A method, system, device, and equipment for protecting device access based on a switch.

By installing network port locks and smart network port locks on switches and terminal devices, combined with device fingerprint monitoring, the problem of insufficient physical security during the access process of switch terminal devices is solved, realizing dual protection and remote management, and improving the security and convenience of access.

CN121530760BActive Publication Date: 2026-05-05HANGZHOU RUISHENGBO TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HANGZHOU RUISHENGBO TECH CO LTD
Filing Date
2026-01-15
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

In existing technologies, switches lack physical security protection during the access process of terminal devices, resulting in insufficient access efficiency, security and convenience, and making it difficult to achieve remote control and precise management.

Method used

By installing network port locks on the switch side and smart network port locks on the terminal devices, combined with device fingerprint monitoring, dual physical and logical protection is achieved. The status of the network port locks can be remotely controlled by the server, and abnormal device access can be judged by analyzing traffic data.

Benefits of technology

It improves the security and convenience of terminal device access, enhances physical security, and enables remote and precise control and management, significantly improving both convenience and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530760B_ABST
    Figure CN121530760B_ABST
Patent Text Reader

Abstract

This application relates to the field of network communication and discloses a method, system, device, and equipment for protecting device access based on a switch. The method includes: responding to a network port unlocking command issued by a server, switching a designated network port lock to an unlocked state and connecting a target device to the designated network port (the target device is equipped with a smart network port lock); responding to a network port locking command issued by the server, switching the designated network port lock to a locked state and continuously monitoring the traffic data of the designated network port, extracting a device fingerprint from the traffic data, and determining whether there is an abnormal device access based on the device fingerprint; if an abnormal device access is determined, obtaining the first state information of the designated network port lock and the second state information of the smart network port lock to determine the abnormal information of the target device. The technical solution provided by this application achieves dual physical and logical protection for network access, thereby improving the security and convenience of terminal devices when accessing the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication, and in particular to a method, system, device and equipment for protecting device access based on a switch. Background Technology

[0002] In current cybersecurity management practices, the security of intranet access in critical sectors such as finance and energy mainly relies on logical-level protection measures such as identity authentication and access control lists. Access protection is achieved by verifying the identity information, IP address, or compliance status of access devices.

[0003] However, in terms of actual deployment and security management, these logical management methods have obvious limitations, especially in terms of physical security. Furthermore, switches have difficulty in providing remote access protection for terminal devices, resulting in insufficient protection efficiency, security, and convenience for switches and terminal devices during the access process.

[0004] Therefore, improving the security and convenience of terminal devices when accessing the network has become an urgent technical problem to be solved in the current network security construction. Summary of the Invention

[0005] This application provides a switch-based device access protection method, system, device, and equipment, which can achieve both physical and logical protection for network access, thereby improving the security and convenience of terminal devices when accessing the network.

[0006] This application provides a device access protection method based on a switch, the method being applied to the switch, the method comprising: responding to a network port unlocking command issued by a server, switching a designated network port lock to an unlocked state, and connecting a target device to the designated network port, wherein the designated network port lock is installed on the designated network port, and the target device is equipped with a smart network port lock; responding to a network port locking command issued by the server, switching the designated network port lock to a locked state, and continuously monitoring the traffic data of the designated network port, extracting a device fingerprint from the traffic data, and determining whether there is a device access anomaly based on the device fingerprint; if a device access anomaly is determined to exist, obtaining first state information of the designated network port lock and second state information of the smart network port lock, and determining the anomaly information of the target device based on the first state information and the second state information.

[0007] In one embodiment, before responding to the network port unlocking command issued by the server, the method further includes: in the power-on state, setting all network ports to a locked state and sending a registration request to the server, wherein the registration request carries the device identifier of the switch, the number of network ports, and the network port locking state; in response to the registration request, establishing a communication link with the server, wherein the server has a generated network port unlocking command, the network port unlocking command carrying the device identifier of the target device, the device identifier of the switch, and a specified network port number.

[0008] In one embodiment, the smart network port lock is used to switch to a locked state after the target device is connected; after the target device is connected to the designated network port, the method further includes: receiving the status information of the target device and reporting the status information to the server, wherein the status information represents the locking state of the smart network port lock; receiving a network port locking command fed back by the server, wherein the network port locking command is generated by the server after confirming the status information.

[0009] In one embodiment, the switch includes a PoE power supply module; after the target device is connected to a designated network port, the method further includes: the PoE power supply module supplies power to the target device through the designated network port, so that after the target device is connected to power, the automatic reporting function of the smart network port lock is activated, so as to report the locking status of the smart network port lock to the switch.

[0010] In one embodiment, determining whether there is a device access anomaly based on the device fingerprint includes: comparing the fingerprint information of the target device obtained in advance with the device fingerprint, wherein the fingerprint information represents fixed information of the target terminal device; if the fingerprint information is consistent with the device fingerprint, it is determined that there is no device access anomaly, and if the fingerprint information is inconsistent with the device fingerprint, it is determined that there is a device access anomaly.

[0011] In one embodiment, the fingerprint information of the target device is obtained in the following manner: after the target device is connected to a designated network port, the protocol data of the target device is obtained through traffic mirroring, and the fingerprint information is extracted from the protocol data. The protocol data represents the network protocol generated by the target device during the access process, and the fingerprint information includes the protocol type, device communication address, and device fixed information.

[0012] In one implementation, determining the abnormal information of the target device based on the first state information and the second state information includes: if both the first state information and the second state information represent a locked state, then it is determined to be a physical intrusion abnormality; if either the first state information or the second state information represents an unlocked state, then it is determined to be a permission change pending verification.

[0013] A second aspect of this application provides a device access protection system based on a switch. The system includes: a server, configured to configure and issue network port unlocking and locking commands, store and compare device fingerprints, receive status information, and perform anomaly analysis based on the device fingerprints and the status information; a smart network port lock, configured to communicate with the switch via a network cable, monitor and report its own status information; and a switch, configured to, in response to the network port unlocking command issued by the server, switch a designated network port lock to an unlocked state and connect a target device to the designated network port, wherein the designated network port lock is installed on the designated network port and the target device is equipped with a smart network port lock; in response to the network port locking command issued by the server, switch the designated network port lock to a locked state, continuously monitor the traffic data of the designated network port, extract device fingerprints from the traffic data, and determine whether there is a device access anomaly based on the device fingerprints; if a device access anomaly is determined, obtain first status information of the designated network port lock and second status information of the smart network port lock, and determine the anomaly information of the target device based on the first status information and the second status information.

[0014] A third aspect of this application provides a switch-based device access protection device, comprising: a device access unit, configured to, in response to a network port unlocking command issued by a server, switch a designated network port lock to an unlocked state and connect a target device to the designated network port, wherein the designated network port lock is installed on the designated network port and the target device is equipped with a smart network port lock; a traffic monitoring unit, configured to, in response to a network port locking command issued by the server, switch the designated network port lock to a locked state and continuously monitor the traffic data of the designated network port, extract a device fingerprint from the traffic data, and determine whether there is a device access anomaly based on the device fingerprint; and an anomaly determination unit, configured to, if a device access anomaly is determined to exist, acquire first state information of the designated network port lock and second state information of the smart network port lock, and determine the anomaly information of the target device based on the first state information and the second state information.

[0015] A fourth aspect of this application provides a computer device, including: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to perform a switch-based device access protection method as described in the first aspect above.

[0016] The technical solution provided in one or more embodiments of this application achieves dual physical and logical protection for network access by installing a network port lock on the switch side and a smart network port lock on the terminal device side. Specifically, the dual locking mechanism of the network port lock and the smart network port lock effectively prevents unauthorized devices from accessing or replacing legitimate devices, enhancing the physical security of network access. The server can remotely issue commands to control the network port lock status of the switch, enabling flexible management of network access and improving the efficiency of network access implementation. In addition, the smart network port lock can report its status information in real time, and the server can monitor these statuses in real time, promptly detecting anomalies and improving the real-time performance and accuracy of security monitoring. After a device is connected, the switch can extract the device's fingerprint information through traffic data to further verify the device's identity, preventing the device from being replaced or tampered with, thereby improving the access security and reliability of terminal devices. Simultaneously, it also improves the convenience of connection and management for both the switch and terminal devices.

[0017] As can be seen, the technical solution provided in this application can improve the access security and reliability of terminal devices. At the same time, it can also improve the convenience of accessing and managing switches and terminal devices. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in the specific embodiments of this application or the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0019] Figure 1 A schematic diagram illustrating a network access scenario for the related technologies provided in the embodiments of this application;

[0020] Figure 2 A schematic diagram illustrating the steps of a switch-based device access protection method provided in one embodiment of this application;

[0021] Figure 3 A flowchart illustrating a device access protection method based on a switch, provided as an embodiment of this application;

[0022] Figure 4This application provides a schematic diagram of the structure of a switch-based device access protection system according to one embodiment;

[0023] Figure 5 A schematic diagram of a switch-based device access protection device provided in one embodiment of this application;

[0024] Figure 6 This is a schematic diagram of the structure of a computer device provided in one embodiment of this application. Detailed Implementation

[0025] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0026] Furthermore, the use of terms such as "first," "second," etc., in this application is for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of embodiments in this application, unless otherwise stated, "multiple" means two or more. Additionally, the use of "based on" or "according to" implies openness and inclusiveness, because processes, steps, calculations, or other actions "based on" or "according to" one or more of the stated conditions or values ​​may in practice be based on additional conditions or beyond the stated values.

[0027] Please see Figure 1 This application provides an example of a network access scenario in related technologies. By installing a passive network port lock on the switch side, the switch and multiple terminal devices are physically locked, preventing other terminal devices from accessing the private network. Response software is installed on the terminal devices to report the fingerprint information of the terminal devices to the backend, thus determining whether the terminal connected to the switch port has been changed. However, the passive network port lock relies entirely on mechanical structure design, which can easily lead to insufficient protection efficiency, security, and convenience for terminal device access in actual deployment and security management.

[0028] In this embodiment, traditional network access methods are not suitable for device access and protection in large-scale networks. The deployment cycle for installing port locks on each network port of a switch is lengthy, and when access devices malfunction or experience abnormalities, maintenance personnel cannot respond and assess the situation remotely, requiring them to carry dedicated unlocking equipment for on-site unlocking, resulting in poor convenience for device intervention and protection. Furthermore, device replacement detection relies on the fingerprint response of the terminal device software, but many dumb terminal devices cannot install such software due to system closures or hardware resource limitations, leading to poor compatibility and security of device access protection.

[0029] In terms of practical deployment and security management, the logical control methods in related technologies have significant limitations. Traditional switch port management suffers from poor flexibility and security. On the one hand, it cannot effectively prevent unauthorized access through physical contact, such as attackers directly connecting illegal devices using idle ports. On the other hand, existing detection mechanisms lack the ability to identify changes in device identity, lacking both effective device fingerprinting methods and the ability to collaboratively analyze physical status information with logical detection results. Furthermore, traditional switch ports cannot achieve remote and precise control, while terminal-side status monitoring is limited by power supply and communication capabilities, resulting in problems such as delayed response and inaccurate judgments in the entire security protection system.

[0030] In view of this, one or more embodiments of this application provide a device access protection method, system, device and equipment based on a switch, which can solve the above problems. By coordinating the physical locking of the switch network port and the intelligent network port lock of the terminal, combined with real-time monitoring of device fingerprints, dual protection from the physical layer to the logical layer is achieved. While significantly improving the security of private network device access, it also greatly improves the convenience of management through remote and precise control.

[0031] Please see Figure 2 One embodiment of this application provides a device access protection method based on a switch. The method is applied to the switch and may include the following steps:

[0032] S1: In response to the network port unlocking command issued by the server, the specified network port lock is switched to the unlocked state, and the target device is connected to the specified network port. The specified network port lock is installed on the specified network port, and the target device is equipped with a smart network port lock. The smart network port lock is used to switch to the locked state after the target device is connected to the specified network port.

[0033] S3: In response to the network port locking command issued by the server, switch the specified network port lock to the locked state, continuously monitor the traffic data of the specified network port, extract the device fingerprint from the traffic data, and determine whether there is a device access anomaly based on the device fingerprint;

[0034] S5: If it is determined that there is a device access anomaly, obtain the first status information of the specified network port lock and the second status information of the smart network port lock, and determine the anomaly information of the target device based on the first status information and the second status information.

[0035] The aforementioned network port unlocking command is used to instruct the switch to unlock the designated network port of the terminal device to be connected. Specifically, the administrator initiates a terminal access request in the server backend, specifying the device information of the terminal to be connected, the target switch, and the network port number. After approval, a network port unlocking command is sent to the designated switch. In response to the network port unlocking command, the designated network port lock deployed on the designated network port is unlocked, switching the designated network port lock to the unlocked state. Optionally, a network port unlocking time limit can be set. Further, maintenance personnel connect the network cable of the target device to the unlocked designated network port. The aforementioned target device can be understood as the terminal device to be connected. Further, after the target device successfully connects, the aforementioned smart network port lock switches to the locked state, and in response to the network port lock command, the switch also switches the designated network port lock to the locked state, indicating that the device connection is complete.

[0036] In this embodiment, each network port of the switch is equipped with a network port lock to control the physical access status of the port. The aforementioned smart network port lock is installed on the target device to further enhance the security of device access. The server sends commands to control the network port lock status on the switch side, combining this with the smart network port lock on the terminal side for dual locking, preventing the device from being unplugged or a new device from being connected. This strengthens the physical protection of network access. Furthermore, by remotely sending network port unlocking and locking commands from the server, the network port lock status of both the switch and the target device can be controlled, enabling flexible management of network access and thus improving the security and convenience of terminal devices accessing the network.

[0037] The aforementioned traffic data can be understood as all data packets transmitted in the network, containing information about various network communication protocols, such as TCP (Transmission Control Protocol) / IP (Internet Protocol), UDP (User Datagram Protocol), LLDP (Link Layer Discovery Protocol), DHCP (Dynamic Host Configuration Protocol), and SNMP (Simple Network Management Protocol). This traffic data is used to enable communication between switches and terminal devices. The aforementioned device fingerprint can be understood as unique identification information bound to a device extracted by analyzing specific protocol fields in network traffic data. This can include the device's hardware characteristics, software characteristics, and network configuration, used to uniquely identify and verify the identity of the target device.

[0038] In this embodiment, all traffic data transmitted through the network port is continuously monitored, and device fingerprints are extracted from the traffic data for identity verification. Specifically, the switch continuously monitors the network port's traffic data, and by parsing the protocol fields in the traffic data, extracts the currently bound, unchanging information as the device fingerprint. This allows for real-time detection of changes in the device fingerprint and timely detection of abnormal device access. Optionally, the real-time extracted device fingerprint can be compared with a pre-stored baseline fingerprint, and the comparison result can be used to determine whether there is an abnormal device access. Optionally, the device fingerprints at adjacent time points can also be compared in real time to determine whether there is an abnormal device access. For example, the above-mentioned abnormal device access situations can include unauthorized device access, device replacement, device configuration tampering, etc. Detecting these anomalies can improve network security and reliability.

[0039] The first state information described above represents the state information of the designated network port lock on the switch side, including the unlocked or locked state of the designated network port lock. The second state information described above represents the state information of the smart network port lock on the terminal device side, including the unlocked or locked state of the smart network port lock. By combining the physical locking state of the designated network port on the switch side and the physical locking state on the target device side, the specific cause of the device access anomaly can be further determined, and the specific anomaly type can be identified, that is, the anomaly information of the target device can be determined. Based on the anomaly type represented by the anomaly information, corresponding security measures can be taken, such as alarms and device blocking. This achieves accurate judgment and handling of device access anomalies, improving the accuracy of anomaly detection and management efficiency.

[0040] For example, the anomaly types represented by the above-mentioned abnormal information may include physical intrusion anomalies, pending verification of permission changes, normal device replacement, device maintenance, device malfunction, and false alarm handling. For instance, if both the first and second state information indicate a locked state, but the device fingerprint changes, it indicates that someone replaced the device without authorization, which is a physical intrusion anomaly. For instance, if both the first and second state information indicate an unlocked state, and the device fingerprint changes, it indicates that the device replacement may have been authorized (such as maintenance or device update), which is a normal device replacement. For instance, if the first state information indicates an unlocked state and the second state information indicates a locked state, but the device fingerprint does not change, it indicates that the device may be undergoing maintenance, which is a device maintenance issue.

[0041] Based on the above ideas, the technical solution provided in this embodiment of the application achieves physical protection of the switch's network ports, device identity monitoring, and anomaly alarms through the collaboration of servers, switches, and terminal devices. Specifically, a dual locking mechanism of network port locks and smart network port locks prevents unauthorized devices from accessing or replacing legitimate devices, enhancing the physical security of network access. The server can remotely issue commands to control the switch's network port lock status, enabling flexible management of network access and improving the efficiency of network access implementation. Furthermore, the smart network port lock can report its status information (such as unlocked or locked status) in real time, allowing the server to monitor these statuses and promptly detect anomalies, improving the real-time nature and accuracy of security monitoring. After a device connects, the switch can extract the device's fingerprint information through traffic data to further verify the device's identity, preventing device replacement or tampering, thereby improving the access security and reliability of terminal devices. Simultaneously, it also improves the convenience of connection and management for both the switch and terminal devices.

[0042] In one implementation, prior to step S1 above, i.e., before responding to the network port unlocking command issued by the server, the switch needs to be initialized. Specifically, in the power-on state, all network ports are set to the locked state, and a registration request is sent to the server. The registration request carries the switch's device identifier, the number of network ports, and the network port locking status. In response to the registration request, a communication link is established with the server. The server has a generated network port unlocking command, which carries the device identifier of the target device, the device identifier of the switch, and the specified network port number.

[0043] The technical solution provided in this embodiment details the initialization preparation process of the switch before network access is initiated. Specifically, in the initial startup state, the switch locks all network ports to prevent incorrect access by other unknown terminal devices, ensuring the switch is in its most secure state and improving the security of access between terminal devices and the switch. Furthermore, a registration request is sent to the server, distributing the switch's device information for registration. This allows the server to directly determine the designated network port for access when a target device needs to connect, based on the information carried in the registration request. Through the established communication link, the server can directly send the allocated network port information to the switch via a port unlocking command, enabling network access for the target device and thus improving the convenience of network access.

[0044] In one implementation, after step S1, i.e., after the target device is connected to the designated network port, the smart network port lock of the target device automatically locks and reports the locking status as status information. Specifically, the switch receives the status information sent by the target device and reports the status information to the server. This status information represents the locking status of the smart network port lock, including unlocked and locked states, used to confirm whether the target device is properly locked. By reporting the status information to the server, it is easier to subsequently confirm whether the target device has been unauthorizedly removed or replaced. This status information is automatically generated by the smart network port lock after the target device is connected, and the smart network port lock is used to switch to the locked state after the target device is connected. Further, after confirming the status information, the server generates and sends a network port locking command. After receiving the network port locking command from the server, the switch switches the state of the designated network port lock to the locked state to ensure the network port is in a secure state. The network port locking command is generated by the server after confirming the status information, ensuring that the network port locking operation is only performed when the device status is normal and complies with the security policy.

[0045] The technical solution provided in this embodiment monitors and reports the status information of the smart network port lock through a switch, confirming the locked and unlocked states of the smart network port lock and the designated network port lock, effectively preventing the access and replacement of other target devices. Specifically, the switch can receive and report the device status information in real time, facilitating timely detection and handling of anomalies during target device access, improving the security and real-time performance of target device network access. Furthermore, the smart network port lock automatically switches to a locked state after device access, reducing manual intervention. By automatically reporting its own status information, it informs the switch and server that the access and locking actions have been completed, improving the convenience and accuracy of device management. Simultaneously, the server generates a network port locking command based on the status information, allowing flexible setting of access permissions according to different devices and scenarios, improving the security, convenience, and adaptability of target devices when accessing the network.

[0046] In one embodiment, the switch includes a PoE power supply module, which can supply power to the target device through a designated network port to ensure the normal operation of the target device. Specifically, after the target device is connected to the designated network port, the PoE power supply module supplies power to the network cable of the target device through the designated network port, so that the smart port lock can automatically report its locking status to the switch in real time after the target device is connected to power.

[0047] The technical solution provided in this embodiment adds a PoE power supply module to the switch, providing power to the target devices connected via the PoE power supply module. Specifically, after receiving power from the PoE power supply module, the smart port lock can report its locking status in real time. The switch can monitor the access status of the devices in real time, ensuring that the devices can operate normally after connection, thus improving the security of target devices when accessing the network. Furthermore, through the PoE power supply module, the switch can provide stable power support to the target devices, eliminating the need for other power supply equipment to provide external power to the target devices and the switch, further improving the convenience of network access for target devices and making it suitable for device access needs in various scenarios.

[0048] In one implementation, a determination is made regarding whether a target device has an access anomaly based on the device fingerprint and pre-acquired fingerprint information. Specifically, the target device's fingerprint information is pre-stored as a comparison benchmark. This fingerprint information is compared with the device fingerprint extracted in real time. The comparison result determines whether the device's identity is legitimate, thus promptly detecting access anomalies. The fingerprint information represents fixed information about the target terminal device and is determined when the target device first connects to the designated network port, serving as its unique identifier. If the fingerprint information matches the device fingerprint, it is determined that there is no access anomaly; if the fingerprint information does not match the device fingerprint, it is determined that there is an access anomaly.

[0049] In this embodiment, the fingerprint information of the target device is obtained as follows: After connecting the target device to a designated network port, the protocol data of the target device is obtained through traffic mirroring, and the fingerprint information is extracted from the protocol data. The protocol data represents the network protocol generated by the target device during the access process, and the fingerprint information includes the protocol type, device communication address, and device fixed information. Traffic mirroring technology allows the switch to capture and analyze all data packets transmitted through the network port, i.e., the protocol data of the target device, providing data support for extracting the device fingerprint.

[0050] The aforementioned protocol types are part of the device fingerprint, representing the network protocol type used by the target device during access, such as LLDP, DHCP, SNMP, etc. The device communication address can be the target device's MAC address. The device's fixed information consists of its hardware or software characteristics, such as device model and client identifier. Employing a multi-protocol fusion device fingerprint and fingerprint information, covering binding information for multiple protocols such as LLDP and DHCP, effectively avoids identity spoofing caused by MAC address forgery compared to single MAC address identification.

[0051] The technical solution provided in this embodiment achieves real-time anomaly detection for network access anomalies of target devices by comparing pre-acquired fingerprint information with real-time acquired device fingerprints. Both fingerprint information and device fingerprints can be obtained from designated network ports using traffic mirroring technology. Fingerprint comparison accurately verifies the identity of accessing devices, promptly detecting and preventing unauthorized terminal devices from accessing the network, thereby significantly improving network access security. Furthermore, real-time extraction of device fingerprints using traffic mirroring technology ensures the real-time nature and accuracy of anomaly detection, reducing false alarms and missed alarms, and enhancing the flexibility and reliability of network management.

[0052] In one implementation, in the event of a device access anomaly, based on the aforementioned first and second state information, the anomaly information of the target device is further determined. Specifically, if both the first and second state information indicate an unlocked state, it indicates that someone has replaced the device without authorization, which is determined to be a physical intrusion anomaly. In this case, alarm mechanisms such as audible and visual alarms and SMS notifications are immediately triggered, and the anomaly details are recorded. If either the first or second state information indicates an unlocked state, it indicates that the device replacement may have been authorized (e.g., maintenance or device update), but further verification is required. This is determined to be a permission change pending verification, and manual confirmation is prompted. After confirmation, the fingerprint information is updated. If the replacement is confirmed to be unauthorized, the same handling measures as for physical intrusion anomalies are taken.

[0053] The technical solution provided in this embodiment, by combining the status information of the network port lock and the smart network port lock, can accurately determine the specific type of abnormal device access, effectively distinguishing between physical intrusion and legitimate device replacement or maintenance operations. This dual locking and status monitoring mechanism not only improves the security of network access and prevents unauthorized device access or replacement, but also enhances the accuracy of anomaly detection and management efficiency, reduces false alarms and missed alarms, and ensures the safe operation of the network, thereby improving the security and adaptability of network access.

[0054] Please refer to Figure 3 This application provides an embodiment of the above-described device access protection method based on a switch. Figure 3 The instruction and data processing flow of this embodiment is characterized by the collaborative network access and protection achieved through the server, switch, and target device. This embodiment is carried out according to the following steps:

[0055] Step 1: The switch sends a registration request to the server.

[0056] All network port locks are switched to the locked state, and a registration request is initiated to the server. This registration request carries the device identifier, number of network ports, and network port lock status of the switch. The server responds to the registration request and establishes a communication link with the switch. At this point, the switch enters a standby state managed by the server.

[0057] Step 2: Issuance and execution of network port unlocking command.

[0058] When a user performs an operation on the server, the server generates a network port unlock command based on this operation and sends the network port unlock command to the switch. The switch carries the device identifier of the target device, the device identifier of the switch, and the specified network port number. In response to the network port unlock command sent by the server, the switch switches the specified network port lock to the unlocked state.

[0059] Step 3: Connect the target device to the designated network port.

[0060] The maintenance personnel then connect the target device to the designated network port. The target device is equipped with a smart network port lock. After the target device is connected, the switch's PoE power supply module supplies power to it through the designated network port, activating the smart network port lock's automatic reporting function.

[0061] Step 4: Status information reporting.

[0062] The smart network port lock reports its locking status as status information to the switch, and the switch then reports this status information to the server.

[0063] Step 5: Issuance and execution of the network port locking command.

[0064] After confirming the locked state of the smart port lock, the server generates and sends a port lock command. In response to the port lock command sent by the server, the switch switches the specified port lock to the locked state.

[0065] Step Six: Uploading and comparing fingerprint information.

[0066] The switch acquires traffic data from the designated network port and extracts initial fingerprint information from the traffic data. This fingerprint information is uploaded to the server for storage and serves as a benchmark for subsequent comparisons. The switch continuously monitors the traffic data of the designated network port and extracts real-time device fingerprints from it. The switch compares the device fingerprints with the benchmark fingerprints pre-stored on the server to determine if there are any abnormal device accesses.

[0067] Step 7: Exception handling.

[0068] When a device access anomaly is detected, the switch obtains the first status information of the specified network port lock and the second status information of the smart network port lock. Based on the first status information and the second status information, the switch determines the anomaly information of the target device. For the determined anomaly information, the server triggers the corresponding alarm mechanism.

[0069] In this embodiment, through steps one through seven, the "two-end locking" design of the switch's physical port locking and the smart port lock, combined with the switch's PoE power supply function, achieves integrated management and control of "protection + power supply + monitoring". Compared to the traditional logic management mode that relies solely on identity authentication, the technical solution of this embodiment blocks unauthorized access at the physical layer and ensures the continuous operation of the smart port lock through the PoE power supply link. This solves the defects of traditional physical locks that rely on external power supply or lack state feedback, thereby improving the security, adaptability, and convenience of the target device when accessing the network.

[0070] Furthermore, remote control of the network port lock status is achieved through the server, supporting flexible operations such as temporary unlocking and time-limited management. This solves the inefficiency problem of traditional physical locks requiring on-site operation. The default power-on lock design ensures that the device remains secure after a restart. Simultaneously, the linkage between port lock status and device fingerprint changes effectively distinguishes between compliant maintenance and malicious intrusion. Compared to single-dimensional alarms, this significantly reduces the false alarm rate, further improving the security, adaptability, and convenience of target devices when accessing the network.

[0071] Please see Figure 4 This application also provides a switch-based device access protection system, the system comprising a server, one or more switches, and one or more target devices. Specifically,

[0072] The server is used to configure and issue network port unlock and network port lock commands, store and compare device fingerprints, receive status information, and perform anomaly analysis based on the device fingerprint and the status information.

[0073] The smart network port lock is used to communicate with the switch via a network cable, monitor and report its own status information;

[0074] A switch is configured to respond to a network port unlock command issued by a server, switch a designated network port lock to an unlocked state, and connect a target device to the designated network port, wherein the designated network port lock is installed on the designated network port, and the target device is equipped with a smart network port lock; respond to a network port lock command issued by the server, switch the designated network port lock to a locked state, continuously monitor the traffic data of the designated network port, extract device fingerprints from the traffic data, and determine whether there is a device access anomaly based on the device fingerprints; if a device access anomaly is determined, acquire the first state information of the designated network port lock and the second state information of the smart network port lock, and determine the anomaly information of the target device based on the first state information and the second state information.

[0075] In one embodiment, the server has the following functions: full lifecycle management of customized switches and smart network port locks (registration, status monitoring, permission configuration); issuance and execution result verification of network port locking or unlocking commands; storage, comparison, and change detection of device fingerprint information; linkage analysis and alarm of multi-dimensional abnormal information (port status, fingerprint changes); recording, querying, and auditing of operation logs and security events.

[0076] In one embodiment, the smart network port lock has the following functions: physically locking the network cable on the terminal side, preventing it from being pulled out without authorization; feeding back the terminal's locking status to the switch; and having unlocking status detection and reporting functions, feeding back the status information to the switch in real time after the unlocking operation is triggered.

[0077] In one embodiment, the aforementioned switch includes a customized communication module, a network port locking control module, a traffic mirroring and monitoring module, and a PoE power supply module. Specifically, the customized communication module is used to interact with the server and receive the network port unlocking command or the network port locking command; the network port locking control module is used to switch the specified network port lock to an unlocked or locked state in response to the network port unlocking command or the network port locking command; the traffic mirroring and monitoring module is used to obtain protocol data or traffic data through traffic mirroring to extract fingerprint information or device fingerprints; and the PoE power supply module is used to power the smart network port lock through the specified network port lock.

[0078] Further functional descriptions of the above modules and units are the same as those in the corresponding embodiments described above, and will not be repeated here.

[0079] Please see Figure 5 This application also provides a device access protection device based on a switch, the device comprising:

[0080] The device access unit 100 is used to respond to the network port unlocking command issued by the server, switch the specified network port lock to the unlocked state, and connect the target device to the specified network port, wherein the specified network port lock is installed on the specified network port, and the target device is equipped with a smart network port lock;

[0081] The traffic monitoring unit 200 is used to respond to the network port locking command issued by the server, switch the specified network port lock to the locked state, continuously monitor the traffic data of the specified network port, extract the device fingerprint from the traffic data, and determine whether there is a device access anomaly based on the device fingerprint.

[0082] The anomaly determination unit 300 is used to obtain the first status information of the specified network port lock and the second status information of the smart network port lock when it is determined that there is a device access anomaly, and to determine the anomaly information of the target device based on the first status information and the second status information.

[0083] in,

[0084] In one embodiment, the device further includes a switch initialization unit, which is configured to, before responding to a network port unlocking command issued by the server, set all network ports to a locked state in the power-on state, send a registration request to the server, wherein the registration request carries the device identifier of the switch, the number of network ports, and the network port locking state, and establish a communication link with the server in response to the registration request, wherein the server has a generated network port unlocking command, the network port unlocking command carrying the device identifier of the target device, the device identifier of the switch, and a specified network port number.

[0085] In one embodiment, the device further includes a device configuration unit, which is used to receive the status information of the target device after connecting the target device to a designated network port, and report the status information to the server, wherein the status information represents the locking status of the smart network port lock, receive a network port locking command fed back by the server, wherein the network port locking command is generated by the server after confirming the status information, and supply power to the target device through the designated network port so that after the target device is connected to power, the automatic reporting function of the smart network port lock is activated so as to report the locking status of the smart network port lock to the switch.

[0086] In this application embodiment, a switch-based device access protection device is presented in the form of a functional unit. Here, a unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that execute one or more software or fixed programs, or other devices that can provide the above functions.

[0087] Please see Figure 6 , Figure 6 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application, such as... Figure 6 As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 6 Take a processor 10 as an example.

[0088] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.

[0089] The memory 20 stores instructions executable by at least one processor 10 to cause the at least one processor 10 to perform the method shown in the above embodiments.

[0090] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the computer device. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some alternative embodiments, the memory 20 may optionally include memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0091] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0092] The computer device also includes a communication interface 30 for communicating with other devices or communication networks.

[0093] This application also provides a computer-readable storage medium. The methods described in this application can be implemented in hardware or firmware, or implemented as recordable on a storage medium, or implemented as computer code downloaded over a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and subsequently stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code. When the software or computer code is accessed and executed by the computer, processor, or hardware, the methods shown in the above embodiments are implemented.

[0094] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0095] For ease of description, the above devices are described separately by function as various units. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware.

[0096] Those skilled in the art will understand that embodiments of this application can be provided as methods, apparatus, systems, and devices. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0097] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus, systems, and devices according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0098] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0099] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0100] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0101] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system and device embodiments are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0102] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

[0103] Although embodiments of this application have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of this application, and such modifications and variations all fall within the scope defined by the appended claims.

Claims

1. A device access protection method based on a switch, characterized in that, The method is applied to the switch, and the method includes: In response to the network port unlocking command issued by the server, the specified network port lock is switched to the unlocked state, and the target device is connected to the specified network port. The specified network port lock is installed on the specified network port and is used to control the physical access state of the specified network port. The target device is equipped with a smart network port lock, which can physically lock the network cable on the target device side and prevent it from being pulled out without authorization. In response to the network port locking command issued by the server, the specified network port lock is switched to the locked state, and the traffic data of the specified network port is continuously monitored. The device fingerprint is extracted from the traffic data, and the device fingerprint is used to determine whether there is a device access anomaly. If an abnormal device access is detected, the system obtains the first status information of the specified network port lock and the second status information of the smart network port lock, and determines the abnormal information of the target device based on the first status information and the second status information.

2. The method according to claim 1, characterized in that, Before responding to the network port unlock command issued by the server, the method further includes: When powered on, all network ports are set to the locked state, and a registration request is sent to the server. The registration request carries the device identifier, number of network ports, and network port lock status of the switch. In response to the registration request, a communication link is established with the server, wherein the server has a generated network port unlocking command, which carries the device identifier of the target device, the device identifier of the switch, and the specified network port number.

3. The method according to claim 1, characterized in that, The smart network port lock is used to switch to the locked state after the target device is connected; After connecting the target device to the designated network port, the method further includes: The status information of the target device is received and reported to the server, wherein the status information represents the locking status of the smart network lock; Receive the network port locking command fed back by the server, wherein the network port locking command is generated by the server after confirming the status information.

4. The method according to claim 1 or 3, characterized in that, The switch includes a PoE power supply module; After connecting the target device to the designated network port, the method further includes: The PoE power supply module supplies power to the target device through the designated network port, so that after the target device is connected to the power supply, the automatic reporting function of the smart network port lock is activated, so as to report the locking status of the smart network port lock to the switch.

5. The method according to claim 1, characterized in that, Determining whether there is a device access anomaly based on the device fingerprint includes: The fingerprint information of the target device obtained in advance is compared with the fingerprint of the device, wherein the fingerprint information represents the fixed information of the target device; If the fingerprint information matches the device fingerprint, it is determined that there is no device access anomaly; if the fingerprint information does not match the device fingerprint, it is determined that there is a device access anomaly.

6. The method according to claim 5, characterized in that, The fingerprint information of the target device is obtained in the following manner: After the target device is connected to the designated network port, the protocol data of the target device is obtained through traffic mirroring, and the fingerprint information is extracted from the protocol data. The protocol data represents the network protocol generated by the target device during the access process, and the fingerprint information includes the hardware or software characteristics of the device.

7. The method according to claim 1, characterized in that, Based on the first status information and the second status information, the abnormal information of the target device is determined to include: If both the first status information and the second status information represent a locked state, then it is determined to be a physical intrusion anomaly. If either the first status information or the second status information contains status information representing an unlocked state, then it is determined that the permission change is pending verification.

8. A device access protection system based on a switch, characterized in that, The system includes: The server is used to configure and issue network port unlock and network port lock commands, store and compare device fingerprints, receive status information, and perform anomaly analysis based on the device fingerprint and the status information. The smart network port lock is used to communicate with the switch via a network cable, monitor and report its own status information; A switch, in response to a network port unlock command issued by a server, switches a designated network port lock to an unlocked state and connects a target device to the designated network port. The designated network port lock is installed on the designated network port and controls the physical access status of the designated network port. The target device is equipped with a smart network port lock, which physically locks the network cable on the target device side, preventing unauthorized removal. In response to a network port lock command issued by the server, the switch switches the designated network port lock to a locked state and continuously monitors the traffic data of the designated network port. It extracts a device fingerprint from the traffic data and determines whether there is a device access anomaly based on the device fingerprint. If a device access anomaly is determined, it acquires the first state information of the designated network port lock and the second state information of the smart network port lock, and determines the anomaly information of the target device based on the first and second state information.

9. A device access protection device based on a switch, characterized in that, The device access protection device is applied to the switch, and the device includes: The device access unit is used to respond to the network port unlocking command issued by the server, switch the specified network port lock to the unlocked state, and connect the target device to the specified network port. The specified network port lock is installed on the specified network port and is used to control the physical access state of the specified network port. The target device is equipped with a smart network port lock, which can physically lock the network cable on the target device side and prevent it from being pulled out without authorization. The traffic monitoring unit is used to respond to the network port locking command issued by the server, switch the specified network port lock to the locked state, continuously monitor the traffic data of the specified network port, extract the device fingerprint from the traffic data, and determine whether there is a device access anomaly based on the device fingerprint. An anomaly determination unit is used to obtain the first status information of the specified network port lock and the second status information of the smart network port lock when it is determined that there is a device access anomaly, and to determine the anomaly information of the target device based on the first status information and the second status information.

10. A computer device, characterized in that, include: A memory and a processor are interconnected, the memory stores computer instructions, and the processor executes the computer instructions to perform a switch-based device access protection method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method for preventing invasions and access equipment

    CN104883340A

  • Enhanced smart process control switch port lockdown

    CN109617813A