Heterogeneous terminal network authentication method and system
By automatically acquiring and verifying user certificates through a cross-platform unified authentication client, the compatibility issues of 802.1X certificate authentication schemes in heterogeneous terminal environments are resolved, enabling a network access experience where login is instantaneous, and improving authentication efficiency and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-26
- Publication Date
- 2026-03-13
AI Technical Summary
The existing 802.1X certificate authentication scheme is incompatible with domestic operating systems in heterogeneous terminal environments, resulting in the inability to establish trust relationships, increasing IT operation and maintenance costs and user operation complexity, and affecting network access efficiency and security.
It adopts a cross-platform unified authentication client, which automatically obtains and verifies the validity of user certificates through identity identifiers, configures network interfaces and initiates 802.1X authentication, so as to realize the network access experience of logging in and connecting to the network. It includes identity identifier acquisition module, certificate determination module, certificate verification module, network configuration module and authentication initiation module.
It improves the convenience and security of network authentication operations in heterogeneous terminal environments, enhances authentication efficiency, ensures certificate policy compliance and network access continuity, and reduces operation and maintenance costs and user operation complexity.
Smart Images

Figure CN121664559A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data communication technology, and in particular to a method and system for authentication of heterogeneous terminal networks. Background Technology
[0002] Against the backdrop of the comprehensive advancement of the national information technology innovation strategy, a considerable number of key industries need to complete the localization of hardware, systems, and business applications within a specified period. This policy drive has led to a fundamental change in the enterprise terminal environment, gradually transitioning from the traditional single Windows system to a heterogeneous hybrid terminal form where Windows coexists with domestic operating systems such as Kylin and UnionTech UOS. Therefore, network authentication, as a core link of enterprise network security, faces new demands for adapting to heterogeneous environments.
[0003] In enterprise network security architecture, the 802.1X certificate authentication solution has become the mainstream network authentication choice due to its flexibility based on link layer authentication and the high security of the PKI system. In a traditional single Windows terminal environment, this solution can automatically distribute authentication configurations and associate them with accounts through Microsoft Active Directory domain group policies. The terminal can automatically complete 802.1X certificate authentication and access the network, meeting the enterprise's operation and security needs.
[0004] However, existing 802.1X certificate authentication solutions have the following drawbacks in heterogeneous terminal environments: First, domestic operating systems cannot join Microsoft Active Directory (AD) domain controllers, making it difficult to establish trust relationships and incompatible with AD domain group policy configuration and distribution; second, some domestic IT companies are required to decommission Microsoft AD due to policy requirements, rendering the original solutions completely unusable; third, multiple authentication tools need to be maintained for multiple system terminals, with inconsistent operating logic, which not only increases the configuration and maintenance costs of IT operations but also reduces employee efficiency due to operational complexity, affecting overall office efficiency. Therefore, network authentication in heterogeneous terminal environments faces problems of cumbersome operation and poor user experience. Summary of the Invention
[0005] To address the aforementioned shortcomings in existing technologies, the present invention aims to provide a heterogeneous terminal network authentication method that improves the convenience of network authentication operations in heterogeneous terminal environments.
[0006] The above-mentioned objective of this invention is achieved through the following technical solution: A heterogeneous terminal network authentication method, applied to a unified authentication client implemented across platforms, includes: In response to a user login event to the terminal system, obtain the identity identifier of the currently logged-in user from the event; Based on the identity identifier, determine the user certificate corresponding to the identity identifier; The user certificate is validated to obtain the certificate validation result; If the certificate verification result is valid, then the network interface parameters of the terminal system are configured. The user certificate is used to initiate 802.1X authentication with the authentication server through the configured network interface to obtain the communication authentication result; If the communication authentication result is successful, the terminal system is authorized to access the network.
[0007] By adopting the above technical solution, the network authentication process is automatically triggered after the user logs in to the system. The validity of the user certificate is quickly obtained and verified based on the identity identifier. When the certificate is valid, the network interface is automatically configured and two-way security authentication with the authentication server is completed based on the 802.1X protocol. Finally, network access is automatically authorized after the authentication is successful. This achieves a network access experience of logging in and connecting to the network immediately in a heterogeneous terminal environment, effectively improving authentication efficiency and user operation convenience.
[0008] Preferably, determining the user certificate corresponding to the identity identifier based on the identity identifier includes: Based on the identity identifier, query the preset certificate security storage area; Determine whether a user certificate bound to the identity is present in the certificate security storage area; If it exists, the user certificate corresponding to the identity identifier is read from the certificate security storage area.
[0009] By adopting the above technical solution, user certificates stored locally are automatically queried and read based on identity identifiers, realizing fast and accurate matching between user identity and digital certificate. This avoids the tedious operation of users manually selecting or searching for certificates, improves the automation level and response speed of the authentication process, and enhances the security and reliability of the authentication process through localized certificate management.
[0010] Preferably, the certificate verification result includes a valid result; The step of verifying the validity of the user certificate to obtain the certificate verification result includes: The user certificate is parsed to obtain its template identifier and validity period. The template identifier of the user certificate is verified for consistency based on the pre-configured group policy template identifier; Obtain the current system time and verify whether the current system time is within the validity period of the user certificate; If the group policy template identifier matches the user certificate template identifier and the current system time is within the validity period of the user certificate, then the user certificate validity verification is deemed successful and the valid result is output.
[0011] By adopting the above technical solution, the template identifier consistency verification and validity period check of user certificates are performed, realizing dual verification of certificate policy compliance and timeliness. This ensures that the certificates used always comply with the current security policy issued by the management platform and are in a valid state, thereby eliminating security risks and authentication failures caused by expired or non-compliant certificate policies at the source and improving the reliability and security of the authentication process.
[0012] Preferably, the certificate verification result also includes an invalid result; The step of verifying the validity of the user certificate to obtain the certificate verification result further includes: If the group policy template identifier is inconsistent with the user certificate template identifier, and / or the current system time is not within the validity period of the user certificate, an invalid result will be output, and the certificate update process will be triggered.
[0013] By adopting the above technical solution, the certificate update process is automatically triggered when the certificate verification fails, realizing real-time detection and self-repair of the certificate invalidation status. This avoids authentication interruption caused by certificate policy incompatibility or expiration, ensures the continuity and reliability of network access services, and improves the automation level and user experience of the system in certificate lifecycle management.
[0014] Preferably, the certificate update process is as follows: Initiate a certificate update request to the management platform and receive the response information returned by the management platform in response to the certificate update request; Based on the response information, a determination is made regarding the user certificate update, and a determination result is obtained; If the determination result is successful, then the new user certificate is obtained from the response information; The new user certificate is stored in the certificate security storage area and bound to the corresponding identity identifier. The new user certificate is generated by the management platform based on the latest policy corresponding to the group policy template identifier. If the determination result is failure, a certificate update request failure report will be generated.
[0015] By adopting the above technical solution, when a certificate expires, it is possible to automatically apply to the management platform and obtain a new user certificate generated based on the latest policy, complete the security update and identity binding of the local certificate, and ensure that the terminal certificate is always consistent with the server policy. At the same time, through the update status judgment and failure reporting mechanism, the automation level of certificate management and system maintainability are improved.
[0016] Preferably, if the certificate verification result is valid, then the network interface of the terminal system is configured with parameters, including: Obtain the interface type identifier of the network interface of the terminal system; Based on the interface type identifier, determine the target authentication strategy corresponding to the interface type identifier; Based on the target authentication strategy, the network interface is configured with parameters.
[0017] By adopting the above technical solution, the corresponding authentication policy is automatically matched and configured according to the network interface type, realizing differentiated parameter configuration for wired and wireless network interfaces, ensuring the correctness and adaptability of authentication parameters in different network environments, and improving the compatibility and configuration efficiency of heterogeneous terminals at the network access layer.
[0018] Preferably, the step of initiating 802.1X authentication with the authentication server through the configured network interface to obtain the communication authentication result includes: The user certificate is submitted to the authentication server through the configured network interface to perform client authentication and obtain the client authentication result. Receive the server certificate returned by the authentication server, and verify the authentication server based on the server certificate to obtain the server verification result; The authentication result is determined by comparing the client verification result with the server verification result to obtain the communication authentication result. The condition for the communication authentication result to be passed is that both the client verification result and the server verification result are passed.
[0019] By adopting the above technical solution, two-way authentication between the client and the authentication server based on digital certificates is realized. Through the dual protection of client certificate verification and server certificate verification, an end-to-end trusted authentication channel is established, effectively preventing man-in-the-middle attacks and unauthorized server access, and ensuring the two-way security and trustworthiness of the network access process.
[0020] The second objective of this invention is to provide a heterogeneous terminal network authentication system that improves the convenience of network authentication operations in heterogeneous terminal environments.
[0021] The second objective of this invention is achieved through the following technical solution: A heterogeneous terminal network authentication system, applied to a unified authentication client implemented across platforms, includes: The identity identification acquisition module is used to respond to the user login terminal system event and obtain the identity identification of the currently logged-in user from the event; The certificate determination module is used to determine the user certificate corresponding to the identity identifier based on the identity identifier; The certificate verification module is used to verify the validity of the user certificate and obtain the certificate verification result; The network configuration module is used to configure the parameters of the network interface of the terminal system if the certificate verification result is valid. The authentication initiation module is used to initiate 802.1X authentication to the authentication server through the configured network interface of the user certificate and obtain the communication authentication result; The network authorization module is used to authorize the terminal system to access the network if the communication authentication result is successful.
[0022] By adopting the above technical solutions, a complete authentication system including identity recognition, certificate management, network configuration, security authentication, and access authorization has been constructed. Through the collaborative work of each module, the entire network authentication process after user login has been automated, which improves network access efficiency and user experience in heterogeneous terminal environments while ensuring security.
[0023] The third objective of this invention is to provide an electronic device that improves the convenience of network authentication operations in heterogeneous terminal environments.
[0024] The above-mentioned third objective of this invention is achieved through the following technical solution: An electronic device includes a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and execute the heterogeneous terminal network authentication method described above.
[0025] The fourth objective of this invention is to provide a computer storage medium capable of storing corresponding programs, which facilitates network authentication operations in heterogeneous terminal environments.
[0026] The fourth objective of this invention is achieved through the following technical solution: A computer-readable storage medium storing a computer program that can be loaded by a processor and execute the heterogeneous terminal network authentication method described in any of the preceding claims.
[0027] In summary, the present invention has at least one of the following beneficial technical effects: 1. This invention achieves end-to-end automation of the network authentication process after a user logs into the system. It overcomes the compatibility bottleneck of heterogeneous terminal environments based on a cross-platform unified client, builds an end-to-end security defense system through certificate validity verification and 802.1X two-way authentication, and improves operation and maintenance efficiency by using automated policy synchronization and parameter configuration. Ultimately, it achieves a seamless authentication experience of logging in and connecting to the network while ensuring the baseline of network security, providing a secure, efficient and unified network access solution for heterogeneous terminal management in the context of information technology innovation. 2. This invention performs dual verification of user certificates for both validity and invalidity. When the certificate is valid, it ensures the smooth execution of the authentication process and maintains the continuity of network access. When the certificate is invalid, it automatically triggers an update mechanism to restore authentication capabilities in a timely manner and generate an anomaly report. This dynamic verification mechanism not only prevents authentication interruptions caused by certificate expiration or policy incompatibility, but also improves the reliability and security level of the system through real-time status monitoring and self-repair capabilities. At the same time, it reduces the need for manual intervention and makes the certificate management process more automated and intelligent. 3. This invention initiates 802.1X authentication of the user certificate to the authentication server through a network interface. On the one hand, the pre-configured network interface ensures accurate matching between authentication parameters and the network environment, avoiding authentication failures due to configuration errors. On the other hand, leveraging the link-layer authentication feature of the 802.1X protocol, authentication is completed before establishing a network connection, effectively preventing unauthorized devices from accessing the network. Simultaneously, a two-way certificate verification mechanism constructs an end-to-end trusted communication channel, verifying both the legitimacy of the client's identity and the authenticity of the authentication server. This improves the authentication success rate and efficiency while enhancing the security and reliability of the entire network access process, providing a unified and secure network access solution for heterogeneous terminals. Attached Figure Description
[0028] Figure 1 This is a flowchart of the client configuration process before authentication for a heterogeneous terminal network authentication method provided in Embodiment 1 of the present invention.
[0029] Figure 2 This is a flowchart illustrating the steps of a heterogeneous terminal network authentication method provided in Embodiment 1 of the present invention.
[0030] Figure 3 This is a structural block diagram of a heterogeneous terminal network authentication system provided in Embodiment 2 of the present invention. Detailed Implementation
[0031] This invention provides a heterogeneous terminal network authentication method and system to address the following shortcomings of existing 802.1X certificate authentication schemes in heterogeneous terminal environments: First, domestic operating systems cannot join Microsoft Active Directory (AD) domain controllers, making it difficult to establish trust relationships and incompatible with AD domain group policy configuration and distribution; second, some IT innovation enterprises are required to decommission Microsoft AD due to policy requirements, rendering the original solutions completely unusable; third, multiple authentication tools need to be maintained for multiple system terminals, with inconsistent operating logic, which not only increases the configuration and maintenance costs of IT operations but also raises the usage threshold for employees, affecting office efficiency. Therefore, network authentication in heterogeneous terminal environments faces technical problems such as cumbersome operation and poor user experience. This invention improves the ease of network authentication operation in heterogeneous terminal environments.
[0032] It is worth mentioning that this invention constructs a collaborative authentication system consisting of three parts: a web management platform (hereinafter referred to as the management platform), an authentication server (RADIUS server), and a unified authentication client. The management platform undertakes the core task of centralized management. Administrators can use this platform to uniformly configure certificate authority parameters, support self-signing or importing external CA certificates, and uniformly issue and verify user and server certificates. The platform provides certificate template configuration functions, allowing users to define security attributes such as certificate validity period, renewal cycle, encryption algorithm, and key extension usage to meet the certificate requirements of different scenarios. Simultaneously, the platform supports a simplified configuration process through an intuitive graphical interface (such as drag-and-drop setting of validity period and one-click generation of self-signed certificates), and supports RADIUS server certificate configuration and policy formulation, including setting the maximum number of online terminals per account and account-terminal binding relationships. The platform offers fine-grained control policies and configurable 802.1X network access policies, covering wireless network SSIDs, user certificate template associations, wired connection permissions, and specific network cards to be ignored. All policies support batch distribution to heterogeneous terminals across the network. Based on a PKI trust system, the platform processes client certificate applications through an SSL encrypted channel and guides clients to store user certificates locally using SM4 salting encryption, effectively preventing certificate leakage. The platform also handles centralized application, review, issuance, and revocation of user certificates, achieving certificate specification uniformity through standardized certificate templates and automatically processing certificate update requests according to preset policies, realizing automated lifecycle management. Furthermore, the platform provides global monitoring and auditing capabilities, displaying the online status and authentication results of all terminals in real time, recording authentication logs including authentication time, terminal information, and certificate details, and supporting real-time alerts for abnormal behaviors such as certificate expiration and excessively high authentication failure frequencies, providing administrators with unified visual control and auditing capabilities.
[0033] As the core of network access control, the authentication server adopts the RADIUS protocol and EAP-TLS authentication framework. The server receives 802.1X authentication requests initiated by the unified authentication client, and performs strict verification of the user certificate submitted by the client based on the PKI system, including verifying the validity of the certificate signature, validity period and CRL status. At the same time, the server presents its own server certificate to the client to complete two-way identity authentication. After the verification is successful, the server grants the terminal the corresponding network access permissions according to the pre-authorization policy, and can synchronize the authentication results and session information to the management platform for auditing and monitoring.
[0034] The unified authentication client is deployed on various operating system terminals (such as Windows, Kylin, and UOS). Its core function is to listen for system login events and automatically extract user identity identifiers, perform local user certificate lifecycle management, autonomously complete certificate validity verification, and intelligently configure network interface parameters. Finally, it achieves automatic network access through secure interaction with the authentication server, resulting in a seamless login and network access experience for users.
[0035] It should be noted that this client achieves cross-platform compatibility based on the Tauri framework. It builds a unified abstract interface through its Rust core layer, and calls native certificate management interfaces such as CryptoAPI for Windows systems and PKCS#11 for domestic systems to achieve unified certificate operations. At the same time, it adapts to network protocol stacks such as Windows WLANAPI and Linux NetworkManager to complete 802.1X parameter configuration. This architecture design encapsulates system differences in the underlying modules, ensuring that the business logic layer maintains completely consistent functional performance and interactive experience across platforms.
[0036] It's worth noting that the client supports silent installation, completing installation and initial configuration without user interaction or awareness. This allows the client to be seamlessly integrated into the enterprise's existing IT asset management system, enabling large-scale batch pushes and deployments via Microsoft Active Directory domain group policies, mobile device management platforms, or other unified distribution mechanisms. Furthermore, the client is designed to run as a system service or background daemon, with all core authentication activities completed automatically in the background without popping up irrelevant prompts or interfering with the user's foreground focus. It consumes very few system resources such as CPU, memory, and storage, avoiding system lag and slow response caused by security software, allowing users to enjoy secure network access services without ever noticing.
[0037] To make the objectives, features, and advantages of this invention more apparent and understandable, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the embodiments described below are only some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.
[0038] It should be noted that, in the embodiments of this invention, when the relevant object information and other related data are used in specific products or technologies, permission or consent from the object is required, and the collection, use, and processing of the relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. In other words, if the embodiments of this invention involve data related to an object, it must be obtained with the object's authorization and consent, the authorization and consent of relevant departments, and in accordance with the relevant laws, regulations, and standards of the country and region. If personal information is involved in the embodiments, the acquisition of all personal information requires the individual's consent; if sensitive information is involved, the separate consent of the information subject is required. The embodiments also need to be implemented with the object's authorization and consent.
[0039] It should be noted that the terms "first," "second," etc., used in this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. The implementations described in the following exemplary embodiments do not represent all implementations consistent with this disclosure.
[0040] Furthermore, the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article, unless otherwise specified, generally indicates that the preceding and following related objects have an "or" relationship.
[0041] Example 1: Please see Figure 1 and Figure 2 This invention provides a heterogeneous terminal network authentication method, applied to a unified authentication client implemented across platforms, comprising: A unified authentication client refers to a software program built using a cross-platform development framework and technology system. It combines a unified business logic code library with an underlying adaptation layer for different operating systems, enabling the same authentication function to run with consistent behavior and user experience on heterogeneous terminal operating systems.
[0042] Step 101: Respond to the user login terminal system event and obtain the identity identifier of the currently logged-in user from the event.
[0043] An event refers to the complete process by which a user successfully enters the system desktop environment or user session through the authentication mechanism provided by the operating system. The authentication mechanism includes, but is not limited to, entering a password, using biometric features such as fingerprints or faces.
[0044] An identity identifier refers to credential information that uniquely represents a currently logged-in user within a local or domain environment. Its specific form depends on the type of terminal operating system and network environment configuration, and includes, but is not limited to, the following: User Subject Name (UPN): The format is username@domain, such as zhangsan@company.com. This format is an ideal identifier for integration with enterprise directory services (such as LDAP / AD) to achieve precise matching between user identity and certificate subject name; Security Identifier (SID) / User Identifier (UID): In Windows, it refers to a unique SID assigned by the operating system; in Linux / domestic OS environments, it refers to a unique UID. Local username: This is the name of the local account in the operating system, such as zhangsan. It serves as a reliable alternative when the above global identifier cannot be obtained.
[0045] Specifically, the unified authentication client listens for and responds to this event through the following cross-platform mechanism: On Windows operating systems, the client registers as a system service and listens for Winlogon notification packets. When a user successfully logs in interactively, the system generates a specific login event. The client subscribes to and captures this event, allowing it to be triggered the instant the user completes login. On a domestic operating system based on the Linux kernel, the client registers a custom module in the PAM session configuration file (such as / etc / pam.d / common-session). When the user successfully authenticates and starts a session, the PAM framework automatically calls the module, thereby seamlessly triggering the client's response logic.
[0046] Understandably, both of the above mechanisms are standard, non-intrusive interfaces provided by the operating system. The client does not participate in the core authentication process and is only passively triggered after the login is successful. This ensures that the security of the system authentication process is not interfered with, and also ensures the legitimacy and reliability of the client's acquisition of identity information.
[0047] It is worth mentioning that, in order to ensure the accuracy and consistency of identity acquisition, the unified authentication client will automatically complete the configuration and registration of the corresponding event listening mechanism according to the current operating system type during installation. The whole process does not require manual intervention or script writing by the administrator, realizing one-time deployment and automatic adaptation in heterogeneous terminal environments, which greatly reduces the complexity of operation and maintenance.
[0048] In this embodiment of the invention, the triggering of network authentication is deeply bound to the system-level login success event. The network authentication process is only triggered when the user successfully logs into the terminal system, and the identity identifier is obtained based on the event. This identity identifier comes directly from the operating system kernel or trusted security subsystem, avoiding the risk of tampering that may be caused by obtaining information from non-privileged processes or user space.
[0049] Step 102: Based on the identity identifier, determine the user certificate corresponding to the identity identifier.
[0050] Preferably, step 102 may include the following sub-steps: S11. Based on the identity identifier, query the preset certificate security storage area.
[0051] The certificate security storage area refers to a dedicated, secure storage area provided by the operating system for storing digital certificates and their associated private keys that are bound to a specific user's identity.
[0052] It is worth mentioning that this storage area uses an operating system-level access control mechanism to ensure that only the certificate owner and privileged system processes can access it, effectively preventing the certificate from being read or copied without authorization.
[0053] When user certificates are stored in this security zone, they are encrypted using the SM4 national cryptographic algorithm with salting to effectively prevent unauthorized access and leakage of certificate data. Specifically, the SM4 salting encryption process is implemented as follows: when storing the certificate, the client generates a random salt value, and the certificate data is encrypted using the SM4 algorithm in combination with this salt value. The salt value and the encrypted data are stored together. When reading the certificate, the stored salt value is retrieved first, and then the same SM4 algorithm is used for decryption.
[0054] S12. Determine whether a user certificate bound to an identity exists in the certificate security storage area.
[0055] A user certificate refers to a digital certificate based on the X.509 standard, which includes, but is not limited to, key fields such as the user's public key, identity information, issuer information, validity period, and template identifier. It is digitally signed by a trusted Certificate Authority (CA) and used as a core credential to prove the user's identity in 802.1X authentication.
[0056] S13. If it exists, read the user certificate corresponding to the identity from the certificate security storage area.
[0057] Specifically, the unified authentication client achieves secure certificate query and retrieval through the following methods: On the Windows operating system, the certificate security store specifically refers to the personal certificate store of the currently logged-in user. The client calls the Windows CryptoAPI or CNG interface, uses the identity identifier as the query condition, and searches for the user certificate in the store whose subject name or alternative subject name matches the identifier.
[0058] On domestic operating systems based on the Linux kernel, the certificate security storage area is preferably implemented through a local PKCS#12 format keystore file. This file is usually stored in the .pki directory under the user's home directory. The client performs a query operation based on the identity by calling the OpenSSL library or the system's built-in certificate management interface.
[0059] Understandably, the binding relationship between certificates and identity identifiers is established in advance during the certificate application or deployment phase. The subject name or alternative subject name field of the certificate contains the user's identity identifier. When the client executes a query, it can determine and locate the corresponding user certificate by accurately matching these fields.
[0060] In this embodiment of the invention, the corresponding user certificate is automatically queried and located based on the identity identifier of the system authentication, avoiding the tedious operation of manually selecting or searching for the certificate by the user. This makes the entire authentication process free of manual intervention, improving authentication efficiency and user experience. Although the certificate storage interfaces of different operating systems are different, the unified authentication client provides a unified certificate query and read interface to the upper layer by encapsulating the differences in the underlying layer. This ensures that the certificate determination logic remains consistent on different platforms, simplifies development and maintenance, and enhances the adaptability of the solution in heterogeneous environments.
[0061] It's worth noting that if the certificate security store does not contain a user certificate bound to the identity, the certificate application process is automatically triggered. During this process, the client first reads its locally pre-configured Group Policy template identifier or one synchronized from the management platform. This identifier indicates the current certificate security baseline to be followed. Based on this pre-configured Group Policy template identifier, the client then applies to the certificate management platform for a new user certificate corresponding to that identity. The specific process includes: First, an RSA or ECC key pair conforming to the Group Policy template is generated for the identity in the local certificate security storage area. The private key is always securely stored locally and never disclosed. Then, a certificate issuance request is constructed using the public key and the identity according to the PKCS#10 standard. The CSR and identity credentials are submitted to the management platform through an SSL / TLS encrypted channel. This process is verified through the enterprise single sign-on system. After the management platform verifies the identity, the CA issues an X.509 user certificate based on the corresponding Group Policy template. After receiving the certificate, the client binds it to the local private key and stores it securely.
[0062] It's worth noting that, to ensure the validity of the credentials from application to installation, the client performs a success verification after receiving the certificate data. If the verification fails, the process terminates and displays a message indicating that the certificate application failed and the specific reason. The logic followed in this judgment process is consistent with the certificate update process described later, and will not be repeated here.
[0063] Understandably, this certificate application process can be seen as a specific implementation of the certificate update process in the scenario where local certificates are missing. When there is no valid certificate in the certificate security storage area, the certificate update process is manifested as the process of applying for and installing a certificate from scratch. Whether the certificate is missing or expired, the system ensures that the terminal eventually obtains a valid user certificate that complies with the latest policy through a unified certificate update mechanism.
[0064] Understandably, when a new employee logs into their device for the first time, the system can seamlessly guide them through the certificate application process without requiring the user to have certificate management knowledge or submit manual work orders. This reduces the cost of manual intervention in IT operations and maintenance, and greatly improves user satisfaction and office efficiency.
[0065] Step 103: Verify the validity of the user certificate and obtain the certificate verification result.
[0066] Certificate verification results include valid results.
[0067] Preferably, step 103 may include the following sub-steps: S21. Parse the user certificate to obtain the template identifier and validity period of the user certificate.
[0068] Template identifier refers to a string or numeric identifier embedded in a specific custom extended field of a user certificate. It is used to uniquely represent the security policy template followed when issuing the certificate. This template is uniformly configured and managed by the management platform and defines the core security attributes of the certificate, including but not limited to key usage (such as digital signature, key encryption), extended key usage (such as client authentication, secure email), and the public key algorithm (such as RSA-2048, ECC-256) and hash algorithm (such as SHA-256) used.
[0069] The validity period refers to the time interval between the certificate's effective date (notBefore) and its expiration date (notAfter). This information is directly taken from the Validity field in the X.509 certificate standard structure.
[0070] Specifically, the unified authentication client determines the validity period by calling a cross-platform certificate resolution interface: On the Windows operating system, the client first uses functions such as CertFindCertificateInStore to locate the certificate, and then uses the CertGetCertificateContextProperty function with the corresponding property identifier to access the certificate extended properties, thereby reading the template identifier in the custom extension item. At the same time, by parsing the pCertInfo->Validity member in the certificate context structure, the notBefore and notAfter timestamps are directly obtained.
[0071] On domestic operating systems based on the Linux kernel, the client mainly uses OpenSSL library functions. First, it uses the X509_get_ext_d2i function to parse the template identifier from the certificate extension stack by specifying the object identifier corresponding to the template identifier. For the validity period, the X509_get0_notBefore and X509_get0_notAfter functions are used to obtain the effective and expiration times, respectively.
[0072] It is worth mentioning that this parsing process is based entirely on the standard PKI certificate processing flow. The client uses a predefined object identifier to locate and extract the custom template identifier, ensuring the consistency of the parsing logic across different platforms. For obtaining the validity period, the standard fields of the certificate are read directly. All times are expressed in Coordinated Universal Time (UTC), ensuring the validity of the data.
[0073] S22. Verify the consistency of the template identifier of the user certificate based on the pre-configured group policy template identifier.
[0074] The pre-configured group policy template identifier refers to the latest certificate policy template ID that is currently in effect, issued by the management platform and stored in the client's local configuration file or registry. This identifier represents the latest security benchmark that the enterprise management platform believes all currently valid certificates should follow.
[0075] It is worth mentioning that the pre-configured group policy template identifier is actively synchronized from the management platform by the unified authentication client at startup or according to a preset period. The preset period can be flexibly configured according to the enterprise network policy and security requirements, such as 1 hour, 12 hours or 24 hours, etc., without any virtual limitation here.
[0076] It should be noted that the management platform refers to a cloud-based management console built on a web technology architecture, which provides system administrators with centralized configuration, monitoring and auditing functions.
[0077] Specifically, when performing identity consistency verification, the client will perform a precise string comparison between the template identifier parsed from the user certificate and the pre-configured group policy template identifier stored locally. If the two are completely consistent, the identity consistency verification will pass; if they are inconsistent, it indicates that the user certificate was issued based on an outdated or revoked security policy template. Even if the certificate itself has not expired, it will be considered as non-compliant with the policy and the verification will fail.
[0078] For example, during initial deployment, a company created a certificate policy named "Basic Security Template" on the management platform. Its unique template identifier was POLICY_V1, and it specified the use of the RSA-2048 algorithm. Six months later, to improve security, the administrator upgraded the global policy to "Enhanced Security Template," updating the template identifier to POLICY_V2 and mandating the ECC-256 algorithm. This new identifier was distributed to all online clients in real time through the platform. At this point, user A had already obtained a new certificate issued based on the POLICY_V2 template through the system's automated process after the policy upgrade; while user B, having not logged in recently, still had a valid certificate issued by the old template POLICY_V1 stored on their terminal.
[0079] During the verification process, for user A's certificate, the client first parses the template identifier as POLICY_V2, then reads the locally pre-configured Group Policy template identifier POLICY_V2, and confirms that the two are completely consistent through a string comparison. The identifier consistency verification passes successfully, and the client continues with subsequent verification steps. For user B's certificate, the client parses the template identifier as POLICY_V1, which is inconsistent with the currently effective POLICY_V2 policy identifier. Although user B's certificate has not yet expired, the system immediately determines that the certificate policy is non-compliant, and the identifier consistency verification fails. The system then connects the terminal to the network using the old certificate and automatically triggers the update process, guiding it to apply for a new certificate issued based on the latest POLICY_V2 template from the management platform.
[0080] S23. Obtain the current system time and verify whether the current system time is within the validity period of the user certificate.
[0081] The current system time refers to the Coordinated Universal Time (UTC) timestamp maintained by the terminal operating system kernel and synchronized with an authoritative time source when performing certificate validity verification.
[0082] Specifically, the unified authentication client obtains the precise system time by calling the standard time application programming interface (API) provided by the operating system. For example: On Windows operating systems, clients call the GetSystemTimeAsFileTime or GetSystemTimePreciseAsFileTime functions to obtain the UTC system time; on domestic operating systems based on the Linux kernel, clients call the clock_gettime function and specify the CLOCK_REALTIME clock source to obtain the UTC system time.
[0083] Understandably, in enterprise network environments, terminal operating systems typically synchronize with internal time servers periodically via the NTP protocol to ensure that their system time remains consistent and highly accurate throughout the organization. This effectively prevents misjudgments of certificate validity due to local clock drift, user manual misadjustment, or malicious tampering.
[0084] For example, when user Zhang San logs into his office computer running the UnionTech UOS system at 10:00 AM, the unified authentication client immediately triggers the certificate verification process. At this time, the client obtains the UTC timestamp "2025-05-20 02:00:00UTC" (corresponding to Beijing time 10:00:00) by calling the operating system's interface. Then, it reads the validity period field from Zhang San's user certificate and finds that its notBefore is "2023-01-01 00:00:00UTC" and notAfter is "2025-12-31 23:59:59UTC". Through comparison and verification, the current system time "2024-05-20 02:00:00UTC" is clearly within the certificate's validity period, and the time validity verification is passed.
[0085] S24. If the Group Policy template identifier is consistent with the user certificate template identifier and the current system time is within the validity period of the user certificate, then the user certificate validity verification is deemed successful and a valid result is output.
[0086] It should be noted that certificate validity verification is a dual verification process. It checks not only the validity of the certificate in terms of time, but also the validity of the certificate in terms of policy compliance. Only when both are met will the user certificate be deemed valid.
[0087] In this embodiment of the invention, the user certificate is first parsed to read the template identifier and validity period of the user certificate content. The group policy template identifier is obtained through the management platform. Based on the group policy template identifier and the template identifier of the user certificate, the identifier consistency verification is performed. The current system time is obtained and it is determined that the system time is within the certificate validity period. If both conditions are met, the certificate is determined to be valid. This dual verification mechanism ensures that the certificate used for network access is not only not expired, but also complies with the latest enterprise security policies.
[0088] Preferably, step 103 may further include the following sub-steps: Certificate verification results may also include invalid results.
[0089] S25. If the Group Policy template identifier is inconsistent with the user certificate template identifier, and / or the current system time is not within the validity period of the user certificate, an invalid result will be output, and the certificate update process will be triggered.
[0090] In this embodiment of the invention, if a certificate fails due to either policy inconsistency or expiration, the certificate is deemed invalid, and a built-in certificate update process is triggered. In this way, the network access service is ensured to be uninterrupted due to periodic certificate expiration or policy iteration, while avoiding a large number of maintenance work orders and operational costs caused by manually handling certificate expiration issues. This reduces reliance on IT administrators and makes certificate management more intelligent and efficient.
[0091] Preferably, the certificate renewal process is as follows: S31. Send a certificate update request to the management platform and receive the response information returned by the management platform for the certificate update request.
[0092] A certificate update request is a structured data message that contains at least the identity of the currently logged-in user, the reason code for triggering the update (such as policy incompatibility or expiration), and the pre-configured group policy template identifier held by the current client.
[0093] Response information is the feedback from the management platform regarding the processing of update requests. Response information includes, but is not limited to: Global status codes: A code used to quickly determine the overall status of request processing. For example, 200 represents success, 400 represents failure due to client-side data errors (such as incorrect identity format or missing template), and 500 represents failure due to internal server processing exceptions. Detailed description information: A text description corresponding to the status code, readable by the administrator or log system, explaining the specific reason for success or failure; New User Certificate Data: This core data must be included in the response message when the determination result is successful. This data segment contains the complete X.509 user certificate newly issued by the CA and conforming to the latest group policy, typically presented in PEM or DER encoded format; Certificate chain information: Optionally, when the determination result is successful, the response information may include a complete certificate chain (such as the path from the user certificate to the root CA certificate) to assist the client in building a complete trust chain; Specific error codes and reasons: When the judgment result is failure, in addition to the global status code, it should also include more granular error codes (such as AUTH_FAILED indicating identity verification failure, QUOTA_EXCEEDED indicating that the number of user certificates has exceeded the limit) and a specific description of the reason; Timestamp: The timestamp used by the management platform to generate this response is used by the client for logging and timeliness verification; Policy template identifier: Optionally, the group policy template identifier on which this certificate is based may be included again in the response information for the client to verify and record locally.
[0094] It is worth mentioning that the client sends this request to the management platform through the established SSL / TLS encrypted channel. The SSL / TLS encrypted channel refers to an end-to-end encrypted communication link established between the unified authentication client and the management platform based on the Secure Sockets Layer or Transport Layer security protocol.
[0095] S32. Based on the response information, determine whether the user certificate needs to be updated and obtain the determination result.
[0096] Understandably, the client parses this response information and makes a judgment based on specific status codes or flags. The judgment result mainly includes two states: Success: This indicates that the management platform has approved the update request and has prepared the new user certificate.
[0097] Failure: This indicates that the update request was rejected or an error occurred. The response information usually contains a specific error code (such as authentication failure, insufficient permissions, invalid template identifier, etc.).
[0098] S33. If the determination result is successful, obtain the new user certificate from the response information.
[0099] The new user certificate refers to the X.509 format certificate issued by the CA authority after the management platform verifies the legitimacy of the request, based on the latest security policy corresponding to the group policy template identifier specified in the request.
[0100] Understandably, the client extracts the certificate data from specific fields in the response message.
[0101] S34. Store the new user certificate in the certificate security storage area and bind it to the corresponding identity identifier. The new user certificate is generated by the management platform based on the latest policy corresponding to the group policy template identifier.
[0102] Understandably, the client securely writes the newly acquired user certificate into the operating system's certificate security store. After storage, the client uses an interface provided by the operating system (such as Windows' CertSetCertificateContextProperty) to associate the certificate with the current user's identity (such as UPN) or set its attributes, thereby completing the binding and ensuring that the certificate can be accurately retrieved through the identity in the future.
[0103] S35. If the determination result is failure, generate a certificate update request failure report.
[0104] A certificate update request failure report is a structured log entry that includes at least the failure timestamp, the user identity that triggered the update, the error code returned from the management platform, and a description of the reason.
[0105] It is worth mentioning that this report can be used to generate user-readable prompts on the client's local interface, or it can be uploaded to the management platform for administrators to conduct centralized audits and troubleshooting.
[0106] In this embodiment of the invention, a certificate update request is sent to the management platform and a response information is received. If the result of the response information is successful, a new user certificate is determined and stored in the certificate security storage area and bound to the identity identifier. This realizes fully automated management of the certificate lifecycle, reduces operation and maintenance intervention costs, simplifies the operation process, ensures the continuity of network access services, and improves the authentication success rate.
[0107] Step 104: If the certificate verification result is valid, configure the parameters of the network interface of the terminal system.
[0108] Preferably, step 104 may include the following sub-steps: S41. Obtain the interface type identifier of the network interface of the terminal system.
[0109] Interface type identifier refers to a unique identifier used to distinguish different physical or logical network interfaces.
[0110] Specifically, the unified authentication client enumerates and identifies currently available network interfaces by calling the operating system's native network management interface: On Windows systems, clients obtain interface information by calling the Windows Networking API and distinguish between wired interfaces (such as Ethernet adapters, identified as IF_TYPE_ETHERNET_CSMACD) or wireless interfaces (such as Wi-Fi adapters, identified as IF_TYPE_IEEE80211) based on their characteristics.
[0111] On domestic operating systems based on the Linux kernel, the client obtains the interface type by querying the device file in the / sys / class / net directory or by calling the DBus interface of NetworkManager, thereby determining whether it is wired (ethernet) or wireless (wifi).
[0112] It's worth noting that the unified authentication client not only enumerates and identifies currently available network interfaces by calling the operating system's native network management interface, but also determines their connection conditions: Wireless Condition Assessment: The client checks for the presence of a ready wireless network adapter. On Windows systems, it checks whether `wlan_interface_state` is `wlan_interface_state_connected` or `wlan_interface_state_disconnected` via the WLAN API. On Linux / domestic OSes, it queries the wireless device status using `iwconfig` or `NetworkManager`, simultaneously checking for available target SSID signals and determining the existence of the policy SSID issued by the management platform by scanning the wireless network list. Wired connection status check: The client checks the physical connection status of the wired network adapter. On Windows systems, it checks if the OperaStatus is IfOperStatusUp using GetAdaptersAddresses; on Linux / domestic OSes, it checks the physical link connectivity using ethtool or by querying the / sys / class / net / eth0 / carrier file.
[0113] It is worth mentioning that if the terminal system lacks available wired and wireless network connections, the client will abort the network configuration process and generate a clear error report indicating that no valid network card was found and the root cause.
[0114] S42. Based on the interface type identifier, determine the target authentication strategy corresponding to the interface type identifier.
[0115] A target authentication strategy refers to a set of predefined 802.1X authentication parameters that are bound to a specific interface type.
[0116] It's worth noting that these policies are configured uniformly by the administrator on the management platform and distributed to clients in batches. After obtaining the interface type identifier, the client queries its local policy configuration file or database. Specifically: When the interface type is identified as wired network, the target authentication policy may specify the use of the EAP-TLS protocol, a specific CA root certificate, and a user certificate; When the interface type is identified as a wireless network, the matching policy will include the target wireless network SSID (such as "Office-Guest") in addition to the parameters mentioned above.
[0117] When multiple conditions are met simultaneously, the best connection scheme is selected based on preset priority rules (such as wired priority) or user configuration.
[0118] S43. Configure network interface parameters based on target authentication policy.
[0119] In this embodiment of the invention, the wired or wireless interface of the terminal system is obtained, and the interface connection conditions are judged. If the conditions are met, a strategy is determined according to different interface types, and the network interface parameters are configured based on the corresponding strategy. This ensures that different network interfaces can automatically and accurately apply the authentication parameters most suitable for their connection environment without requiring manual intervention or understanding of complex network configurations by the user. This improves the compatibility and ease of use of heterogeneous terminals at the network access layer and is a key technical link to achieve a seamless experience of logging in and connecting to the network.
[0120] Step 105: Send the user certificate to the authentication server via the configured network interface to initiate 802.1X authentication and obtain the communication authentication result.
[0121] Preferably, step 105 may include the following sub-steps: S51. Submit the user certificate to the authentication server through the configured network interface to perform client authentication and obtain the client authentication result.
[0122] The client verification result refers to the conclusive status indicator obtained by the authentication server after performing a series of verifications on the user certificate submitted by the client.
[0123] Specifically, the unified authentication client, through the network interface configured in step 104, encapsulates the user certificate as the client's identity credential using the EAP-TLS authentication protocol and sends it to the authentication server. Upon receiving the user certificate, the authentication server performs the following verification operations: verifies the validity of the certificate issuer's signature, confirming it was issued by a trusted CA; checks if the certificate is within its validity period; queries the certificate revocation list to confirm the certificate has not been revoked; and verifies whether the extended key usage in the certificate includes client authentication purposes. If all the above verifications pass, the authentication server generates a client verification result of "pass"; if any verification fails, the result is "fail".
[0124] It is worth mentioning that if the verification fails, the authentication server will immediately terminate the current authentication session and return an EAP failure message containing the specific failure reason code to the client.
[0125] Upon receiving a failure response, the client will execute corresponding operations according to the predefined error handling strategy: For recoverable errors such as network fluctuations or temporary server unavailability, a retry mechanism will be automatically triggered (the number of retries and intervals can be configured); for errors that require a certificate update process, such as expired certificates or policy inconsistencies, a certificate update process will be automatically triggered; for unrecoverable errors such as certificate revocation or incorrect formatting, a detailed authentication failure log will be recorded locally, a user-visible prompt message will be generated, and subsequent authentication attempts will be stopped, awaiting intervention from the user or administrator. At the same time, the authentication failure event and its cause code will be reported to the management platform in real time for administrators to audit and troubleshoot.
[0126] S52. Receive the server certificate returned by the authentication server, and verify the authentication server based on the server certificate to obtain the server verification result.
[0127] A server certificate is a digital certificate issued by a trusted certificate authority to an authentication server, used to prove the server's identity during the 802.1X authentication process. This certificate conforms to the X.509 standard and contains key fields such as the server's public key, identity information, issuer information, validity period, and the purpose of the extended key.
[0128] The server verification result refers to the conclusive status indicator obtained by the client after verifying the certificate submitted by the authentication server.
[0129] During or after client authentication, the authentication server sends its own server certificate to the client. Upon receiving the server certificate, the unified authentication client performs the following verification operations: verifies the validity of the issuer's signature and confirms it was issued by a trusted CA; checks if the certificate is valid; queries the certificate revocation list to confirm the certificate has not been revoked; verifies that the extended key usage in the certificate includes server authentication purposes; and ensures that the subject name or subject alternate name in the certificate matches the authentication server identifier expected by the client. If all the above verifications pass, the client generates a server verification result of "pass"; if any verification fails, the result is "fail".
[0130] It is worth mentioning that if the result is unsuccessful, the client will immediately terminate the network connection attempt and mark the server as an untrusted target. The system will generate a security event log containing the specific reasons for the failure and report it to the management platform for auditing and analysis. At the same time, the client will issue a security warning to the user according to the preset policy, indicating that there may be a man-in-the-middle attack or abnormal server configuration, and prohibiting the transmission of any user credentials or sensitive data on this untrusted channel.
[0131] S53. Determine the authentication result by comparing the client authentication result with the server authentication result to obtain the communication authentication result. The condition for the communication authentication result to be passed is that both the client authentication result and the server authentication result are passed.
[0132] The communication authentication result refers to the final comprehensive judgment conclusion based on the two-way authentication between the client and the authentication server in the 802.1X authentication process.
[0133] The unified authentication client makes a final judgment based on the combined client and server verification results. Only when both the client and server verification results are passed is the communication authentication result considered successful, signifying that the two-way authentication based on the digital certificate has been successfully completed and an end-to-end trusted communication channel has been established between the client and the authentication server.
[0134] If any verification result fails, the communication authentication result is deemed unsuccessful. If the authentication result is successful, the client can proceed with subsequent network access authorization; if it fails, the client records the authentication failure log and may automatically trigger a re-authentication process after a certain delay, or wait for the user to manually initiate re-authentication. Simultaneously, authentication failure information is synchronized to the management platform in real time, providing administrators with global authentication status monitoring and fault diagnosis support.
[0135] In this embodiment of the invention, the client sends the certificate as a credential through a configured network interface, encapsulates it using the EAP-TLS authentication protocol, and sends it to the authentication server. The server verifies the certificate and sends its own certificate to the client for verification. Only when both verification results are successful will network access be authorized. This two-way certificate verification mechanism not only ensures the legitimacy of the client but also verifies the authenticity of the authentication server, effectively preventing man-in-the-middle attacks and unauthorized server impersonation, establishing an end-to-end trusted communication channel, and improving the security of the network access process.
[0136] Step 106: If the communication authentication result is successful, the terminal system is authorized to access the network.
[0137] Specifically, the client calls the operating system's underlying network configuration interface to remove the temporary access restrictions set for 802.1X authentication and set the corresponding network interface status to fully available. At the same time, the authentication server will issue the terminal's specific access permission attributes to the network access device (such as a switch or wireless controller) via the RADIUS protocol according to the pre-configured policy. These attributes may include: the VLAN ID assigned to it, the preset bandwidth rate limiting policy, the accessible IP address range, or a specific access control list (ACL). The network access device will establish a corresponding data forwarding channel for the terminal based on these authorization attributes, thereby ensuring that while the terminal obtains network connectivity, its access scope and behavior strictly comply with the enterprise security policy. Ultimately, the terminal system obtains network access capabilities that match its identity and permissions.
[0138] It is worth mentioning that the successful execution of the entire authorization process will be recorded in the audit logs of the client's local machine and the management platform, forming a complete network access traceability record.
[0139] In this embodiment of the invention, if the communication authentication result is successful, the authorized terminal system can access the network. The user can start normal network communication without any manual operation, realizing a seamless authentication experience of logging in and connecting to the network, which greatly improves the convenience of network authentication operations in heterogeneous terminal environments.
[0140] Example 2: Please see Figure 3 This invention provides a heterogeneous terminal network authentication system, applied to a unified authentication client implemented across platforms, comprising: The identity acquisition module 101 is used to respond to the user login terminal system event and obtain the identity of the currently logged-in user from the event.
[0141] The certificate determination module 102 is used to determine the user certificate corresponding to the identity identifier based on the identity identifier.
[0142] The certificate verification module 103 is used to verify the validity of user certificates and obtain the certificate verification result.
[0143] The network configuration module 104 is used to configure the parameters of the network interface of the terminal system if the certificate verification result is valid.
[0144] The authentication initiation module 105 is used to initiate 802.1X authentication of the user certificate to the authentication server through the configured network interface and obtain the communication authentication result.
[0145] The network authorization module 106 is used to authorize the terminal system to access the network if the communication authentication result is successful.
[0146] Since the above is a system corresponding to a heterogeneous terminal network authentication method, its implementation principle is the same as that of a heterogeneous terminal network authentication method. For the sake of convenience and brevity, those skilled in the art can clearly understand that the specific working process of the system and modules described above can be referred to the corresponding process in the aforementioned method embodiments, and will not be repeated here.
[0147] Example 3: An electronic device according to an embodiment of the present invention includes: a memory and a processor, wherein the memory stores a computer program; when the computer program is executed by the processor, the processor performs a heterogeneous terminal network authentication method as described in any of the above embodiments.
[0148] The memory can be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or ROM. The memory has storage space for program code used to perform any of the method steps described above. For example, the storage space for program code may include individual program codes for implementing the various steps in the methods described above. This program code can be read from or written to one or more computer program products. These computer program products include program code carriers such as hard disks, compact discs (CDs), memory cards, or floppy disks. The program code may be compressed, for example, in a suitable form. When run by a computing processing device, this code causes the computing processing device to perform the various steps in the methods described above.
[0149] Example 4: This invention provides a computer-readable storage medium storing a computer program thereon, which, when executed, implements the heterogeneous terminal network authentication method of any of the above embodiments.
[0150] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0151] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0152] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0153] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0154] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0155] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A heterogeneous terminal network authentication method, characterized in that, Unified authentication clients applicable to cross-platform implementations include: In response to a user login event to the terminal system, obtain the identity identifier of the currently logged-in user from the event; Based on the identity identifier, determine the user certificate corresponding to the identity identifier; The user certificate is validated to obtain the certificate validation result; If the certificate verification result is valid, then the network interface parameters of the terminal system are configured. The user certificate is used to initiate 802.1X authentication with the authentication server through the configured network interface to obtain the communication authentication result; If the communication authentication result is successful, the terminal system is authorized to access the network.
2. The heterogeneous terminal network authentication method according to claim 1, characterized in that, The step of determining the user certificate corresponding to the identity identifier based on the identity identifier includes: Based on the identity identifier, query the preset certificate security storage area; Determine whether a user certificate bound to the identity is present in the certificate security storage area; If it exists, the user certificate corresponding to the identity identifier is read from the certificate security storage area.
3. The heterogeneous terminal network authentication method according to claim 1 or 2, characterized in that, The certificate verification result includes a valid result; The step of verifying the validity of the user certificate to obtain the certificate verification result includes: The user certificate is parsed to obtain its template identifier and validity period. The template identifier of the user certificate is verified for consistency based on the pre-configured group policy template identifier; Obtain the current system time and verify whether the current system time is within the validity period of the user certificate; If the group policy template identifier matches the user certificate template identifier and the current system time is within the validity period of the user certificate, then the user certificate validity verification is deemed successful and the valid result is output.
4. The heterogeneous terminal network authentication method according to claim 3, characterized in that, The certificate verification result also includes an invalid result; The step of verifying the validity of the user certificate to obtain the certificate verification result further includes: If the group policy template identifier is inconsistent with the user certificate template identifier, and / or the current system time is not within the validity period of the user certificate, an invalid result will be output, and the certificate update process will be triggered.
5. The heterogeneous terminal network authentication method according to claim 4, characterized in that, The certificate update process is as follows: Initiate a certificate update request to the management platform and receive the response information returned by the management platform in response to the certificate update request; Based on the response information, a determination is made regarding the user certificate update, and a determination result is obtained; If the determination result is successful, then the new user certificate is obtained from the response information; The new user certificate is stored in the certificate security storage area and bound to the corresponding identity identifier. The new user certificate is generated by the management platform based on the latest policy corresponding to the group policy template identifier. If the determination result is failure, a certificate update request failure report will be generated.
6. The heterogeneous terminal network authentication method according to claim 1, characterized in that, If the certificate verification result is valid, then the network interface of the terminal system is configured with parameters, including: Obtain the interface type identifier of the network interface of the terminal system; Based on the interface type identifier, determine the target authentication strategy corresponding to the interface type identifier; Based on the target authentication strategy, the network interface is configured with parameters.
7. The heterogeneous terminal network authentication method according to claim 1, characterized in that, The step of initiating 802.1X authentication with the user certificate to the authentication server through the configured network interface and obtaining the communication authentication result includes: The user certificate is submitted to the authentication server through the configured network interface to perform client authentication and obtain the client authentication result. Receive the server certificate returned by the authentication server, and verify the authentication server based on the server certificate to obtain the server verification result; The authentication result is determined by comparing the client verification result with the server verification result to obtain the communication authentication result. The condition for the communication authentication result to be passed is that both the client verification result and the server verification result are passed.
8. A heterogeneous terminal network authentication system, characterized in that, Unified authentication clients applicable to cross-platform implementations include: The identity identification acquisition module is used to respond to the user login terminal system event and obtain the identity identification of the currently logged-in user from the event; The certificate determination module is used to determine the user certificate corresponding to the identity identifier based on the identity identifier; The certificate verification module is used to verify the validity of the user certificate and obtain the certificate verification result; The network configuration module is used to configure the parameters of the network interface of the terminal system if the certificate verification result is valid. The authentication initiation module is used to initiate 802.1X authentication of the user certificate to the authentication server through the configured network interface and obtain the communication authentication result; The network authorization module is used to authorize the terminal system to access the network if the communication authentication result is successful.
9. An electronic device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and executed as described in any one of claims 1 to 7 for heterogeneous terminal network authentication.
10. A computer-readable storage medium, characterized in that, The computer program is stored that can be loaded by a processor and execute the heterogeneous terminal network authentication method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Bidirectional identity authentication method between terminal and authentication gateway
CN108834146A
System and method for supporting multiple certificates of server aiming at EAP-TLS protocol
CN118199965A
Applying logged-in-user-specific 802.1x security on a multi-user client computing device
US20240146720A1