughout their entire lifecycle, from issuance, use, maintenance, to disposal, to ensure that network access permissions can be adjusted or revoked in a timely manner in cases such as loss of terminal devices or employee departure.

[0103] In this embodiment, when accessing network resources, in response to a terminal device's request to access private resources in the network, the system receives first identification information of the terminal device; based on the first identification information, it determines the binding result between the terminal device and the target account; in response to the binding result indicating successful binding between the terminal device and the target account, it determines the terminal device's access permission information based on the second identification information of the target account. Because this embodiment of the invention, when determining the binding result between the terminal device and the target account based on the first identification information, indicating successful binding between the terminal device and the target account, can determine the terminal device's access permission information based on the second identification information of the target account, it achieves the goal of avoiding the risk of unauthorized terminal devices accessing the internal network and private resources, thereby solving the technical problem of low security when accessing the internal network and thus achieving the technical effect of improving the security of accessing the internal network.

[0104] According to embodiments of the present invention, a network resource access device is also provided. It should be noted that this network resource access device can be used to execute a network resource access method according to one of the embodiments.

[0105] Figure 3 This is a schematic diagram of a network resource access device according to an embodiment of the present invention. Figure 3As shown, the network resource access device 300 may include: a receiving unit 301, a first determining unit 302, and a second determining unit 303.

[0106] The receiving unit 301 is configured to receive first identification information of the terminal device in response to the terminal device's request to access private resources in the network, wherein the first identification information is used to identify the terminal device.

[0107] The first determining unit 302 is used to determine the binding result between the terminal device and the target account based on the first identification information, wherein the target account is the account used to log in to the terminal device, and the binding result is used to indicate whether the terminal device and the target account are successfully bound.

[0108] The second determining unit 303 is used to determine the access permission information of the terminal device based on the second identification information of the target account in response to the binding result indicating that the terminal device and the target account are successfully bound. The second identification information is used to identify the target account, and the access permission information is used to indicate whether the terminal device has the permission to request access to private resources.

[0109] Optionally, the first determining unit 302 may include: a first determining module, used to determine the information relationship between the first identification information and the second identification information; and a second determining module, used to determine the binding result based on the information relationship.

[0110] Optionally, the second determining module may include: a first determining submodule, used to determine the binding result indicating that the terminal device and the target account are successfully bound in response to an information relationship indicating that the first identification information and the second identification information are bound; and a second determining submodule, used to determine the binding result indicating that the terminal device and the target account are not bound in response to an information relationship indicating that the first identification information and the second identification information are not bound.

[0111] Optionally, the second determining unit 303 may include: a verification module, used to verify the second identification information and obtain a verification result in response to the binding result indicating that the terminal device and the target account are successfully bound, wherein the verification result is used to indicate the relationship between the target account and normal accounts and abnormal accounts; a third determining module, used to determine the access permission information indicating that the terminal device has the permission to request access to private resources in response to the verification result indicating that the target account is a normal account; and a fourth determining module, used to determine the access permission information indicating that the terminal device does not have the permission to request access to private resources in response to the verification result indicating that the target account is an abnormal account.

[0112] Optionally, the network resource access device 300 may include: a sending unit, configured to send a verification password to a handheld device associated with a target account in response to access permission information indicating that the terminal device has permission to request access to the private resource, wherein the target account is used to access the private resource on the terminal device by means of the verification password.

[0113] Optionally, the network resource access device 300 may include: an access unit, configured to allow the terminal device to access public resources in the network in response to an access permission information indicating that the terminal device does not have permission to request access to private resources.

[0114] In this embodiment, a network resource access device is provided. The device may include: a receiving unit, configured to receive first identification information of the terminal device in response to a terminal device's request to access private resources in the network, wherein the first identification information identifies the terminal device; a first determining unit, configured to determine a binding result between the terminal device and a target account based on the first identification information, wherein the target account is an account used to log in to the terminal device, and the binding result indicates whether the terminal device and the target account are successfully bound; and a second determining unit, configured to determine access permission information of the terminal device based on the second identification information of the target account in response to the binding result indicating successful binding between the terminal device and the target account, wherein the second identification information identifies the target account, and the access permission information indicates whether the terminal device has permission to request access to private resources. This achieves the goal of avoiding the risk of unauthorized terminal devices accessing the internal network and private resources, thereby solving the technical problem of low security when accessing the internal network and thus achieving the technical effect of improving the security of accessing the internal network.

[0115] According to an embodiment of the present invention, a processor is also provided for running a program, wherein the program is executed by the processor to perform the network resource access method of the embodiment.

[0116] According to embodiments of the present invention, an electronic device is also provided. Figure 4 This is a schematic diagram of an electronic device according to an embodiment of the present invention, such as... Figure 4 As shown, the electronic device 400 may include a memory 410 and a processor 420, wherein the memory 410 is used to store computer programs; and the processor 420 is used to run the programs stored in the memory 410 to implement the network resource access method of this application.

[0117] In this application, "multiple" refers to two or more.

[0118] In this application, unless otherwise expressly defined, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.

[0119] The terms “first,” “second,” “third,” “fourth,” etc., in this application (if present) are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0120] In this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, in this application, the character " / " generally indicates that the preceding and following related objects have an "or" relationship.

[0121] Unless otherwise specified, all steps of this application may be performed sequentially or randomly. For example, the method for accessing network resources in this application may include steps S101 and S102, meaning that the method for accessing network resources in this application may include steps S101 and S102 performed sequentially, or it may include steps S102 and S101 performed sequentially.

[0122] For example, the network resource access method of this application may also include step S103, which means that step S103 can be added to the method in any order. For example, the network resource access method of this application may include steps S101, S102 and S103, or it may include steps S101, S103 and S102, or it may include steps S103, S101 and S102, etc. This is only an example and is not specifically limited.

[0123] According to another aspect of the present invention, a computer-readable storage medium is also provided. The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device where the computer-readable storage medium is located to perform the network resource access method of the embodiment.

[0124] Computer-readable storage media, also known as computer storage media, may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. These propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable storage media can transmit, propagate, or transfer programs for use by or in conjunction with an instruction execution system, apparatus, or device.

[0125] The program code contained in a computer-readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, radio frequency, or any suitable combination thereof.

[0126] According to an embodiment of the present invention, a computer program product is also provided, the computer program product including a computer program, wherein the computer program, when executed by a processor, implements the network resource access method of the embodiment.

[0127] According to an embodiment of the present invention, a computer program product is also provided, including a non-volatile computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the network resource access method of the embodiment.

[0128] According to an embodiment of the present invention, a computer program is also provided, which, when executed by a processor, implements the method for accessing network resources in the embodiment.

[0129] Optionally, when the above-mentioned computer program is executed by the processor, the program code implements the following steps: in response to a terminal device's request to access private resources in the network, receiving first identification information of the terminal device, wherein the first identification information is used to identify the terminal device; based on the first identification information, determining the binding result between the terminal device and a target account, wherein the target account is an account used to log in to the terminal device, and the binding result is used to indicate whether the terminal device and the target account are successfully bound; in response to the binding result indicating that the terminal device and the target account are successfully bound, determining the terminal device's access permission information based on the second identification information of the target account, wherein the second identification information is used to identify the target account, and the access permission information is used to indicate whether the terminal device has the permission to request access to private resources.

[0130] Optionally, when the above computer program is executed by the processor, the program code implements the following steps: determining the information relationship between the first identification information and the second identification information; and determining the binding result based on the information relationship.

[0131] Optionally, when the above computer program is executed by the processor, the program code performs the following steps: in response to the information relationship indicating that the first identification information and the second identification information have a binding relationship, the binding result is determined to indicate that the terminal device and the target account are successfully bound; in response to the information relationship indicating that the first identification information and the second identification information do not have a binding relationship, the binding result is determined to indicate that the terminal device and the target account have failed to bind.

[0132] Optionally, when the above computer program is executed by the processor, the program code implements the following steps: in response to the binding result indicating that the terminal device and the target account are successfully bound, the second identification information is verified to obtain a verification result, wherein the verification result is used to indicate the relationship between the target account and normal accounts and abnormal accounts; in response to the verification result indicating that the target account is a normal account, the access permission information is determined to indicate that the terminal device has the permission to request access to private resources; in response to the verification result indicating that the target account is an abnormal account, the access permission information is determined to indicate that the terminal device does not have the permission to request access to private resources.

[0133] Optionally, when the above computer program is executed by the processor, the program code implements the following steps: in response to the access permission information indicating that the terminal device has the permission to request access to private resources, a verification password is sent to the handheld device associated with the target account, wherein the target account is used to access the private resources on the terminal device by verifying the password.

[0134] Optionally, when the above computer program is executed by the processor, the program code implements the following steps: in response to the access permission information indicating that the terminal device does not have permission to request access to private resources, the terminal device is allowed to access public resources in the network.

[0135] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0136] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0137] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.

[0138] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0139] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0140] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, in essence, or the part that contributes to related technologies, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0141] The above are merely preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method of accessing a network resource, characterized by, The method comprises: in response to a terminal device's access request for a private resource in a network, receiving first identification information of the terminal device, wherein the first identification information is used to identify the terminal device; based on the first identification information, determining a binding result between the terminal device and a target account, wherein the target account is an account used to log in the terminal device, and the binding result is used to indicate whether the terminal device and the target account are successfully bound; in response to the binding result indicating that the terminal device and the target account are successfully bound, determining access permission information of the terminal device based on second identification information of the target account, wherein the second identification information is used to identify the target account, and the access permission information is used to indicate whether the terminal device has permission to request access to the private resource.

2. The method of claim 1, wherein, The method further comprises: determining a binding result between the terminal device and a target account based on the first identification information, comprising: determining an association relationship between the first identification information and the second identification information; 3. The method of claim 2, wherein, based on the information relationship, determining the binding result. The method further comprises: in response to the information relationship indicating that the first identification information and the second identification information have a binding relationship, determining that the binding result indicates that the terminal device and the target account are successfully bound; 4. The method of claim 1, wherein, in response to the information relationship indicating that the first identification information and the second identification information do not have a binding relationship, determining that the binding result indicates that the terminal device and the target account are not successfully bound. The method further comprises: in response to the binding result indicating that the terminal device and the target account are successfully bound, determining access permission information of the terminal device based on second identification information of the target account, comprising: in response to the binding result indicating that the terminal device and the target account are successfully bound, verifying the second identification information to obtain a verification result, wherein the verification result is used to indicate a relationship between the target account and a normal account and an abnormal account; 5. The method of claim 1, wherein, in response to the verification result indicating that the target account is the normal account, determining that the access permission information indicates that the terminal device has permission to request access to the private resource; in response to the verification result indicating that the target account is the abnormal account, determining that the access permission information indicates that the terminal device does not have permission to request access to the private resource.

6. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: in response to the access permission information indicating that the terminal device has permission to request access to the private resource, sending a verification password to a handheld device associated with the target account, wherein the target account is used to access the private resource on the terminal device through the verification password.

7. A device for accessing network resources, characterized in that, The method further comprises: in response to the access permission information indicating that the terminal device does not have permission to request access to the private resource, allowing the terminal device to access a public resource in the network. The method comprises: a receiving unit, configured to, in response to a terminal device's access request for a private resource in a network, receive first identification information of the terminal device, wherein the first identification information is used to identify the terminal device; The first determining unit is configured to determine a binding result between the terminal device and a target account based on the first identification information, wherein the target account is an account used to log in the terminal device, and the binding result is used to indicate whether the terminal device and the target account are successfully bound. The second determining unit is configured to, in response to the binding result indicating that the terminal device and the target account are successfully bound, determine access permission information of the terminal device based on second identification information of the target account, wherein the second identification information is used to identify the target account, and the access permission information is used to indicate whether the terminal device has permission to request access to the private resource.

8. A processor, comprising: The processor is configured to run a program, and the program, when run by the processor, performs the network resource access method in any one of claims 1 to 6.

9. An electronic device, comprising: The computer readable storage medium comprises a stored executable program, and when the executable program is run, the device where the storage medium is located performs the network resource access method in any one of claims 1 to 6. The computer readable storage medium comprises a stored executable program, and when the executable program is run, the device where the storage medium is located performs the network resource access method in any one of claims 1 to 6. ​ 10. A computer-readable storage medium, characterized in that, ​