Terminal network access control method and related device
By implementing authentication and compliance plugin checks within the network security channel, the security issues of Portal authentication and the resource overhead of 802.1x authentication are resolved, thereby improving both security and efficiency.
Patent Information
- Application Number
- CN202410925463.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-10
- Publication Date
- 2026-01-13
AI Technical Summary
In existing technologies, Portal authentication suffers from low data security during transmission, making it susceptible to identity leakage due to over-the-air packet capture. Furthermore, the 802.1x authentication method requires the user terminal to install a client that supports the 802.1x protocol, increasing resource overhead and maintenance costs.
By obtaining terminal identity information through a preset network security channel, verifying identity, and using a compliance plugin for lightweight compliance judgment, the terminal is allowed to access the network only after its security status meets the preset conditions, thus reducing terminal resource consumption and operation and maintenance costs.
It improves network security, reduces the risk of identity leakage, reduces terminal memory consumption and client software maintenance costs, and achieves reliability and efficiency in terminal network access.
Smart Images

Figure CN121333607A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a terminal network access control method and related apparatus. Background Technology
[0002] With the rapid development of network application technologies, network security issues are becoming increasingly prominent. In order to ensure the security of various user terminals and prevent unauthorized users from threatening to intrude into the network, it is necessary to effectively control the network access behavior of user terminals, thereby ensuring the safe operation of enterprise networks.
[0003] Under relevant technologies, the traditional method for addressing network security issues in terminal network access is to ensure the security of user terminals by combining portal authentication with terminal compliance verification processes. Portal authentication forces user terminals to enter a web authentication page when they access any website, verifies the user terminal's identity information (such as account password or verification code), and authorizes the user terminal to access network resources after successful verification, thereby ensuring the security of the network environment.
[0004] However, during the Portal authentication process, the network traffic between the user terminal, the Portal server, and the switch is not encrypted. The data security during transmission is low, and there is a risk of identity leakage due to packet capture over the air interface, which could lead to network attacks.
[0005] Furthermore, port-based network access control protocol authentication (802.1X authentication) establishes a secure channel by mutually verifying the identities of the user terminal and the authentication server. Compared with Portal authentication, it reduces the risk of identity information leakage and is gradually becoming the mainstream terminal network access method.
[0006] However, the current 802.1x authentication method requires the installation of a client that supports the 802.1x protocol on the user terminal in order to facilitate the user terminal to initiate 802.1x authentication and complete the identity verification and compliance verification process. This greatly increases the resource consumption of the user terminal and the maintenance cost of the client. Summary of the Invention
[0007] This application provides a terminal network access control method and related apparatus to improve the security of the network environment.
[0008] In a first aspect, embodiments of this application provide a terminal network access control method, the method comprising:
[0009] The identity information sent by the target terminal is obtained through a preset network security channel, and the target terminal is authenticated.
[0010] After verifying that the identity information has been authenticated, in response to the compliance request triggered by the target terminal based on the preset compliance entry, the current compliance status of the target terminal is determined according to the preset security status information compliance list. The compliance entry is the call link corresponding to the compliance plugin required to determine the compliance status, and the security status information includes at least software information.
[0011] If the target terminal is currently compliant, then the target terminal is allowed to access the target network and is authorized to access all network resources in the target network.
[0012] Optionally, the identity information sent by the target terminal is obtained based on a preset network security channel, and the target terminal is authenticated, including:
[0013] Obtain the validity verification result of the target terminal's digital certificate to the server, and verify the validity of the device digital certificate sent by the target terminal;
[0014] When the validity verification results of both the server digital certificate and the device digital certificate are passed, and the pre-stored historical identity information of the target terminal matches the identity information sent by the target terminal, the identity verification is deemed successful.
[0015] Optionally, after confirming that the identity information has been authenticated, and before responding to the compliance request triggered by the target terminal based on a preset compliance entry point, the following steps are also included:
[0016] If the most recent historical compliance record is compliant, then the current compliance status of the target terminal is directly determined to be compliant;
[0017] If the most recent historical compliance record is non-compliant, or if the target terminal does not have a historical compliance record, an alarm message is sent to the target terminal. The alarm message contains the compliance log and the compliance entry point. The compliance log is used to modify the security status information of the target terminal.
[0018] Optionally, based on a preset list of compliant security status information, the current compliance status of the target terminal is determined, including:
[0019] Obtain multiple compliance items from the security status compliance list, where each compliance item must contain at least the software name of the software to be assessed.
[0020] For each of the multiple compliance items, a compliance judgment is made on the status information corresponding to each compliance item, and the corresponding compliance judgment results and the weight of each compliance judgment result are obtained.
[0021] If the sum of the weights corresponding to the compliance judgment results of multiple compliance items is less than the preset weight threshold, then the current compliance status of the target terminal is determined to be compliant.
[0022] Optional, also includes:
[0023] If authentication fails and / or the target terminal's current compliance status is non-compliant, then the target terminal's access to restricted network resources in the target network will be restricted.
[0024] Optional, also includes:
[0025] During the process of the target terminal accessing network resources, the security status information of the target terminal is dynamically verified for compliance at preset time intervals, and the network resource access permissions of the target terminal in the target network are adjusted according to the dynamic compliance verification results.
[0026] In this embodiment, the server obtains the identity information sent by the target terminal based on a preset network security channel and verifies the identity of the target terminal. After confirming that the identity information has passed the identity verification, in response to the compliance request triggered by the target terminal based on a preset compliance entry, the server determines the current compliance status of the target terminal according to a preset list of compliant security status information. The compliance entry is the call link corresponding to the compliance plugin required to determine the compliance status, and the security status information includes at least software information. If the current compliance status of the target terminal is compliant, the server allows the target terminal to access the target network and authorizes the target terminal to access all network resources in the target network.
[0027] This approach, based on the identity verification of terminals applying for network access, uses a lightweight compliance plugin to make compliance judgments on the security status information of the terminals, ensuring that only terminal devices that meet a certain security level are allowed to access the network. This enhances the reliability of terminal network access verification, reduces network security risks, and, compared to the traditional 802.1x authentication method, reduces terminal memory consumption and client software maintenance costs.
[0028] Secondly, embodiments of this application also provide a terminal network access control device, the device comprising:
[0029] The acquisition module is used to acquire the identity information sent by the target terminal based on a preset network security channel and to authenticate the target terminal.
[0030] The verification module is used to respond to the compliance request triggered by the target terminal based on the preset compliance entry after the identity information has been verified. It determines the current compliance status of the target terminal according to the preset security status information compliance list. The compliance entry is the call link corresponding to the compliance plugin required to determine the compliance status. The security status information includes at least software information.
[0031] The control module is used to allow the target terminal to access the target network and authorize the target terminal to access all network resources in the target network if the target terminal's current compliance status is compliant.
[0032] Optionally, when verifying the identity information sent by the target terminal through a preset network security channel, the verification module is used to:
[0033] Obtain the validity verification result of the target terminal's digital certificate to the server, and verify the validity of the device digital certificate sent by the target terminal;
[0034] When the validity verification results of both the server digital certificate and the device digital certificate are passed, and the pre-stored historical identity information of the target terminal matches the identity information sent by the target terminal, the identity verification is deemed successful.
[0035] Optionally, after confirming that the identity information has passed authentication, and before responding to the compliance request triggered by the target terminal based on a preset compliance entry point, the verification module is used to:
[0036] If the most recent historical compliance record is compliant, then the current compliance status of the target terminal is directly determined to be compliant;
[0037] If the most recent historical compliance record is non-compliant, or if the target terminal does not have a historical compliance record, an alarm message is sent to the target terminal. The alarm message contains the compliance log and the compliance entry point. The compliance log is used to modify the security status information of the target terminal.
[0038] Optionally, when determining the current compliance status of the target terminal based on a preset list of security status information compliance, the verification module is used to:
[0039] Obtain multiple compliance items from the security status compliance list, where each compliance item must contain at least the software name of the software to be assessed.
[0040] For each of the multiple compliance items, a compliance judgment is made on the status information corresponding to each compliance item, and the corresponding compliance judgment results and the weight of each compliance judgment result are obtained.
[0041] If the sum of the weights corresponding to the compliance judgment results of multiple compliance items is less than the preset weight threshold, then the current compliance status of the target terminal is determined to be compliant.
[0042] Optionally, the control module is also used for:
[0043] If authentication fails and / or the target terminal's current compliance status is non-compliant, then the target terminal's access to restricted network resources in the target network will be restricted.
[0044] Optionally, the verification module is also used for:
[0045] During the process of the target terminal accessing network resources, the security status information of the target terminal is dynamically verified for compliance at preset time intervals, and the network resource access permissions of the target terminal in the target network are adjusted according to the dynamic compliance verification results.
[0046] Thirdly, embodiments of this application provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method as described in any of the first aspects.
[0047] Fourthly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of any of the methods described in the first aspect.
[0048] Fifthly, embodiments of this application provide a computer program product that, when invoked by a computer, causes the computer to execute the method described in the first aspect. Attached Figure Description
[0049] Figure 1 This is a schematic diagram illustrating possible application scenarios in the embodiments of this application;
[0050] Figure 2 This is a flowchart of a terminal network access control method according to an embodiment of this application;
[0051] Figure 3 This is a flowchart of an authentication method based on a secure channel, as described in an embodiment of this application.
[0052] Figure 4 This is a flowchart of a security status information compliance verification method according to an embodiment of this application;
[0053] Figure 5 This is a flowchart of a compliance verification method in an embodiment of this application;
[0054] Figure 6 This is an example table of compliance judgment weight assignment in the embodiments of this application;
[0055] Figure 7 This is a flowchart of a terminal network access scenario in an embodiment of this application;
[0056] Figure 8 This is a schematic diagram of the structure of a terminal network access control device according to an embodiment of this application;
[0057] Figure 9 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation
[0058] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this application. Obviously, the described embodiments are only some embodiments of the technical solutions of this application, and not all embodiments. Based on the embodiments recorded in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the technical solutions of this application.
[0059] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in sequences other than those illustrated or described herein.
[0060] The following explanations of some terms used in the embodiments of this application are provided to facilitate understanding by those skilled in the art.
[0061] (1) Authentication server: Its function is to authenticate and authorize users, determine whether the terminal attempting to access the network is legitimate, and specify the network access permissions that a legitimate terminal can have.
[0062] (2) Extensible authentication protocol (EAP): is a layer 2 process that allows the network to authenticate wireless clients.
[0063] (3) Portal authentication: also known as web authentication, it can provide users with identity verification and personalized information services in the form of web pages. The terminal needs to be authenticated through the Portal page before it can access network resources.
[0064] (4) 802.1x authentication: It is a port-level network authentication protocol. Unauthenticated terminals cannot communicate through the network port, which provides strong security.
[0065] (5) Terminal access: The process by which a terminal goes from accessing the network to obtaining network access permissions.
[0066] (6) Terminal compliance: The network administrator formulates compliance policies, and the system performs compliance checks on the terminals according to the policies.
[0067] (7) Identity verification: Verify the legitimacy of the terminal's identity, commonly using methods such as account password authentication, SMS authentication, and facial verification.
[0068] (8) Digital Certificates: Digital certificates provide electronic authentication for secure communication between parties. They are used for identity verification and encryption of electronic information on the Internet, company intranets, or extranets. A digital certificate contains identification information of the key pair (public and private keys), and the authenticity of this information is verified to authenticate the certificate holder's identity.
[0069] The preferred embodiments of this application are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit this application. Furthermore, the embodiments and features in the embodiments of this application can be combined with each other without conflict.
[0070] See Figure 1 As shown, it is a schematic diagram of possible application scenarios in the embodiments of this application.
[0071] This application scenario includes terminal device 110 (including terminal device 1101, terminal device 1102... terminal device 110n) and server 120. Terminal device 110 and server 120 can communicate with each other through a communication network.
[0072] In one alternative implementation, the communication network can be a wired network or a wireless network. Therefore, the terminal device 110 and the server 120 can be connected directly or indirectly via wired or wireless communication. For example, the terminal device 110 can be indirectly connected to the server 120 via a wireless access point, or the terminal device 110 can be directly connected to the server 120 via the Internet; this application does not impose any limitations on this.
[0073] In this application embodiment, the terminal device 110 includes, but is not limited to, mobile phones, tablets, laptops, desktop computers, e-book readers, smart voice interaction devices, smart home appliances, vehicle terminals, and other devices; various clients can be installed on the terminal device, which can be applications that support video preview, video playback, and other functions (such as browsers, game software, etc.), or web pages, mini programs, etc.
[0074] Server 120 is the backend server corresponding to the client installed in terminal device 110. Server 120 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.
[0075] It should be noted that the terminal network access control method in this application embodiment can be executed by an electronic device, which can be a server 120 or a terminal device 110. That is, the method can be executed by the server 120 or the terminal device 110 alone, or by the server 120 and the terminal device 110 together.
[0076] It should be noted that the following text mainly uses the example of the server running alone, and no specific limitations are made here.
[0077] It should be noted that, Figure 1 The examples shown are merely illustrative; in reality, the number of terminal devices 110 and servers 120 is not limited and is not specifically limited in this embodiment.
[0078] In this embodiment of the application, when there are multiple servers 120, the multiple servers 120 can form a blockchain, and each server 120 is a node on the blockchain.
[0079] In traditional technologies, Portal authentication is vulnerable to identity information leakage due to over-the-air packet capture, resulting in low reliability of its security assessment of terminals. On the other hand, client-based 802.1x authentication requires the installation of a specific client on each user terminal, increasing the burden on the user terminal.
[0080] To solve the above technical problems, please refer to Figure 2 As shown in the figure, this application provides a terminal network access control method, which will be described below in conjunction with the appendix. Figure 2 The method flowchart provides a detailed explanation of the specific execution steps:
[0081] Step S201: Obtain the identity information sent by the target terminal based on the preset network security channel, and verify the identity of the target terminal.
[0082] Specifically, in this embodiment of the application, the port on the authentication server enables 802.1x authentication, which forces terminals connected to the port to authenticate themselves and obtain the identity information sent by the target terminal.
[0083] Furthermore, to prevent identity information from being intercepted and tampered with during transmission, the authentication server and the target terminal verify each other's digital certificates, thereby establishing a secure channel.
[0084] For example, see Figure 3 The diagram shown is a flowchart of an authentication method based on a secure channel in an embodiment of this application, specifically including:
[0085] Step S2011: Obtain the validity verification result of the target terminal's digital certificate for the server, and verify the validity of the device digital certificate sent by the target terminal.
[0086] For example, the authentication server sends its own server digital certificate to the target terminal. The target terminal uses the stored server certificate chain to verify the validity of the server certificate. After successful verification, the target terminal informs the authentication server of the verification result.
[0087] Step S2012: When the validity verification results of both the server digital certificate and the device digital certificate are passed, and the pre-stored historical identity information of the target terminal matches the identity information sent by the target terminal, the identity verification is confirmed to be successful.
[0088] For example, the authentication server uses the stored device certificate chain to verify the validity of the device digital certificate. When both the device digital certificate and the server digital certificate pass the validity verification, the security of the channel between the target terminal and the authentication server is determined. Furthermore, if the historical identity information of the target terminal pre-stored by the authentication server matches the identity information sent by the target terminal, the authentication server determines that the identity verification of the target terminal is successful.
[0089] When the authentication server verifies the identity of the target terminal, it may use account password, SMS verification code or facial recognition verification method, or a combination of account password and SMS verification code verification method. This application does not restrict this.
[0090] In addition, when reporting identity information, the target terminal can also use methods such as asymmetric keys to encrypt the identity information, further ensuring data security.
[0091] Step S202: After confirming that the identity information has been verified, in response to the compliance request triggered by the target terminal based on the preset compliance entry, determine the current compliance status of the target terminal according to the preset security status information compliance list.
[0092] The compliance entry point is the call link corresponding to the compliance plugin required to determine the compliance status, and the security status information includes at least software information.
[0093] Specifically, in this embodiment of the application, in order to prevent the target terminal from having malicious programs on its local machine that could threaten the network environment after the target terminal enters the network, the authentication server will also perform compliance verification on the security status information of the target terminal after authenticating the target terminal.
[0094] Before responding to a compliance request triggered by the target terminal based on a preset compliance entry, the server first determines whether the target terminal has a historical compliance record.
[0095] See Figure 4The diagram shown is a flowchart of a security status information compliance verification method according to an embodiment of this application. Regarding whether the target terminal has historical compliance records and whether the most recent historical compliance record is compliant, the server includes two specific scenarios, A and B, when executing the compliance verification process:
[0096] Step S2021A: If the most recent historical compliance record is compliant, then directly determine the current compliance status of the target terminal as compliant.
[0097] In one optional embodiment, for a target terminal with a historical compliance record, when the most recent historical compliance record is compliant, the authentication server will directly determine that the current compliance status of the target terminal is compliant. This can improve the compliance verification speed and enable the target terminal to quickly access the target network.
[0098] Step S2021B: If the most recent historical compliance record is non-compliant, or if the target terminal does not have a historical compliance record, then send an alarm message to the target terminal.
[0099] The alarm information includes compliance logs and compliance entry points. The compliance logs are used to modify the security status information of the target terminal.
[0100] If a historical compliance record exists but the most recent historical compliance record is non-compliant, the authentication server directly determines that the target terminal's current compliance record is non-compliant and sends an alarm message to the target terminal.
[0101] In another optional embodiment, when the target terminal has no historical compliance record, it indicates that the target terminal is requesting access to the target network for the first time. At this time, the authentication server directly determines the current security status information of the target terminal as non-compliant and sends an alarm message carrying the compliance entry to the target terminal, so that the target terminal can actively enter the compliance process based on the compliance entry.
[0102] Specifically, when the target terminal first enters the compliance process through the compliance portal, it will download a dedicated compliance plugin locally and complete the compliance verification by running the compliance plugin.
[0103] In this way, compared with the traditional 802.1x authentication method that combines the client, this application does not require the installation of specific client software locally, which can reduce the memory consumption of the terminal and reduce the maintenance cost of the client software.
[0104] Optionally, the compliance plugin can also be configured on the authentication server, with the compliance entry point designed as a link to remotely call the compliance plugin. This eliminates the need to save and run the compliance plugin locally on the terminal, further reducing the terminal's memory resource consumption.
[0105] Step S2022B: In response to the compliance request triggered by the target terminal based on the compliance entry, determine the current compliance status of the target terminal according to the preset security status information compliance list.
[0106] Furthermore, in this embodiment of the application, after the target terminal enters the compliance process through the compliance portal, the authentication server or the terminal runs a compliance plugin locally, and performs compliance verification on the target terminal in conjunction with the compliance list of security status information.
[0107] See Figure 5 As shown, it is a flowchart of a compliance verification method in an embodiment of this application, which specifically includes:
[0108] Step S501: Obtain multiple compliance items from the security status information compliance list.
[0109] Among these, several compliance items include at least the software name of the software to be assessed.
[0110] It should be noted that the security status information compliance list in this application embodiment is a security status information blacklist or whitelist. In addition, the server may also set only a security status information whitelist or a security status information blacklist as the security status information compliance list, and this application does not restrict this.
[0111] Specifically, the authentication server presets a blacklist and whitelist of security status information for terminals requesting network access, which includes multiple compliance items. In this embodiment, the multiple compliance items include at least the name of the software to be judged.
[0112] For example, the security status information blacklist includes several compliance items: the names of software that the target terminal cannot install, while the security status information whitelist includes several compliance items: the names of software that the target terminal must install.
[0113] In one alternative embodiment, the compliance items may further include the target terminal's Internet Protocol Address (IP address) and Media Access Control Address (MAC address), which are not limited in this application.
[0114] For example, when IP addresses are included in compliance items, if a company's internal LAN stipulates that only terminals with IP addresses in the range of 192.168.1.2 to 192.168.2.254 are allowed to access the network, then terminals with IP addresses outside this range will be deemed non-compliant and will not be able to access the company's internal LAN. The same applies to MAC addresses.
[0115] Step S502: Perform compliance judgments on the status information corresponding to each of the multiple compliance items to obtain the corresponding compliance judgment results and the weight of each compliance judgment result.
[0116] In this embodiment of the application, the authentication server first determines whether the target terminal has installed any software that cannot be installed or must be installed as recorded in the security status information blacklist and whitelist. If the target terminal has installed any software in the blacklist or has not installed any software in the whitelist, the server immediately determines that the compliance status of the target terminal is non-compliant.
[0117] For example, when the target terminal has installed software corresponding to a compliance item in the blacklist, the weight of the compliance judgment result of that compliance item can be set to infinitely large. In this case, to save time, the compliance verification process can be terminated immediately. The same applies to the whitelist.
[0118] When the software installed on the target terminal meets the requirements of the blacklist and whitelist, the authentication server further performs a compliance judgment on the status information corresponding to the software in the whitelist, and obtains the weight corresponding to the compliance judgment result.
[0119] For example, see Figure 6 As shown, it is an example table of compliance judgment weight assignment in an embodiment of this application. In this table, the authentication server checks the current status of a software to obtain a status code. Each status code corresponds to an abnormal situation, and each abnormal situation has a preset weight.
[0120] Step S503: If the sum of the weights corresponding to the compliance judgment results of multiple compliance items is less than the preset weight threshold, then the current compliance status of the target terminal is determined to be compliant.
[0121] Furthermore, after obtaining the compliance judgment results of all software and their corresponding weights, the certification server calculates the weight sum and compares it with the preset weight threshold. If the weight sum is less than the weight threshold, the current compliance status of the target terminal is determined to be compliant.
[0122] For example, suppose the security status information blacklist and whitelist contain three compliance items, and the status codes corresponding to the three compliance items are 500, 200, and 504, respectively. Figure 6 It can be seen that the sum of the weights corresponding to the compliance judgment results of the three compliance items is 102. If the preset weight threshold is 100, and the sum of the weights is greater than the weight threshold, then the current compliance status of the target terminal is determined to be non-compliant.
[0123] For example, suppose the status codes corresponding to the three compliance items mentioned above are 500, 501, and 504, respectively. Figure 6It can be seen that the sum of the weights corresponding to the three compliance items and the compliance judgment result is 3. If the sum of the weights is less than the weight threshold, then the current compliance status of the target terminal is determined to be compliant.
[0124] Furthermore, in practical applications, the authentication server can directly use status codes to represent the compliance judgment results of compliance items, or it can use status codes in combination with other parameters to accurately classify the compliance judgment results and adjust the corresponding weights according to the actual situation. This application does not impose any restrictions on this.
[0125] In another alternative embodiment, if the sum of the weights is greater than or equal to the weight threshold, the current compliance status of the target terminal is determined to be non-compliant.
[0126] The weighting threshold is determined by relevant personnel based on the actual situation, and this application does not impose any restrictions on it.
[0127] It should be noted that the compliance process in this application embodiment is a visual interface. Users can change the software information and other security status information of the target terminal at any time based on the current compliance page, thereby ensuring that the target terminal can successfully pass the compliance verification.
[0128] In addition, when the target terminal's current compliance status is non-compliant, the authentication server will send an alarm message to the target terminal. At this time, the alarm message carries a compliance log. Users can modify the security status information of the target terminal based on the compliance log and re-enter the compliance process based on the compliance entry point carried in the first alarm message.
[0129] Optionally, the authentication server can include the compliance entry only in the first alarm message to reduce data redundancy, or it can include the compliance entry in every alarm message to deal with situations where the compliance entry is updated or lost.
[0130] Based on step S503, the final compliance status of the target terminal is determined by summing the weights of the compliance judgment results of each compliance item. Compared with the traditional method that determines the compliance status of the target terminal to be non-compliant as long as there is one non-compliant item, the method provided in this application can avoid the problem of misjudging the status of some compliance items, which would lead to the target terminal being judged as non-compliant.
[0131] Step S203: If the target terminal is currently compliant, then allow the target terminal to access the target network and authorize the target terminal to access all network resources in the target network.
[0132] Specifically, in this embodiment of the application, when the target terminal is verified and its compliance status is determined to be compliant, the authentication server will allow the target terminal to access the target network and authorize the target terminal to access all network resources in the target network.
[0133] In another alternative embodiment, if the authentication and / or the target terminal's current compliance status is non-compliant, the authentication server controls the target terminal's access to restricted network resources in the target network.
[0134] In this application embodiment, all network resources refer to the sum of various information resources that can be utilized with the help of the network environment, and the restricted network resources are the target terminal's local data and some websites allowed by the authentication server.
[0135] Furthermore, in this embodiment of the application, during the process of the target terminal accessing network resources, the authentication server will also perform dynamic compliance verification on the security status information of the target terminal at preset time intervals, and adjust the network resource access permissions of the target terminal in the target network according to the dynamic compliance verification results.
[0136] For example, every half hour, the authentication server sequentially traverses multiple terminals on the access port and performs dynamic compliance verification on the multiple terminals. If the security status information of a terminal does not meet the prescribed security level, its access to network resources is immediately restricted. In this embodiment, the security level is divided into only two levels: secure and insecure. Compliance is secure, and non-compliance is insecure. In addition, multiple security levels can be divided based on the sum of the weights corresponding to the compliance judgment results of each compliance item of the terminal, so as to perform fine-grained control over the terminal's network access permission and provide visual warnings to users. This application does not limit this.
[0137] It should be noted that in this embodiment of the application, when the authentication server adjusts the target terminal's access permissions to network resources, it needs to first kick the target terminal out of the target network, that is, cut off the connection between the target terminal and the target network, and then allow the target terminal to reconnect and obtain new access permissions. When the target terminal reconnects to the network, there is no need to prompt the user to re-enter identity information for identity verification. The process is seamless for the user to reconnect to the network.
[0138] The above embodiments will be further described in detail below using a specific application scenario.
[0139] See Figure 7 As shown, it is a flowchart of a terminal network access scenario in an embodiment of this application, wherein:
[0140] Step S701: The user terminal requests network access.
[0141] Step S702: A pop-up 802.1x authentication account and password input box appears.
[0142] Step S703: Enter your account and password.
[0143] Step S704: Determine if the account password is correct. If yes, proceed to step S705; otherwise, return to step S703.
[0144] Step S705: Verify whether the security status information is compliant. If yes, proceed to step S706; otherwise, proceed to step S707.
[0145] Step S706: Allow the user's terminal to access all network resources.
[0146] Step S707: Control the user terminal's access to restricted network resources and send an alarm message carrying the compliance entry point.
[0147] Step S708: Click the compliance entry to enter the compliance process and return to step S705.
[0148] In summary, this embodiment employs a dual authentication method of identity verification and compliance verification to control terminal network access, thereby improving network security. Furthermore, the use of a compliance plugin for terminal compliance verification enables users to perform self-service through a compliance entry point. Compared to the traditional 802.1x authentication method using client software, this reduces local terminal resource consumption and client software maintenance costs. Additionally, dynamic compliance verification of terminal security status information at preset time intervals allows for dynamic adjustment of access permissions for terminals already connected to the network, further enhancing network security.
[0149] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0150] Based on the same technical concept, see [reference] Figure 8 As shown in the figure, this application embodiment also provides a terminal network access control device, which includes:
[0151] The acquisition module 801 is used to acquire the identity information sent by the target terminal based on a preset network security channel and to authenticate the target terminal.
[0152] The verification module 802 is used to determine the current compliance status of the target terminal in response to a compliance request triggered by the target terminal based on a preset compliance entry after the identity information has been verified. The compliance entry is the call link corresponding to the compliance plugin required to determine the compliance status, and the security status information includes at least software information.
[0153] The control module 803 is used to allow the target terminal to access the target network and authorize the target terminal to access all network resources in the target network if the current compliance status of the target terminal is compliant.
[0154] Optionally, when verifying the identity information sent by the target terminal based on a preset network security channel, the verification module 802 is used for:
[0155] Obtain the validity verification result of the target terminal's digital certificate to the server, and verify the validity of the device digital certificate sent by the target terminal;
[0156] When the validity verification results of both the server digital certificate and the device digital certificate are passed, and the pre-stored historical identity information of the target terminal matches the identity information sent by the target terminal, the identity verification is deemed successful.
[0157] Optionally, after confirming that the identity information has passed authentication, and before responding to the compliance request triggered by the target terminal based on a preset compliance entry, the verification module 802 is used to:
[0158] If the most recent historical compliance record is compliant, then the current compliance status of the target terminal is directly determined to be compliant;
[0159] If the most recent historical compliance record is non-compliant, or if the target terminal does not have a historical compliance record, an alarm message is sent to the target terminal. The alarm message contains the compliance log and the compliance entry point. The compliance log is used to modify the security status information of the target terminal.
[0160] Optionally, when determining the current compliance status of the target terminal based on a preset list of security status information compliance, the verification module 802 is used to:
[0161] Obtain multiple compliance items from the security status compliance list, where each compliance item must contain at least the software name of the software to be assessed.
[0162] For each of the multiple compliance items, a compliance judgment is made on the status information corresponding to each compliance item, and the corresponding compliance judgment results and the weight of each compliance judgment result are obtained.
[0163] If the sum of the weights corresponding to the compliance judgment results of multiple compliance items is less than the preset weight threshold, then the current compliance status of the target terminal is determined to be compliant.
[0164] Optionally, the control module 803 is also used for:
[0165] If authentication fails and / or the target terminal's current compliance status is non-compliant, then the target terminal's access to restricted network resources in the target network will be restricted.
[0166] Optionally, the verification module 802 is also used for:
[0167] During the process of the target terminal accessing network resources, the security status information of the target terminal is dynamically verified for compliance at preset time intervals, and the network resource access permissions of the target terminal in the target network are adjusted according to the dynamic compliance verification results.
[0168] Based on the same technical concept, this application also provides an electronic device that can implement the terminal network access control method provided in the above embodiments of this application.
[0169] In one embodiment, the electronic device may be a server, a terminal device, or other electronic devices.
[0170] See Figure 9 As shown, the electronic device may include:
[0171] At least one processor 901 and a memory 902 connected to at least one processor 901. In this embodiment, the specific connection medium between the processor 901 and the memory 902 is not limited. Figure 9 The example shown is the connection between processor 901 and memory 902 via bus 900. Bus 900 is... Figure 9 The connections between other components are indicated by thick lines and are for illustrative purposes only, not as limiting information. The Bus 900 can be divided into address bus, data bus, control bus, etc., for ease of representation. Figure 9 The term is represented by a single thick line, but this does not imply that there is only one bus or one type of bus. Alternatively, the processor 901 can also be called a controller; there is no restriction on the name.
[0172] In this embodiment, the memory 902 stores instructions executable by at least one processor 901. By executing the instructions stored in the memory 902, the at least one processor 901 can execute a terminal network access control method described above. The processor 901 can implement... Figure 8 The functions of each module in the device shown.
[0173] The processor 901 is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory 902 and calling data stored in memory 902, the processor can perform various functions and process data, thereby monitoring the device as a whole.
[0174] In one possible design, processor 901 may include one or more processing units. Processor 901 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may also not be integrated into processor 901. In some embodiments, processor 901 and memory 902 may be implemented on the same chip; in some embodiments, they may also be implemented on separate chips.
[0175] The processor 901 can be a general-purpose processor, such as a CPU, digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the terminal network access control method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or being executed by a combination of hardware and software modules within the processor.
[0176] Memory 902, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 902 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memory, magnetic disk, optical disk, etc. Memory 902 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 902 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.
[0177] By designing and programming the processor 901, the code corresponding to the terminal network access control method described in the foregoing embodiments can be embedded into the chip, thereby enabling the chip to execute the code during operation. Figure 2 The illustrated embodiment presents the steps of a terminal network access control method. How to design and program the processor 901 is a technique well-known to those skilled in the art and will not be described further here.
[0178] Based on the same inventive concept, embodiments of this application also provide a storage medium storing computer instructions that, when executed on a computer, cause the computer to perform a terminal network access control method described above.
[0179] In some possible implementations, various aspects of the terminal network access control method provided in this application can also be implemented in the form of a program product, which includes program code. When the program product is run on a device, the program code is used to cause the control device to perform the steps in the terminal network access control method according to various exemplary embodiments of this application described above.
[0180] It should be noted that although several units or sub-units of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.
[0181] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0182] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0183] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0184] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0185] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0186] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A terminal network access control method, characterized in that, include: The identity information sent by the target terminal is obtained based on a preset network security channel, and the target terminal is authenticated. After confirming that the identity information has been verified, in response to the compliance request triggered by the target terminal based on the preset compliance entry, the current compliance status of the target terminal is determined according to the preset security status information compliance list. The compliance entry is the call link corresponding to the compliance plugin required to determine the compliance status, and the security status information includes at least software information. If the target terminal is currently compliant, then the target terminal is allowed to access the target network and is authorized to access all network resources in the target network.
2. The method as described in claim 1, characterized in that, The step of obtaining the identity information sent by the target terminal based on a preset network security channel and authenticating the target terminal includes: Obtain the validity verification result of the target terminal's digital certificate to the server, and verify the validity of the device digital certificate sent by the target terminal; When the validity verification results of the server digital certificate and the device digital certificate are both passed, and the pre-stored historical identity information of the target terminal matches the identity information sent by the target terminal, the identity verification is determined to be successful.
3. The method as described in claim 1, characterized in that, The step, after determining that the identity information has passed authentication and before responding to the compliance request triggered by the target terminal based on a preset compliance entry, further includes: If the most recent historical compliance record is compliant, then the current compliance status of the target terminal is directly determined to be compliant; If the most recent historical compliance record is non-compliant, or if the target terminal does not have a historical compliance record, an alarm message is sent to the target terminal. The alarm message includes a compliance log and the compliance entry point. The compliance log is used to modify the security status information of the target terminal.
4. The method as described in claim 1, characterized in that, The determination of the current compliance status of the target terminal based on a preset compliance list of security status information includes: Obtain multiple compliance items from the security status information compliance list, wherein the multiple compliance items at least include the software name of the software to be judged; For each of the multiple compliance items, a compliance judgment is made on the status information corresponding to each compliance item, and the corresponding compliance judgment result and the weight of each compliance judgment result are obtained. If the sum of the weights corresponding to the compliance judgment results of multiple compliance items is less than a preset weight threshold, then the current compliance status of the target terminal is determined to be compliant.
5. The method according to any one of claims 1-4, characterized in that, Also includes: If the authentication fails and / or the target terminal's current compliance status is non-compliant, then the target terminal's access to restricted network resources in the target network is controlled.
6. The method according to any one of claims 1-4, characterized in that, Also includes: During the process of the target terminal accessing network resources, the security status information of the target terminal is dynamically verified for compliance at preset time intervals, and the network resource access permissions of the target terminal in the target network are adjusted according to the dynamic compliance verification results.
7. A terminal network access control device, characterized in that, include: The acquisition module is used to acquire the identity information sent by the target terminal based on a preset network security channel, and to authenticate the target terminal. The verification module is used to, after determining that the identity information has been verified, respond to the compliance request triggered by the target terminal based on a preset compliance entry, and determine the current compliance status of the target terminal according to a preset security status information compliance list. The compliance entry is the call link corresponding to the compliance plugin required to determine the compliance status, and the security status information includes at least software information. The control module is configured to allow the target terminal to access the target network and authorize the target terminal to access all network resources in the target network if the target terminal's current compliance status is compliant.
8. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method as described in any one of claims 1-6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1-6.
10. A computer program product, characterized in that, When the computer program product is invoked by a computer, it causes the computer to perform the method as described in any one of claims 1-6.