Method and device for determining cross-park user access authority

By centrally managing user access permissions across branch campuses from the headquarters campus, the problems of high costs and poor user experience in cross-campus user access permission management have been solved. This has enabled seamless access and low-cost access permission management, improving user experience and network security.

CN121744296APending Publication Date: 2026-03-27RUIJIE NETWORKS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-27
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

In existing technologies, cross-campus user access control suffers from high costs or poor user experience, especially in centralized and distributed authentication and policy solutions, which cannot simultaneously guarantee low cost and a good user experience.

Method used

Access permissions for branch campus users are managed uniformly through the access permission calculation system in the headquarters campus. The authentication access points in the branch campuses send user information to the headquarters campus. The headquarters campus determines the complete access permissions or business authorization rules based on the user information and returns them to the branch campuses for execution, avoiding the need to deploy independent access permission calculation systems in each branch campus.

Benefits of technology

It enables seamless access for users across different campuses, reduces deployment costs, improves user experience, and ensures unified management of access permissions and network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121744296A_ABST
    Figure CN121744296A_ABST
Patent Text Reader

Abstract

The invention provides a method and device for determining cross-park user access authority, the method is suitable for performing unified user access authority management on users located in a branch park through a headquarters park, and the method comprises the following steps: an authentication access point of the branch park sends user information corresponding to a user terminal to an access authority calculation system of the headquarters park; the access authority calculation system of the headquarter park receives user information corresponding to the user terminal sent by the authentication access point of the branch park; and the access permission calculation system of the headquarter park determines a complete access permission or service authorization rule corresponding to the user information according to the user information. By adopting the method, the user authentication is completed in the branch park, and the unified management of the user access authority is performed by the headquarter park, so that the deployment cost is saved while the non-inductive access of the user is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of communication technology, in particular to a method and device for determining access permission of cross-park users. BACKGROUND

[0002] In high-tech enterprises, the permissions of R&D personnel or related staff need to be finely managed. Meanwhile, for multi-park enterprises, there may be a demand for collaborative work between employees of different parks. In order to ensure the experience of employees, policy following should be implemented, that is, regardless of which park the employee is located in, the permission or experience of the employee should remain unchanged. Otherwise, when the employee moves from one park to another, the employee needs to reapply for access permission, and accordingly, the network administrator also needs to reconfigure the permission of the employee on the firewall. When the employee leaves the park, the network administrator also needs to delete the permission of the employee, which is tedious and prone to network security problems.

[0003] In related technologies, there are mainly two schemes to implement policy following. One is a distributed authentication and policy scheme, that is, an authentication system and a policy calculation system are deployed in each park, and authentication and policy calculation are completed in each branch park. However, this scheme has a high cost. The other is a centralized authentication and policy scheme, that is, only an authentication system and a policy calculation system are deployed in the headquarters park, and each branch park completes authentication through the headquarters park. After the headquarters park calculates the policy, the policy calculation result is sent to each branch park. Compared with the first scheme, this scheme has a low cost. However, since each branch park communicates with the headquarters park through the Internet, the authentication experience is greatly affected by the network quality, and the authentication experience of employees cannot be guaranteed.

[0004] How to implement a more optimal policy following scheme is a problem to be solved. SUMMARY

[0005] The present application provides a method and device for determining access permission of cross-park users, to realize the seamless access of cross-park users.

[0006] In a first aspect, the present application provides a method for determining access permission of cross-park users, which is suitable for unified user access permission management of users located in branch parks through a headquarters park, and the method comprises the following steps.

[0007] The authentication access point of the branch park sends user information corresponding to a user terminal to an access permission calculation system of the headquarters park, and the user information is used by the access permission calculation system of the headquarters park to determine complete access permission or service authorization rules corresponding to the user information.

[0008] The method for determining cross-park user access permission provided in the application, the authentication access point of the branch park sends the user information corresponding to the user terminal located in the branch park to the access permission computing system of the headquarters park, for obtaining the complete access permission or the business authorization rule corresponding to the user information; that is, the access permission of the user terminal located in the branch park is uniformly determined by the access permission computing system of the headquarters park, without separately deploying the access permission computing system in each branch park, realizing user non-sensing access while reducing deployment cost.

[0009] In a possible design, the user information includes a user name and a user IP address.

[0010] The authentication access point of the branch park sends the user information corresponding to the user terminal to the access permission computing system of the headquarters park, including:

[0011] The authentication access point of the branch park sends the user name and the user IP address to the authentication proxy point of the branch park, and the authentication proxy point of the branch park sends the user name and the user IP address to the access permission computing system of the headquarters park; the authentication proxy point of the branch park is deployed in a core switch or a convergence switch.

[0012] The access permission computing system of the headquarters park stores a plurality of user groups and the access permission corresponding to each user group, the user name is used to determine the user group to which the user name belongs, and then the access permission corresponding to the user name is determined according to the access permission corresponding to the user group; the user IP address is used to identify that the complete access permission or the business authorization rule returned by the access permission computing system of the headquarters park belongs to the user terminal corresponding to the user IP address.

[0013] In a possible design, after the authentication proxy point of the branch park sends the user name and the user IP address to the access permission computing system of the headquarters park, the method further includes:

[0014] The policy execution point of the branch park receives the complete access permission returned by the access permission computing system of the headquarters park; or the authentication proxy point of the branch park receives the business authorization rule returned by the access permission computing system of the headquarters park; the policy execution point of the branch park is deployed in a core switch or a convergence switch.

[0015] The policy execution point of the branch park receives the complete access permission, and the authentication proxy point of the branch park receives the business authorization rule, which are clearly divided in labor, avoiding excessive load.

[0016] In a possible design, after the authentication proxy point of the branch park receives the business authorization rule returned by the access permission computing system of the headquarters park, the method further includes:

[0017] The authentication proxy point of the branch park sends the service authorization rule to the authentication access point of the branch park, and the authentication access point of the branch park modifies a virtual local area network (VLAN) of the user terminal according to the service authorization rule;

[0018] After the policy enforcement point of the branch park receives the complete access right returned by the access right calculation system of the headquarters park, the method further comprises:

[0019] The policy enforcement point of the branch park modifies the basic access right of the user terminal to the complete access right.

[0020] Since the operation of modifying the VLAN of the user terminal needs to be completed by the authentication access point connected with the user terminal, after receiving the service authorization rule, the authentication proxy point of the branch park needs to send the service authorization rule to the authentication access point of the branch park again; and after receiving the complete access right, the policy enforcement point of the branch park can directly change the access right of the user terminal from the basic access right to the complete access right.

[0021] In a possible design, the user information comprises a charging message, the charging message is generated after the network attached storage (NAS) device deployed by the authentication access point of the branch park starts a charging copy function and the user terminal passes the authentication; and the charging message is used to indicate that the access right calculation system of the headquarters park determines the complete access right or the service authorization rule of the user corresponding to the charging message.

[0022] The authentication access point of the branch park sends user information corresponding to the user terminal to the access right calculation system of the headquarters park, and the user information comprises:

[0023] The authentication access point of the branch park sends the charging message to the access right calculation system of the headquarters park.

[0024] The application further provides another way for sending the user information of the user terminal of the branch park to the access right calculation system of the headquarters park, that is, sending the charging message generated after the user terminal passes the authentication to the access right calculation system of the headquarters park directly through the authentication access point of the branch park, without sending the charging message through the authentication proxy point again, so that this way is more lightweight.

[0025] In a possible design, after the authentication access point of the branch park sends the charging message to the access right calculation system of the headquarters park, the method further comprises:

[0026] The authentication access point of the branch park receives the service authorization rule returned by the access right computing system of the headquarters park, and the service authorization rule is used to instruct the authentication access point of the branch park to modify the VLAN of the user terminal; or the policy execution point of the branch park receives the complete access right returned by the access right computing system of the headquarters park and modifies the basic access right of the user terminal to the complete access right.

[0027] Corresponding to the sending of the charging message, the authentication access point of the branch park can directly receive the service authorization rule returned by the access right computing system of the headquarters park without forwarding via the authentication proxy point of the branch park.

[0028] In a possible design, before the authentication access point of the branch park sends the user information corresponding to the user terminal to the access right computing system of the headquarters park, the method further includes:

[0029] The authentication access point of the branch park receives the access request sent by the user terminal, and the access request includes the user information.

[0030] The authentication access point of the branch park sends the user information to the authentication system of the branch park, and the authentication system of the branch park is used to set a basic access right for the user terminal that passes the authentication.

[0031] The authentication access point of the branch park receives the authentication result returned by the authentication system of the branch park.

[0032] The authentication access point of the branch park sends the access request of the user terminal to the authentication system of the branch park, and then the authentication system of the branch park returns the authentication result to the authentication access point of the branch park; when the authentication is passed, the authentication access point of the branch park sends the user information corresponding to the user terminal to the access right computing system of the headquarters park; in this way, compared with the authentication in the headquarters park, the user terminal located in the branch park directly performs authentication in the branch park, which can quickly determine the authentication result, so that the user has a better user experience.

[0033] In a second aspect, the present application also provides a method for determining cross-park user access right, which is suitable for unified user access right management of users located in branch parks by a headquarters park, and the method includes:

[0034] The access right computing system of the headquarters park receives the user information corresponding to the user terminal sent by the authentication access point of the branch park.

[0035] The access right computing system of the headquarters park determines the complete access right or the service authorization rule corresponding to the user information according to the user information.

[0036] The access permission computing system of the headquarters park determines the complete access permission or the service authorization rule corresponding to the user information according to the user information after receiving the user information sent by the authentication access point of the branch park, and determines the access permission of the user terminal located in the branch park by the access permission computing system of the headquarters park, so that the strategy can be implemented while saving the deployment cost.

[0037] In a possible design, the user information includes a username and a user IP address.

[0038] The access permission computing system of the headquarters park determines the complete access permission or the service authorization rule corresponding to the user information according to the user information, including:

[0039] The access permission computing system of the headquarters park determines the user group to which the username belongs according to the username, and determines the complete access permission according to the access permission corresponding to the user group to which the username belongs; the complete access permission further includes the user IP address, which is used to instruct the policy execution point of the branch park to modify the basic access permission of the user terminal corresponding to the user IP address to the complete access permission; wherein each user group has a corresponding user role.

[0040] The access permission computing system of the headquarters park matches the username in a preconfigured service authorization rule file, and determines the service authorization rule according to the matching result; the service authorization rule further includes the user IP address, which is used to instruct the authentication access point of the branch park to modify the VLAN of the user terminal corresponding to the user IP address according to the service authorization rule.

[0041] The content contained in the user information received by the access permission computing system of the headquarters park has two cases. In one case, the user information includes a username and a user IP address, and the access permission computing system of the headquarters park stores a plurality of user groups and the access permission corresponding to each user group. The access permission computing system of the headquarters park determines the user group to which the username belongs according to the username, and takes the access permission corresponding to the user group as the access permission corresponding to the username. Since each user group corresponds to a different role, it is equivalent to determining the access permission corresponding to the username according to the role corresponding to the username. Similarly, the access permission computing system of the headquarters park also stores a service authorization rule file, and matches the username in the preconfigured service authorization rule file to determine the service authorization rule corresponding to the username.

[0042] In a possible design, after the headquarters park access permission calculation system determines the complete access permission according to the access permission corresponding to the user group to which the username belongs, the headquarters park access permission calculation system further includes:

[0043] The headquarters park permission calculation system sends the complete access permission to the policy execution point of the branch park.

[0044] After the headquarters park access permission calculation system determines the business authorization rule according to the matching result, the headquarters park access permission calculation system further includes:

[0045] The headquarters park access permission calculation system sends the business authorization rule to the authentication proxy point of the branch park.

[0046] When the user information received by the headquarters park access permission calculation system includes a username and a user IP address, after the headquarters park access permission calculation system completes the calculation, the headquarters park access permission calculation system sends the complete access permission to the policy execution point of the branch park, and sends the business authorization rule to the authentication proxy point of the branch park.

[0047] In a possible design, the user information includes a charging message; the charging message is generated after the charging copy function of the NAS device deployed by the authentication access point of the branch park is started and the user terminal is authenticated.

[0048] The headquarters park access permission calculation system determines the complete access permission or the business authorization rule corresponding to the user information according to the user information, and includes:

[0049] The headquarters park access permission calculation system generates a user table item according to the charging message, and determines the complete access permission or the business authorization rule according to the username indicated by the user table item.

[0050] Another case of the content contained in the user information received by the headquarters park access permission calculation system is that the user information includes a charging message, the headquarters park access permission calculation system can generate a user table item according to the charging message, and the user table item contains a username, therefore, the headquarters park access permission calculation system can determine the complete access permission or the business authorization rule corresponding to the username indicated by the user table item.

[0051] In a possible design, after the headquarters park access permission calculation system generates a user table item according to the charging message, and determines the complete access permission or the business authorization rule according to the username indicated by the user table item, the headquarters park access permission calculation system further includes:

[0052] The headquarters park access permission calculation system sends the complete access permission to the policy execution point of the branch park.

[0053] The headquarters park access right computing system sends the business authorization rule to the authentication access point of the branch park.

[0054] When the user information received by the headquarters park access right computing system includes a billing message, after the headquarters park access right computing system completes the calculation, the complete access right is sent to the policy execution point of the branch park, and the business authorization rule is sent to the authentication access point of the branch park.

[0055] In a third aspect, the present application also provides a device for determining cross-park user access right, which is suitable for unified user access right management of users in a branch park by a headquarters park, and comprises a transceiver unit and a processing unit; the processing unit invokes the transceiver unit to perform the following steps:

[0056] Send user information corresponding to the user terminal to the access right computing system of the headquarters park; the user information is used by the access right computing system of the headquarters park to determine complete access right or a business authorization rule corresponding to the user information.

[0057] In a possible design, the user information includes a user name and a user IP address; the transceiver unit is specifically configured to send the user name and the user IP address to the authentication proxy point of the branch park, and send the user name and the user IP address to the access right computing system of the headquarters park; the authentication proxy point of the branch park is deployed on a core switch or a convergence switch.

[0058] In a possible design, the transceiver unit is further configured to receive complete access right returned by the access right computing system of the headquarters park; or receive a business authorization rule returned by the access right computing system of the headquarters park; the policy execution point of the branch park is deployed on a core switch or a convergence switch.

[0059] In a possible design, the transceiver unit is specifically configured to send the business authorization rule to the authentication access point of the branch park; and the processing unit is specifically configured to modify a virtual local area network (VLAN) of the user terminal according to the business authorization rule, and modify basic access right of the user terminal to the complete access right.

[0060] In a possible design, the user information includes a charging message, the charging message is generated after a network attached storage (NAS) device deployed by an authentication access point of the branch park starts a charging copy function and the user terminal is authenticated successfully; the charging message is used to instruct an access right calculation system of the headquarters park to determine complete access rights or service authorization rules of a user corresponding to the charging message; and the transceiver is specifically configured to send the charging message to the access right calculation system of the headquarters park.

[0061] In a possible design, the transceiver is configured to receive service authorization rules returned by the access right calculation system of the headquarters park, and the service authorization rules are used to instruct the processing unit to modify a VLAN of the user terminal; or the transceiver is configured to receive complete access rights returned by the access right calculation system of the headquarters park, and the processing unit is configured to modify basic access rights of the user terminal to the complete access rights.

[0062] In a possible design, the transceiver is further configured to receive an access request sent by the user terminal, the access request includes the user information; and send the user information to an authentication system of the branch park and receive an authentication result returned by the authentication system of the branch park, the authentication system of the branch park is configured to set basic access rights for a user terminal that passes authentication.

[0063] In a fourth aspect, the present application provides a device for determining cross-park user access rights, the device is suitable for unified user access right management of a user located in a branch park by a headquarters park, and the device includes a transceiver and a processing unit.

[0064] The transceiver is configured to receive user information corresponding to a user terminal sent by an authentication access point of the branch park.

[0065] The processing unit is configured to determine complete access rights or service authorization rules corresponding to the user information according to the user information.

[0066] In a possible design, the processing unit is specifically configured to determine a user group to which a user name belongs according to the user name, and the access right calculation system of the headquarters park determines the complete access rights according to access rights corresponding to the user group to which the user name belongs; the complete access rights further include an IP address of the user, and the IP address of the user is used to instruct a policy enforcement point of the branch park to modify basic access rights of a user terminal corresponding to the IP address of the user to the complete access rights; and each user group has a corresponding user role.

[0067] The processing unit is further configured to match the username in a preconfigured service authorization rule file, and determine the service authorization rule according to a matching result by the access right calculation system of the headquarters park; the service authorization rule further comprises the user IP address, and is used to instruct the authentication access point of the branch park to modify the VLAN for the user terminal corresponding to the user IP address according to the service authorization rule.

[0068] In a possible design, the transceiving unit is specifically configured to send the complete access right to a policy enforcement point of the branch park, and send the service authorization rule to an authentication proxy point of the branch park.

[0069] In a possible design, the user information comprises a charging message; the charging message is generated after the authentication access point of the branch park deploys a NAS device to start a charging copy function and the user terminal passes the authentication; and the processing unit is specifically configured to generate a user entry according to the charging message, and determine the complete access right or the service authorization rule according to a username indicated by the user entry.

[0070] In a possible design, the transceiving unit is specifically configured to send the complete access right to a policy enforcement point of the branch park, and send the service authorization rule to an authentication access point of the branch park.

[0071] In a fifth aspect, the present application further provides a device for determining a cross-park user access right, comprising: a processor, and a memory connected with the processor in communication;

[0072] The memory stores computer execution instructions.

[0073] The processor executes the computer execution instructions stored in the memory, so as to implement the method in the first aspect or the second aspect.

[0074] In a sixth aspect, the present application further provides a computer readable storage medium, which comprises a program, and when the program is executed on an apparatus, the program causes the apparatus to execute the method in any one of the first aspect or the second aspect.

[0075] In a seventh aspect, the present application further provides a computer program product, which comprises a computer program, and when the computer program is executed by a processor, the computer program implements the method in the first aspect or the second aspect. BRIEF DESCRIPTION OF DRAWINGS

[0076] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments description. Obviously, the drawings described in the following embodiments are only some of the embodiments of the present application, and all other drawings obtained by those of ordinary skill in the art without creative work based on these drawings are within the scope of the present application.

[0077] Figure 1 The distributed authentication and policy scheme provided by the embodiments of the present application is shown in the figure.

[0078] Figure 2 The centralized authentication and policy scheme provided by the embodiments of the present application is shown in the figure.

[0079] Figure 3 The method flowchart for determining the access right of cross-park users provided by the embodiments of the present application is shown in the figure.

[0080] Figure 4 The system architecture adopted by the first scheme for determining the access right of cross-park users provided by the embodiments of the present application is shown in the figure.

[0081] Figure 5 The system architecture adopted by the second scheme for determining the access right of cross-park users provided by the embodiments of the present application is shown in the figure.

[0082] Figure 6 The device structure for determining the access right of cross-park users provided by the embodiments of the present application is shown in the figure. Figure 1

[0083] Figure 7 The device structure for determining the access right of cross-park users provided by the embodiments of the present application is shown in the figure. Figure 2 . DETAILED DESCRIPTION

[0084] In order to make the purpose, technical solutions and advantages of the present application more clear, the following will combine the drawings to further describe the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work are within the scope of the present application.

[0085] The application scenarios described in the embodiments of the present application are to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art can know that, with the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems. In the description of the present application, unless otherwise specified, the meaning of "multiple" is two or more.

[0086] ​​As described in the background section, in the related art, there are mainly two kinds of implementation strategies for the policy follow-up scheme, one is Figure 1 the distributed authentication and policy scheme shown in FIG. 1, Figure 1 In the distributed authentication and policy scheme, there are multiple branch parks, which are branch park 1, branch park 2,..., and branch park n. Figure 1 In the distributed authentication and policy scheme, there are multiple branch parks, which are branch park 1, branch park 2,..., and branch park n.

[0087] The other scheme is Figure 2 the centralized authentication and policy scheme shown in FIG. 2, Figure 2 In the centralized authentication and policy scheme, there are multiple branch parks and one headquarters park, and the multiple branch parks are branch park 1-n. This scheme only needs to deploy a set of authentication system and access right calculation system in the headquarters park. The users in each branch park are authenticated by the authentication system in the headquarters park and the access right is determined by the access right calculation system in the headquarters park. Compared with the first scheme, this scheme can reduce the deployment cost, but the user experience is not good. Because the data transmission between the headquarters park and the branch park is easily affected by the network quality, especially the user authentication. The user authentication process can be divided into multiple sub-steps. If one of the sub-steps fails due to poor network quality, the authentication needs to be performed again, which takes a long time and affects the user experience.

[0088] To solve the problems existing in the above two schemes, the present application provides a method for determining the access right of a cross-park user as shown in Figure 3 The method specifically includes the following steps:

[0089] Step 300: The authentication access point of the branch park sends the user information corresponding to the user terminal to the access right calculation system of the headquarters park. Correspondingly, the access right calculation system of the headquarters park receives the user information corresponding to the user terminal sent by the authentication access point of the branch park.

[0090] Step 301: The access right computing system of the headquarters park determines the complete access right or the business authorization rule corresponding to the user information according to the user information.

[0091] The present application provides two schemes for implementing the above steps 300-301, wherein the system architecture diagram of scheme one is as shown in Figure 4 The system architecture diagram of scheme two is as shown in Figure 5 .

[0092] As shown in Figure 4 , Figure 4 includes a branch park and a headquarters park, wherein the branch park includes an authentication system, a user terminal, an authentication access point, an authentication proxy point, a policy execution point and a firewall; the authentication system of the branch park is used to authenticate the user terminal located in the branch park; the authentication access point of the branch park can be deployed on a network attached storage (English: Network Attached Storage, abbreviated as NAS) device, connected with the user terminal, used to receive the access request of the user terminal, send the user information to the access right computing system of the headquarters park, and modify the virtual local area network (English: Virtual Local Area Network, abbreviated as VLAN) for the user terminal; the authentication proxy point of the branch park can also be called a radius proxy, and the authentication proxy point and the policy execution point of the branch park can be deployed on a core switch or a convergence switch; the authentication proxy point of the branch park is used to send the access request of the user terminal to the authentication system of the branch park and send the user information to the access right computing system of the headquarters park, and the policy execution point of the branch park is used to receive the complete access right returned by the access right computing system of the headquarters park and modify the access right of the user terminal according to the complete access right; the firewall of the branch park is used to monitor network attacks in real time, reduce network risks, and improve the security of communication between the branch park and the headquarters park. The headquarters park includes an access right computing system, a user terminal, an authentication access point, an authentication proxy point, a policy execution point and a firewall; wherein the authentication system of the headquarters park is used to authenticate the user terminal located in the headquarters park, and the access right computing system of the headquarters park is used to determine the complete access right or the business authorization rule corresponding to the user terminal located in the branch park and the headquarters park. In addition, Figure 4 The branch park in may also include a dynamic host configuration protocol (English: Dynamic Host Configuration Protocol, abbreviated as DHCP) server, which is managed by the access right computing system of the headquarters park, and dynamically allocates IP addresses or configuration information for the user terminals of the branch park.

[0093] It should be noted that, Figure 4The branch park in the above description is only an example, and the method for determining the access permission of the cross-park user is applicable to one branch park or multiple branch parks.

[0094] The following describes the specific process of the first implementation scheme based on the system architecture shown in Figure 4 The following describes the specific process of the first implementation scheme based on the system architecture shown in

[0095] Exemplarily, before the authentication access point of the branch park sends the user information corresponding to the user terminal to the access permission calculation system of the headquarters park, the user terminal needs to be authenticated in the branch park. Specifically, the user terminal sends an access request to the authentication access point of the branch park. For example, a user wants to log in to a business system in the branch park to handle related business. First, the user needs to input the username and user password and submit for verification in the business system login interface. This process can be understood as that the user terminal sends an access request. Correspondingly, the authentication access point of the branch park receives the access request sent by the user terminal, and the access request includes user information, such as the username input by the user, the user password input by the user, the user IP address, the user MAC address, and the like. Then, the authentication access point of the branch park sends the user information to the authentication proxy point of the branch park, and the authentication proxy point of the branch park sends the user information to the authentication system of the branch park. The authentication system of the branch park performs a series of verifications on the user information, such as verifying whether the user password is correct. If the user information is verified correctly, it means that the user information authentication is passed. In order to reduce the delay and improve the user experience, the user terminal can be set with basic access permission after the user terminal is authenticated. For example, it is assumed that the business system includes multiple user roles, and the access permission levels corresponding to the user roles from low to high are a browsing user, a first-level administrator, a second-level administrator, and an admin administrator. After the user terminal is authenticated, the browsing user role corresponding access permission can be set for the user terminal. Finally, the authentication system of the branch park returns the authentication result of the user information to the authentication proxy point of the branch park, and the authentication proxy point of the branch park returns the authentication result to the authentication access point of the branch park.

[0096] Exemplarily, after the authentication access point of the branch park receives the authentication result returned by the authentication system of the branch park, if the authentication result indicates that the authentication fails, the user terminal can resubmit an access request, and the authentication access point of the branch park sends the new access request to the authentication system of the branch park, and the authentication system of the branch park performs authentication again; if the authentication result indicates that the authentication passes, the authentication access point of the branch park can send the user information corresponding to the user terminal to the access right calculation system of the headquarters park, to obtain the complete access right or the business authorization rule corresponding to the user information; wherein the complete access right can be understood as the real access right of the user, for example, a user passes the authentication and obtains the access right corresponding to the user role, but actually the role of the user is a secondary administrator, and the complete access right of the user is the access right corresponding to the secondary administrator role.

[0097] Exemplarily, after the authentication of the user terminal passes, the authentication access point of the branch park sends the user information to the authentication proxy point of the branch park, at this time, the user information includes the user name and the user IP address, in other words, the authentication access point of the branch park sends the user name and the user IP address to the authentication proxy point of the branch park, and then the authentication proxy point of the branch park sends the user name and the user IP address to the access right calculation system of the headquarters park. Specifically, the authentication proxy point of the branch park sends the user name and the user IP address to the access right calculation system of the headquarters park by using the Google Remote Procedure Call (gRPC) protocol, and the gRPC protocol is based on the Hypertext Transfer Protocol 2.0 (HTTP2.0) and has high transmission speed and is relatively stable. Accordingly, the access right calculation system of the headquarters park receives the user name and the user IP address sent by the authentication proxy point of the branch park, and determines the corresponding complete access right or business authorization rule according to the user name and the user IP address.

[0098] Exemplarily, a plurality of user groups and corresponding access permissions of each user group are stored in the access permission computing system of the headquarters park, and each user group corresponds to a different user role; the access permission computing system of the headquarters park determines the user group to which the received username belongs, and then determines the complete access permission according to the access permission corresponding to the user group to which the username belongs. Since each user group corresponds to a different user role, it is equivalent to determining the complete access permission according to the user role corresponding to the username. For example, assuming that the access permission computing system of the headquarters park stores four user groups, namely user group 1 to user group 4, each user group includes a plurality of usernames, and the user role corresponding to user group 1 is a browsing user, the user role corresponding to user group 2 is a first-level administrator, the user role corresponding to user group 3 is a second-level administrator, and the user role corresponding to user group 4 is an admin administrator. If the access permission computing system of the headquarters park determines that the user group to which the username belongs is user group 3, then the complete access permission corresponding to the user is the access permission corresponding to the second-level administrator role.

[0099] Further exemplarily, after the access permission computing system of the headquarters park determines the complete access permission according to the access permission corresponding to the user group to which the username belongs, the access permission computing system of the headquarters park sends the complete access permission to the policy execution point of the branch park through the network configuration protocol (English: Network Configuration Protocol, abbreviated as NETCONF). Correspondingly, the policy execution point of the branch park receives the complete access permission returned by the access permission computing system of the headquarters park. In addition, the complete access permission also includes a user IP address, which is used to instruct the policy execution point of the branch park to modify the basic access permission of the user terminal corresponding to the user IP address to the complete access permission; for example, assuming that the complete access permission is “second-level administrator, 1.1.1.1”, then the complete access permission instructs the policy execution point of the branch park to modify the access permission of the user terminal with the IP address 1.1.1.1 to the access permission corresponding to the second-level administrator role.

[0100] Exemplarily, the access permission computing system of the headquarters park also stores a preconfigured service authorization rule file, which is used for the access permission computing system of the headquarters park to determine the service authorization rule according to the user information. Specifically, the access permission computing system of the headquarters park matches the received username in the preconfigured service authorization rule file, and determines the service authorization rule according to the matching result; the service authorization rule is in the format of a change of authorization (English: Change of Authorization, abbreviated as CoA) message, and the CoA message can include a VLAN, which is used to instruct the authentication access point of the branch park to modify the VLAN of the user terminal.

[0101] Further exemplarily, after the headquarters park access right computing system determines the business authorization rule according to the matching result, the headquarters park access right computing system sends the business authorization rule to the authentication proxy point of the branch park through a remote authentication dial-in user service (RADIUS) protocol. Correspondingly, the authentication proxy point of the branch park receives the business authorization rule returned by the headquarters park access right computing system, and sends the business authorization rule to the authentication access point of the branch park, and the authentication access point of the branch park modifies the VLAN of the user terminal according to the business authorization rule. In addition, the business authorization rule also includes a user IP address, which is used to instruct the authentication access point of the branch park to modify the VLAN of the user terminal corresponding to the user IP address according to the business authorization rule. For example, assuming that the business authorization rule is "30, 2.2.2.2", the business authorization rule instructs the authentication access point of the branch park to modify the VLAN of the user terminal with the IP address 2.2.2.2 to 30.

[0102] It should be noted that the business authorization rule can also be used to instruct the authentication access point of the branch park to modify the access control list (ACL) of the user terminal. The ACL can control the access right of the user to the network resource, for example, the ACL can control the access right of the user to the network flow or the database, etc., therefore, the modification of the ACL is also a way to modify the access right of the user.

[0103] The following introduces the specific process of the second scheme based on the system architecture shown in Figure 5

[0104] As shown in Figure 5 Figure 5 ​​The system comprises a branch park and a headquarters park, wherein the branch park comprises an authentication system, a user terminal, an authentication access point, a policy enforcement point and a firewall; the authentication system of the branch park is configured to authenticate the user terminal located in the branch park; the authentication access point of the branch park is configured to be deployed on a NAS device, connected with the user terminal, configured to receive an access request of the user terminal, send user information to the access right calculation system of the headquarters park, and modify a VLAN for the user terminal; the policy enforcement point of the branch park is configured to be deployed on a core switch or a convergence switch, configured to receive complete access rights returned by the access right calculation system of the headquarters park, and modify the access right of the user terminal according to the complete access rights; the firewall of the branch park is configured to monitor network attacks in real time, reduce network risks, and improve the security of communication between the branch park and the headquarters park; the headquarters park comprises an access right calculation system, a user terminal, an authentication access point, a policy enforcement point and a firewall; the authentication system of the headquarters park is configured to authenticate the user terminal located in the headquarters park, and the access right calculation system of the headquarters park is configured to determine complete access rights and business authorization rules corresponding to the user terminal located in the branch park and the headquarters park.

[0105] Similarly to scheme one, before the authentication access point of the branch park sends the user information corresponding to the user terminal to the access right calculation system of the headquarters park, the user terminal needs to be authenticated in the branch park, specifically, the authentication access point of the branch park sends the access request of the user terminal to the authentication system of the branch park; correspondingly, the authentication system of the branch park returns the authentication result to the authentication access point of the branch park.

[0106] Exemplarily, the NAS device deployed by the authentication access point of the branch park has a charging copy function, the charging copy function refers to that the NAS device records the use of network resources by the user terminal after the user terminal is authenticated, for example, the type of service used, the start time, the data flow, etc., and the recorded content can be referred to as a charging message. Scheme two needs to enable the charging copy function of the NAS device, so that when the user terminal connected with the authentication access point of the branch park is authenticated, the authentication access point of the branch park generates the charging message corresponding to the user terminal. Generally, after the user terminal is authenticated, the user terminal is allowed to log in and the basic access right of the user terminal is set. For scheme two, a safer way to grant the user terminal to log in is provided: after the user terminal is authenticated, the user terminal is not allowed to log in, but after the charging message is sent to the access right calculation system of the headquarters park, and the access right calculation system of the headquarters park also authenticates the charging message, the user terminal is allowed to log in, that is, the user terminal is allowed to log in after the authentication system of the branch park and the access right calculation system of the headquarters park are both authenticated, which is equivalent to that the user is allowed to log in after two verifications, and has better security.

[0107] Exemplarily, after the user terminal is authenticated, the authentication access point of the branch park sends the user information to the access right computing system of the headquarters park through the RADIUS protocol, and at this time, the user information includes a charging message. As known from the above, the charging message is generated after the authentication access point of the branch park deploys the NAS device to start the charging copy function and the user terminal is authenticated, and is used to instruct the access right computing system of the headquarters park to determine the complete access right or the service authorization rule of the user corresponding to the charging message.

[0108] Exemplarily, after the access right computing system of the headquarters park receives the charging message, the user table item is generated according to the charging message, and the complete access right is determined according to the username indicated by the user table item. Specifically, the generated user table item includes the username and the user IP address, the access right computing system of the headquarters park determines the user group to which the username belongs according to the username indicated by the user table item, and then determines the complete access right according to the access right corresponding to the user group to which the username belongs.

[0109] Further exemplarily, after the access right computing system of the headquarters park determines the complete access right according to the username indicated by the user table item, the access right computing system of the headquarters park sends the complete access right to the policy execution point of the branch park by using the NETCONF protocol; correspondingly, the policy execution point of the branch park receives the complete access right returned by the access right computing system of the headquarters park and modifies the basic access right of the user terminal to the complete access right.

[0110] Exemplarily, the access right computing system of the headquarters park can also determine the corresponding service authorization rule according to the username indicated by the user table item. Specifically, the access right computing system of the headquarters park matches the username indicated by the user table item in the preconfigured service authorization rule file, and determines the service authorization rule according to the matching result.

[0111] Further exemplarily, after the access right computing system of the headquarters park determines the service authorization rule according to the username indicated by the user table item, the access right computing system of the headquarters park sends the service authorization rule to the authentication access point of the branch park by using the RADIUS protocol; correspondingly, the authentication access point of the branch park receives the service authorization rule returned by the access right computing system of the headquarters park and modifies the VLAN of the user terminal according to the service authorization rule.

[0112] Compared with scheme one, the data transmission between the authentication access point of the branch park and the access right calculation system of the headquarters park does not need to pass through the authentication proxy point of the branch park, so it is more lightweight and fast; but the transmission protocol adopted between the authentication proxy point of the branch park and the access right calculation system of the headquarters park in scheme one is gRPC protocol and NETCONF protocol, which is more stable than the RADIUS protocol adopted between the authentication access point of the branch park and the access right calculation system of the headquarters park, so the transmission process between the authentication proxy point of the branch park and the access right calculation system of the headquarters park is more stable and reliable; the above two schemes can be selected according to actual business needs.

[0113] The method for determining cross-park user access rights provided in the application can realize the cross-park user access without feeling by deploying a set of access right calculation systems in the headquarters park, without deploying access right calculation systems in each branch park, which can reduce the deployment cost; and the authentication of the user terminal in the branch park can improve the user experience.

[0114] Figure 6 And Figure 7 The structure diagram of the possible device for determining cross-park user access rights provided for the embodiments of the application. These devices for determining cross-park user access rights can be used to realize the functions of the authentication access point of the branch park in the above-mentioned method embodiments, or to realize the functions of the access right calculation system of the headquarters park in the above-mentioned method embodiments, so as to also realize the beneficial effects possessed by the above-mentioned method embodiments.

[0115] As Figure 6 shown, the device for determining cross-park user access rights 600 includes a transceiver unit 610 and a processing unit 620, and the device for determining cross-park user access rights 600 is suitable for unified user access right management of users located in branch parks by the headquarters park; the device for determining cross-park user access rights 600 is used to realize the functions of the authentication access point of the branch park or the access right calculation system of the headquarters park in the above-mentioned method embodiments. Figure 3

[0116] When the device for determining cross-park user access rights 600 is used to realize the functions of the authentication access point of the branch park in the method embodiments shown in Figure 3 , the processing unit 620 calls the transceiver unit 610 to perform the following steps:

[0117] send the user information corresponding to the user terminal to the access right calculation system of the headquarters park; the user information is used by the access right calculation system of the headquarters park to determine the complete access right or the business authorization rule corresponding to the user information.

[0118] ​In a possible design, the user information includes a username and a user IP address; the transceiver 610 is specifically configured to send the username and the user IP address to the authentication proxy point of the branch campus, and send the username and the user IP address to the access right calculation system of the headquarters campus; and the authentication proxy point of the branch campus is deployed on a core switch or an aggregation switch.

[0119] In a possible design, the transceiver 610 is further configured to receive complete access rights returned by the access right calculation system of the headquarters campus; or receive service authorization rules returned by the access right calculation system of the headquarters campus; and the policy enforcement point of the branch campus is deployed on a core switch or an aggregation switch.

[0120] In a possible design, the transceiver 610 is specifically configured to send the service authorization rules to the authentication access point of the branch campus; and the processor 620 is specifically configured to modify a virtual local area network (VLAN) of the user terminal and modify basic access rights of the user terminal to the complete access rights according to the service authorization rules.

[0121] In a possible design, the user information includes a charging packet, the charging packet is generated after a network attached storage (NAS) device deployed by the authentication access point of the branch campus starts a charging copy function and the user terminal passes authentication; the charging packet is used to instruct the access right calculation system of the headquarters campus to determine complete access rights or service authorization rules of a user corresponding to the charging packet; and the transceiver is specifically configured to send the charging packet to the access right calculation system of the headquarters campus.

[0122] In a possible design, the transceiver 610 is configured to receive service authorization rules returned by the access right calculation system of the headquarters campus, and the service authorization rules are used to instruct the processor to modify a VLAN of the user terminal; or the transceiver 610 is configured to receive complete access rights returned by the access right calculation system of the headquarters campus, and the processor 620 is configured to modify basic access rights of the user terminal to the complete access rights.

[0123] In a possible design, the transceiver 610 is further configured to receive an access request sent by the user terminal, the access request including the user information; and send the user information to the authentication system of the branch campus and receive an authentication result returned by the authentication system of the branch campus, the authentication system of the branch campus being configured to set basic access rights for a user terminal that passes authentication.

[0124] The apparatus 600 for determining cross-campus user access rights is configured to implementFigure 3 The method embodiment shown is used to implement the function of the headquarters park access permission calculation system:

[0125] The transceiver 610 is configured to receive user information corresponding to the user terminal sent by the authentication access point of the branch park;

[0126] The processing unit 620 is configured to determine complete access permissions or service authorization rules corresponding to the user information according to the user information.

[0127] In a possible design, the processing unit 620 is specifically configured to determine a user group to which the username belongs according to the username, and the headquarters park access permission calculation system determines the complete access permissions according to the access permissions corresponding to the user group to which the username belongs; the complete access permissions further include the user IP address, which is used to instruct the policy execution point of the branch park to modify the basic access permissions of the user terminal corresponding to the user IP address to the complete access permissions; wherein each user group has a corresponding user role.

[0128] The processing unit 620 is further configured to match the username in a preconfigured service authorization rule file, and the headquarters park access permission calculation system determines the service authorization rules according to the matching result; the service authorization rules further include the user IP address, which is used to instruct the authentication access point of the branch park to modify the VLAN for the user terminal corresponding to the user IP address according to the service authorization rules.

[0129] In a possible design, the transceiver 610 is specifically configured to send the complete access permissions to the policy execution point of the branch park; and send the service authorization rules to the authentication proxy point of the branch park.

[0130] In a possible design, the user information includes a charging packet; the charging packet is generated after the charging copy function of the NAS device deployed by the authentication access point of the branch park is started and the user terminal is authenticated; and the processing unit 620 is specifically configured to generate a user table item according to the charging packet, and determine the complete access permissions or the service authorization rules according to the username indicated by the user table item.

[0131] In a possible design, the transceiver 610 is specifically configured to send the complete access permissions to the policy execution point of the branch park; and send the service authorization rules to the authentication access point of the branch park.

[0132] For more detailed description of the transceiver 610 and the processing unit 620, please refer to Figure 3The relevant descriptions in the method embodiments shown are directly obtained and will not be repeated here.

[0133] like Figure 7 As shown, the apparatus 700 for determining cross-campus user access permissions includes a processor 710 and an interface circuit 720. The processor 710 and the interface circuit 720 are coupled to each other. It is understood that the interface circuit 720 can be a transceiver or an input / output interface. Optionally, the apparatus 700 for determining cross-campus user access permissions may further include a memory 730 for storing instructions executed by the processor 710, or storing input data required for the processor 710 to execute instructions, or storing data generated after the processor 710 executes instructions.

[0134] When the device 500 for determining cross-park user access permissions is used to implement Figure 3 In the method shown, the processor 710 is used to implement the functions of the processing unit 620, and the interface circuit 720 is used to implement the functions of the transceiver unit 610.

[0135] The unit division in this embodiment is illustrative and represents only one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into a single processor, exist as separate physical units, or be integrated into a single unit. The integrated units described above can be implemented in hardware or as software functional units.

[0136] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0137] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A method for determining cross-park user access permissions, characterized in that, The method is suitable for unified user access permission management of users in branch parks by a headquarters park, and includes the following steps: The authentication access point of the branch park sends user information corresponding to the user terminal to the access permission calculation system of the headquarters park; the user information is used for the access permission calculation system of the headquarters park to determine complete access permission or service authorization rules corresponding to the user information.

2. The method of claim 1, wherein, The user information includes a user name and a user IP address; The authentication access point of the branch park sends user information corresponding to the user terminal to the access permission calculation system of the headquarters park, including the following steps: The authentication access point of the branch park sends the user name and the user IP address to the authentication proxy point of the branch park, and the authentication proxy point of the branch park sends the user name and the user IP address to the access permission calculation system of the headquarters park; the authentication proxy point of the branch park is deployed on a core switch or a convergence switch.

3. The method of claim 2, wherein, After the authentication proxy point of the branch park sends the user name and the user IP address to the access permission calculation system of the headquarters park, the following steps are further included: The policy execution point of the branch park receives complete access permission returned by the access permission calculation system of the headquarters park; or the authentication proxy point of the branch park receives service authorization rules returned by the access permission calculation system of the headquarters park; the policy execution point of the branch park is deployed on a core switch or a convergence switch.

4. The method of claim 3, wherein, After the authentication proxy point of the branch park receives the service authorization rules returned by the access permission calculation system of the headquarters park, the following steps are further included: The authentication proxy point of the branch park sends the service authorization rules to the authentication access point of the branch park, and the authentication access point of the branch park modifies a virtual local area network (VLAN) of the user terminal according to the service authorization rules. After the policy execution point of the branch park receives the complete access permission returned by the access permission calculation system of the headquarters park, the following steps are further included: The policy execution point of the branch park modifies the basic access permission of the user terminal to the complete access permission.

5. The method of claim 1, wherein, The user information includes a charging message, the charging message is generated after a network attached storage (NAS) device deployed by the authentication access point of the branch park starts a charging copy function and the user terminal is authenticated; the charging message is used for the access permission calculation system of the headquarters park to determine complete access permission or service authorization rules of a user corresponding to the charging message; The authentication access point of the branch park sends the charging message to the access permission calculation system of the headquarters park. After the authentication access point of the branch park sends the charging message to the access permission calculation system of the headquarters park, the following steps are further included:

6. The method of claim 5, wherein, ​ The authentication access point of the branch park receives the service authorization rule returned by the access right calculation system of the headquarters park, and the service authorization rule is used to instruct the authentication access point of the branch park to modify the VLAN of the user terminal; or the policy execution point of the branch park receives the complete access right returned by the access right calculation system of the headquarters park and modifies the basic access right of the user terminal to the complete access right.

7. The method of any one of claims 1-6, wherein, Before the authentication access point of the branch park sends the user information corresponding to the user terminal to the access right calculation system of the headquarters park, the method further comprises: The authentication access point of the branch park receives the access request sent by the user terminal, and the access request comprises the user information; The authentication access point of the branch park sends the user information to the authentication system of the branch park, and the authentication system of the branch park is used to set the basic access right for the user terminal that passes the authentication; The authentication access point of the branch park receives the authentication result returned by the authentication system of the branch park.

8. A method of determining cross-farm user access rights, the method comprising: The method is suitable for unified user access right management of users located in the branch park through the headquarters park, comprising: The access right calculation system of the headquarters park receives the user information corresponding to the user terminal sent by the authentication access point of the branch park; The access right calculation system of the headquarters park determines the complete access right or the service authorization rule corresponding to the user information according to the user information.

9. The method of claim 8, wherein, The user information comprises a user name and a user IP address; The access right calculation system of the headquarters park determines the complete access right or the service authorization rule corresponding to the user information according to the user information, comprising: The access right calculation system of the headquarters park determines the user group to which the user name belongs according to the user name, and determines the complete access right according to the access right corresponding to the user group to which the user name belongs; the complete access right further comprises the user IP address, which is used to instruct the policy execution point of the branch park to modify the basic access right of the user terminal corresponding to the user IP address to the complete access right; wherein each user group has a corresponding user role; The access right calculation system of the headquarters park matches in a preconfigured service authorization rule file according to the user name, and determines the service authorization rule according to the matching result; the service authorization rule further comprises the user IP address, which is used to instruct the authentication access point of the branch park to modify the VLAN of the user terminal corresponding to the user IP address according to the service authorization rule.

10. The method of claim 9, wherein, After the access right calculation system of the headquarters park determines the complete access right according to the access right corresponding to the user group to which the user name belongs, the method further comprises: The access right calculation system of the headquarters park sends the complete access right to the policy execution point of the branch park; After the access right calculation system of the headquarters park determines the service authorization rule according to the matching result, the method further comprises: The headquarters park access right computing system sends the business authorization rule to the authentication proxy point of the branch park.

11. The method of claim 8, wherein, The user information includes a charging message; the charging message is generated after the authentication access point of the branch park deploys a NAS device to start a charging copy function and the user terminal authentication is passed; The headquarters park access right computing system determines the complete access right or the business authorization rule corresponding to the user information according to the user information, including: The headquarters park access right computing system generates a user table item according to the charging message, and determines the complete access right or the business authorization rule according to the username indicated by the user table item.

12. The method of claim 11, wherein, After the headquarters park access right computing system generates a user table item according to the charging message, and determines the complete access right or the business authorization rule according to the username indicated by the user table item, it further includes: The headquarters park access right computing system sends the complete access right to the policy execution point of the branch park; The headquarters park access right computing system sends the business authorization rule to the authentication access point of the branch park.

13. An apparatus for determining cross-farm user access rights, the apparatus comprising: The device is suitable for unified user access right management of users in the branch park through the headquarters park, including a transceiver unit and a processing unit; the processing unit calls the transceiver unit to execute: Send the user information corresponding to the user terminal to the access right computing system of the headquarters park; The user information is used for the access right computing system of the headquarters park to determine the complete access right or the business authorization rule corresponding to the user information.

14. An apparatus for determining cross-farm user access rights, the apparatus comprising: The device is suitable for unified user access right management of users in the branch park through the headquarters park, including: a transceiver unit and a processing unit; The transceiver unit is configured to receive the user information corresponding to the user terminal sent by the authentication access point of the branch park; The processing unit is configured to determine the complete access right or the business authorization rule corresponding to the user information according to the user information.

15. An apparatus for determining cross-farm user access rights, the apparatus comprising: Including: A processor and a memory connected with the processor in communication; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory to realize the method in any one of claims 1-12.

16. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to realize the method in any one of claims 1-12.

17. A computer program product, characterised in that, The computer program is executed by the processor to realize the method in any one of claims 1-12.