Access authentication methods, devices, equipment, storage media, and computer program products
By introducing dual authentication of encrypted biometric data and pre-shared keys into access authentication, and combining it with machine learning models to identify abnormal behavior, the problem of insufficient security of single-key authentication is solved, and higher access authentication security and intelligent management are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING HONGTENG INTELLIGENT TECH CO LTD
- Filing Date
- 2026-03-25
- Publication Date
- 2026-05-26
Smart Images

Figure CN122093166A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to an access authentication method, apparatus, device, storage medium, and computer program product. Background Technology
[0002] Currently, access authentication technologies (such as fwknop) typically implement covert firewall authentication based on Single Packet Authorization (SPA). The core mechanism involves the client sending an encrypted SPA packet containing a pre-shared key; the server verifies the packet and then opens the port. This is widely used in scenarios such as remote management and intranet access. However, because these access authentication technologies usually use a single pre-shared key for authentication, they are vulnerable to breaches of protection if the key is stolen, resulting in insufficient security. Summary of the Invention
[0003] The main purpose of this application is to provide an access authentication method, apparatus, device, storage medium, and computer program product, which aims to solve the technical problem that related access authentication technologies usually use a single pre-shared key for access authentication, resulting in easy breach of protection and insufficient security after the key is stolen.
[0004] To achieve the above objectives, this application provides an access authentication method, which is applied to a server and includes: The system receives a converged authorization protocol packet sent by a user terminal, wherein the extended field of the converged authorization protocol packet contains encrypted biometric data, and the converged authorization protocol packet also includes encrypted access request information encrypted with a pre-shared key. The encrypted biometric data and the encrypted access request information are decrypted respectively to obtain the biometric data and access request information. The biometric data and the access request information are verified respectively, and the access request of the user terminal is authenticated based on the verification results.
[0005] Optionally, the step of verifying the biometric data and the access request information respectively, and authenticating the access request of the user terminal based on the verification results, includes: The access request information is parsed to obtain key verification data, and the key verification data is matched and verified with the pre-shared key of the corresponding user pre-stored on the server to obtain the first-level verification result; If the first layer of verification results in a successful verification, the biometric data is matched and compared with the biometric template of the corresponding user pre-stored on the server to obtain the second layer of verification result. If the second-layer verification result is a successful comparison, then the user terminal's access request authentication is deemed successful. If the first layer of verification results in failure, or the second layer of verification results in failure to match, then the user terminal's access request authentication is deemed unsuccessful.
[0006] Optionally, before receiving the converged authorization protocol packet sent by the user terminal, the method further includes: Receive user identity information and biometric templates uploaded by user terminals through an encrypted secure channel; Negotiate encryption verification parameters with the user terminal, and allocate a pre-shared key to the user based on the negotiation result; The identity information, the biometric template, and the pre-shared key are stored on the server.
[0007] Optionally, after verifying the biometric data and the access request information respectively, and authenticating the user terminal's access request based on the verification results, the method further includes: Collect multidimensional behavioral features corresponding to this visit; Abnormal access behavior is identified based on the multidimensional behavioral features and the preset machine learning fusion model.
[0008] Optionally, the step of identifying abnormal access behavior based on the multidimensional behavioral features and the preset machine learning fusion model includes: The multidimensional behavioral features are standardized and preprocessed to obtain the feature data to be detected; The feature data to be detected is input into a preset machine learning fusion model. The preset machine learning fusion model compares the feature data to be detected with the baseline of the normal access behavior of the corresponding user to obtain the abnormality of the behavior of this access. If the abnormality of the behavior is greater than or equal to the abnormality judgment threshold, then this access is determined to be an abnormal access behavior; If the abnormality level of the behavior is less than the abnormality judgment threshold, then the current access is determined to be a normal access behavior.
[0009] Optionally, before receiving the converged authorization protocol packet sent by the user terminal, the method further includes: Collect legitimate access behavior data of target users within a preset historical period, and extract multidimensional historical behavior features from the legitimate access behavior data; The multidimensional historical behavior features are standardized and preprocessed to obtain the model training sample set; The initial machine learning model is trained based on the model training sample set to obtain a preset machine learning fusion model; Based on the statistical distribution patterns of the multidimensional historical behavior characteristics, a baseline for normal access behavior and anomaly detection thresholds for the target user are constructed.
[0010] Optionally, after identifying abnormal access behavior based on the multidimensional behavioral features and the preset machine learning fusion model, the method further includes: If the access request fails authentication or abnormal access behavior is detected, the access connection will be rejected. A preset automated processing procedure is triggered, and the access is processed based on the preset automated processing procedure.
[0011] Optionally, triggering a preset automated processing procedure and processing the access based on the preset automated processing procedure includes at least one of the following: Revocation operation is performed on the pre-shared key associated with this access, and the pre-shared key is marked as abnormally disabled; Clean up any temporary access rules in the firewall associated with the pre-shared key and close the corresponding open ports; An anomaly alarm is generated based on the abnormal feature data corresponding to this access, and the anomaly alarm is pushed to the management terminal.
[0012] Optionally, after identifying abnormal access behavior based on the multidimensional behavioral features and the preset machine learning fusion model, the method further includes: If the access request is successfully authenticated and no abnormal access behavior is detected, a temporary access control rule is generated based on the access request information, and a corresponding authorized access validity period is configured for the temporary access control rule. The temporary access control rule is sent to the firewall for execution, opening the target access port corresponding to the access request information, and granting the user terminal access to the corresponding intranet resources. When the authorized access period expires, the corresponding temporary access control rule in the firewall is automatically cleared and the target access port is closed. The multidimensional behavioral features corresponding to this visit are stored in the legitimate access behavior dataset to update the normal access behavior baseline of the corresponding user, and the preset machine learning fusion model is incrementally optimized.
[0013] Furthermore, to achieve the above objectives, this application also provides an access authentication method, which is applied to a user terminal, and the access authentication method includes: In response to an access request to a target network, the user's biometric data is collected and encrypted to obtain encrypted biometric data. The access request information corresponding to the access request is encrypted using a pre-shared key to obtain the encrypted access request information; The encrypted biometric data is embedded into the extended fields corresponding to the authorization protocol packet, and combined with the encrypted access request information to generate a fused authorization protocol packet; The converged authorization protocol packet is sent to the server corresponding to the target network, so that the server authenticates the access request based on the converged authorization protocol packet.
[0014] Optionally, before the step of collecting the user's biometric data in response to an access request for the target network and encrypting the biometric data to obtain the encrypted biometric data, the method further includes: In response to a user's registration configuration request, the system collects the user's baseline biometric data and generates a biometric template that conforms to a preset format standard. The user's identity information and biometric template are uploaded to the server corresponding to the target network through an encrypted secure channel; Negotiate encryption verification parameters with the server to obtain the pre-shared key assigned to the user by the server.
[0015] Furthermore, to achieve the above objectives, this application also proposes an access authentication device applied to a server, the access authentication device comprising: The receiving module is used to receive a converged authorization protocol packet sent by a user terminal, wherein the extended field of the converged authorization protocol packet contains encrypted biometric data, and the converged authorization protocol packet also includes encrypted access request information encrypted with a pre-shared key; The decryption module is used to decrypt the encrypted biometric data and the encrypted access request information respectively to obtain the biometric data and the access request information. The verification module is used to verify the biometric data and the access request information respectively, and to authenticate the access request of the user terminal based on the verification results.
[0016] Optionally, the verification module is further configured to parse the access request information to obtain key verification data, and match and verify the key verification data with the pre-shared key of the corresponding user pre-stored on the server to obtain a first-level verification result; if the first-level verification result is successful, the biometric data is matched and compared with the biometric template of the corresponding user pre-stored on the server to obtain a second-level verification result; if the second-level verification result is successful, the access request authentication of the user terminal is determined to be successful; if the first-level verification result is unsuccessful, or the second-level verification result is unsuccessful, the access request authentication of the user terminal is determined to be unsuccessful.
[0017] Optionally, the access authentication device further includes: The storage module is used to receive the user's identity information and biometric template uploaded by the user terminal through an encrypted secure channel; negotiate encryption verification parameters with the user terminal and allocate a pre-shared key to the user according to the negotiation result; and store the identity information, the biometric template and the pre-shared key on the server side.
[0018] Optionally, the access authentication device further includes: The identification module is used to collect multi-dimensional behavioral features corresponding to this visit; and to identify abnormal access behavior based on the multi-dimensional behavioral features and a preset machine learning fusion model.
[0019] Optionally, the identification module is used to perform standardized preprocessing on the multidimensional behavioral features to obtain feature data to be detected; input the feature data to be detected into a preset machine learning fusion model, and compare the feature data to be detected with the baseline of the normal access behavior of the corresponding user through the preset machine learning fusion model to obtain the behavioral abnormality degree of this access; if the behavioral abnormality degree is greater than or equal to the abnormality judgment threshold, then the access is determined to be abnormal access behavior; if the behavioral abnormality degree is less than the abnormality judgment threshold, then the access is determined to be normal access behavior.
[0020] Furthermore, to achieve the above objectives, this application also proposes an access authentication device applied to a user terminal, the access authentication device comprising: The acquisition module is used to collect the user's biometric data in response to an access request to the target network, and to encrypt the biometric data to obtain encrypted biometric data. The encryption module is used to encrypt the access request information corresponding to the access request using a pre-shared key to obtain the encrypted access request information; The fusion module is used to embed the encrypted biometric data into the extended fields corresponding to the authorization protocol packet, and to generate a fused authorization protocol packet by combining the encrypted access request information. The sending module is used to send the converged authorization protocol packet to the server corresponding to the target network, so that the server can authenticate the access request according to the converged authorization protocol packet.
[0021] In addition, to achieve the above objectives, this application also proposes an access authentication device, which includes a memory, a processor, and an access authentication program stored in the memory and executable on the processor, the access authentication program being configured to implement the access authentication method as described above.
[0022] In addition, to achieve the above objectives, this application also proposes a storage medium storing an access authentication program, which, when executed by a processor, implements the access authentication method as described above.
[0023] In addition, to achieve the above objectives, this application also provides a computer program product, which includes an access authentication program that, when executed by a processor, implements the access authentication method as described above.
[0024] One or more technical solutions proposed in this application have at least the following technical effects: This application discloses receiving a converged authorization protocol packet sent by a user terminal. The extended fields of the converged authorization protocol packet embed encrypted biometric data. The converged authorization protocol packet also includes encrypted access request information encrypted with a pre-shared key. The encrypted biometric data and the encrypted access request information are decrypted to obtain the biometric data and access request information. The biometric data and access request information are verified separately, and the user terminal's access request is authenticated based on the verification results. Because this application uses a converged authorization protocol packet for access authentication, which includes a pre-shared key and biometrics, the dual authentication using the pre-shared key and biometrics leverages the uniqueness of biometrics to prevent unauthorized authentication after key theft, thereby improving the security of access authentication protection. Attached Figure Description
[0025] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0026] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0027] Figure 1 This is a flowchart illustrating the first embodiment of the access authentication method of this application; Figure 2 This is a flowchart illustrating the second embodiment of the access authentication method of this application; Figure 3 This is a flowchart illustrating the third embodiment of the access authentication method of this application; Figure 4 This is a schematic diagram of the module structure of the access authentication device according to an embodiment of this application; Figure 5 This is a schematic diagram of the module structure of the access authentication device according to an embodiment of this application; Figure 6 This is a schematic diagram of the device structure of the hardware operating environment involved in the access authentication method in the embodiments of this application.
[0028] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0029] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.
[0030] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.
[0031] Currently, access authentication technologies (such as fwknop) typically implement covert firewall authentication based on Single Packet Authorization (SPA). The core mechanism involves the client sending an encrypted SPA packet containing a pre-shared key; the server verifies the packet and then opens the port. This is widely used in scenarios such as remote management and intranet access. In other words, access authentication technologies use a pre-shared key as the sole authentication credential, reducing the attack surface by eliminating port listening and providing basic covertness. However, they struggle to meet high-security requirements, with the following key drawbacks: 1. Insufficient security of single key authentication: Related technologies rely solely on pre-shared keys for authentication. Once the key is stolen, attackers can directly forge SPA packets to bypass firewall authentication, leading to security incidents such as unauthorized access to internal network resources and data leaks. This fails to guarantee the uniqueness and reliability of authentication from the root.
[0032] 2. Difficulty in detecting abnormal key usage and slow manual intervention: The relevant technologies lack a real-time monitoring mechanism for key usage behavior. When keys are stolen or used abnormally (such as access from untrusted IP addresses, unfamiliar devices, or high-frequency access outside of working hours), the abnormalities cannot be actively identified. Relying on manual inspections to discover security risks results in a delay of several hours or even days in intervention. During this period, attackers can use abnormal keys to continue to illegally access the system, expanding the scope of the security incident.
[0033] 3. Lack of intelligent management of the entire key lifecycle: In related technologies, the revocation of keys and the cleanup of rules rely entirely on manual operation. When a key leak is discovered, the administrator needs to manually execute the revocation process and clean up the firewall rules, which is cumbersome and prone to errors. If the administrator does not take timely action, the abnormal key will remain valid, creating a long-term security risk.
[0034] Therefore, to overcome the above-mentioned deficiencies, this application provides a solution comprising: receiving a converged authorization protocol packet sent by a user terminal, wherein the extended field of the converged authorization protocol packet embeds encrypted biometric data, and the converged authorization protocol packet also includes encrypted access request information encrypted with a pre-shared key; decrypting the encrypted biometric data and the encrypted access request information respectively to obtain the biometric data and the access request information; verifying the biometric data and the access request information respectively; and authenticating the user terminal's access request based on the verification results; since this application performs access authentication through a converged authorization protocol packet, which includes a pre-shared key and biometrics, the dual authentication of the pre-shared key and biometrics, utilizing the uniqueness of biometrics, avoids illegal authentication after key theft, thereby improving the security of access authentication protection.
[0035] It should be noted that the executing entity in this embodiment can be an access authentication device with data processing, network communication and program running functions, such as a computer, server, or other electronic devices that can achieve the same or similar functions. This embodiment does not impose any restrictions on this.
[0036] Based on this, embodiments of this application provide an access authentication method, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the access authentication method of this application.
[0037] In the first embodiment, the access authentication method is applied to a user terminal, and the access authentication method includes: Step S10: In response to an access request to the target network, collect the user's biometric data and encrypt the biometric data to obtain encrypted biometric data.
[0038] It should be understood that a user terminal can refer to a client terminal, which is the terminal device that initiates a request to access the target network. It belongs to the client-side carrier of the FwKnop system and can be an office terminal with biometric data collection capabilities (such as a laptop or mobile terminal with a fingerprint sensor). The target network can refer to the internal network resources that the user needs to access, protected by a firewall and the FwKnop protection system, such as an enterprise internal network server cluster or internal business system. This network has hidden ports by default and does not expose services externally; access is only granted after FwKnop SPA authentication. An access request can refer to an access application initiated by the user through the user terminal for a specified resource within the target network, including information such as the target address, port, and access duration. Biometric data can refer to human biometric information that can identify a user and possesses uniqueness and non-replicability, such as user fingerprint image data or user iris image data. Encrypted biometric data can refer to ciphertext data generated by a user terminal after encrypting the collected user biometric data using a preset asymmetric encryption algorithm (such as the RSA-2048 algorithm), which can be decrypted by the private key of the corresponding server on the target network.
[0039] In the specific implementation, the user's access request to the target network protected by fwknop is used as the trigger condition. The user terminal collects the user's real-time biometric features (such as fingerprints) through terminal sensors (such as fingerprint sensors), and then uses an asymmetric encryption algorithm to encrypt the biometric features to generate encrypted biometric data that can be transmitted securely.
[0040] Furthermore, in order to complete the pre-initialization process before initiating access authentication, before step S10, the method further includes: responding to the user's registration configuration request, collecting the user's baseline biometric data, generating a biometric template that conforms to a preset format standard; uploading the user's identity information and biometric template to the server corresponding to the target network through an encrypted secure channel; negotiating encrypted verification parameters with the server to obtain the pre-shared key allocated by the server to the user.
[0041] It is understandable that a registration configuration request can refer to an initialization configuration request initiated by the user's terminal before accessing the target network, and processed and executed within the enterprise's trusted intranet environment. Baseline biometric data can refer to the user's original biometric sample data, collected through terminal sensors during the registration phase and conforming to collection standards; specifically, it can refer to the user's original fingerprint image data. Preset format standards can refer to the data format, feature extraction rules, encryption specifications, and field definition standards pre-agreed between the client and server, which the biometric template follows. For example, it could be a standardized format specification that adapts to the RSA-2048 encryption algorithm and is identifiable and comparable to the server-side user feature database. A biometric template can refer to a standardized feature file generated by the client after standardizing feature value extraction and format regularization of the collected baseline biometric data. It is a comparison benchmark stored in the user feature database on the server side for subsequent real-time biometric verification; for example, a fingerprint template uploaded to the server by an employee. An encrypted secure channel refers to a dedicated, trusted data transmission channel established between the client and server, protected throughout by an encryption protocol. Specifically, it can refer to an encrypted channel within an enterprise's intranet, preventing the theft, tampering, and eavesdropping of transmitted data. It is specifically designed to ensure the security of core sensitive data such as user identity information and biometric templates. User identity information refers to the registration information used to identify a user's legitimate identity, including employee ID, name, department, and terminal device fingerprint. This information serves as the basis for the server to allocate pre-shared keys to users, establish user access baselines, and bind biometric templates.
[0042] In its implementation, the client initiates a registration configuration request on the client side as the trigger entry point. The client first completes the authorized collection of the user's baseline biometric data. Through standardized feature extraction and format processing, a biometric template conforming to the agreed standards of both ends is generated, resolving the baseline consistency issue for subsequent biometric comparisons. Then, through a pre-established encrypted secure channel, the user's legitimate identity information is bound to the generated biometric template and uploaded to the corresponding server on the target network. This ensures the security of sensitive data transmission throughout the process and allows the server to complete user identity registration and comparison baseline storage, establishing a binding relationship between "user identity" and "biometric template." Next, the client and server negotiate the encryption and verification parameters required for subsequent authentication, ensuring complete matching of encryption / decryption and comparison rules between the two ends. The client also obtains a pre-shared key exclusively allocated to the user by the server, simultaneously establishing a binding between "user identity," "biometric template," and "pre-shared key," completing the entire registration configuration loop and preparing for the subsequent formal access authentication process.
[0043] Step S20: Encrypt the access request information corresponding to the access request using the pre-shared key to obtain the encrypted access request information.
[0044] It should be understood that the pre-shared key refers to a symmetric key that is pre-assigned by the administrator to authorized users and synchronously stored on both the user's terminal and the server, used to encrypt access request information. Access request information can refer to the parameter information directly corresponding to the user's access request and required by the server to complete port authorization, including the target server IP address within the target network, the target access port, access duration, and terminal device information. Encrypted access request information can refer to the ciphertext data generated by the user terminal through symmetric encryption of the access request information using the pre-shared key, which can be decrypted by the server using the same pre-stored pre-shared key.
[0045] In the specific implementation, the request information corresponding to this access is symmetrically encrypted using a pre-allocated pre-shared key to generate encrypted access request information that can be recognized by the native system.
[0046] Step S30: Embed the encrypted biometric data into the extended fields corresponding to the authorization protocol packet, and generate a fused authorization protocol packet by combining the encrypted access request information.
[0047] It is understandable that the authorization protocol packet (i.e., SPA packet) can refer to the data packet used to transmit authentication credentials in the fwknop protocol system. It carries access request information encrypted with a pre-shared key. By default, the server does not listen on any port and only completes pre-authentication verification by sniffing this protocol packet, achieving port concealment and attack surface convergence. The extended field can refer to the optional field in the authorization protocol packet (i.e., SPA packet) that is natively reserved and can be filled with custom data. In this embodiment, it refers to the dedicated extended field used to carry encrypted biometric data (such as the field identifier "bio_data"). The fused authorization protocol packet can refer to the composite SPA message generated after the user terminal embeds the encrypted biometric data into the extended field of the authorization protocol packet and completes compliant encapsulation with the encrypted access request information. It carries both "pre-shared key + biometric" dual authentication credentials.
[0048] In the specific implementation, the encrypted biometric data is embedded into the authorization protocol package through the extended fields natively reserved in the SPA package, and is encapsulated in compliance with the encrypted access request information to generate a fusion authorization protocol package that carries dual identity credentials.
[0049] Step S40: Send the converged authorization protocol packet to the server corresponding to the target network, so that the server authenticates the access request according to the converged authorization protocol packet.
[0050] It should be understood that the server can refer to the fwknop server corresponding to the target network, deployed on the firewall side at the entrance of the target network.
[0051] In the specific implementation, the converged authorization protocol packet is sent to the fwknop server corresponding to the target network to complete the full-process authentication pre-operation on the terminal side, and wait for the authentication result and access authorization from the server side.
[0052] This embodiment uses a pre-shared key plus biometric authentication credentials to collaboratively encapsulate a converged authorization protocol package, so that the server can subsequently perform access authentication through the converged authorization protocol package. The converged authorization protocol package includes a pre-shared key and biometrics. By using the dual authentication of the pre-shared key and biometrics and leveraging the uniqueness of biometrics, illegal authentication after key theft is avoided, thereby improving the security of access authentication protection.
[0053] In addition, refer to Figure 2 , Figure 2 This is a flowchart illustrating the second embodiment of the access authentication method of this application.
[0054] In the second embodiment, the access authentication method is applied to a server, and the access authentication method includes: Step S50: Receive a converged authorization protocol packet sent by the user terminal, wherein the extended field of the converged authorization protocol packet contains encrypted biometric data, and the converged authorization protocol packet also includes encrypted access request information encrypted with a pre-shared key.
[0055] It should be understood that a converged authorization protocol packet can refer to a composite SPA message generated after the user terminal embeds encrypted biometric data into the extended fields of the authorization protocol packet and completes compliant encapsulation with encrypted access request information. This composite SPA message carries both a pre-shared key and biometric authentication credentials. The extended fields can refer to optional fields natively reserved in the authorization protocol packet (i.e., the SPA packet) that can be customized with data. In this embodiment, it refers to a dedicated extended field used to carry encrypted biometric data (e.g., a field identified as "bio_data"). The encrypted biometric data can refer to ciphertext data generated by the user terminal after encrypting the collected user biometric data using a preset asymmetric encryption algorithm (such as RSA-2048), which can be decrypted using the private key of the corresponding server on the target network. The pre-shared key can refer to a symmetric key pre-allocated by the administrator to legitimate users and synchronously stored on the user terminal and server side, used to encrypt access request information. Encrypted access request information can refer to ciphertext data generated by the user terminal through symmetric encryption of the access request information using a pre-shared key, which can be decrypted by the server using the same pre-stored pre-shared key.
[0056] In the specific implementation, the server receives the integrated authorization protocol packet sent by the user terminal through the portless sniffing mechanism on the firewall side. This packet is fully compatible with the native SPA packet format and carries encrypted dual authentication credentials. It does not require the server to open a fixed listening port, thus retaining the attack surface convergence advantage of the native fwknop.
[0057] Step S60: Decrypt the encrypted biometric data and the encrypted access request information respectively to obtain the biometric data and access request information.
[0058] It is understandable that biometric data can refer to user biometric data collected in real time by the user terminal after being decrypted on the server side, such as real-time fingerprint image data. Access request information can refer to user access request parameter data obtained after being decrypted on the server side, including the target intranet server IP, target port, access duration, etc.
[0059] In the specific implementation, the server performs a split-path decryption operation. For the encrypted biometric data in the extended field, it decrypts it using the asymmetric encryption private key held by the server to restore the user's real-time biometric plaintext data. For the encrypted access request information, it decrypts it using the user's exclusive pre-shared key stored on the server to restore the core parameters of the access request. At the same time, the legality of the pre-shared key is initially screened during the decryption process. If the key is invalid, the process is terminated directly.
[0060] Step S70: Verify the biometric data and the access request information respectively, and authenticate the access request of the user terminal based on the verification results.
[0061] In the specific implementation, the server performs independent verification on the two types of decrypted plaintext data. For the pre-shared key corresponding to the access request information, it verifies whether it is consistent with the user-specific key pre-stored on the server and whether it is in a valid and unrevoked state. For biometric data, it verifies whether the matching degree between it and the biometric template pre-stored in the user's user feature database on the server reaches a preset threshold. Finally, the server makes a final authentication decision on the user terminal's access request based on the comprehensive results of the two layers of verification. Only when both layers of verification pass is the authentication deemed successful, and temporary access to the corresponding resources of the target network is granted to the user terminal. If any layer of verification fails, access is directly denied, thus completing the entire authentication process.
[0062] This embodiment uses a converged authorization protocol packet for access authentication. The converged authorization protocol packet includes a pre-shared key and biometrics. By using the dual authentication of the pre-shared key and biometrics, and leveraging the uniqueness of biometrics, unauthorized authentication after key theft is avoided, thereby improving the security of access authentication protection.
[0063] Furthermore, in order to be compatible with the native access authentication protocol while taking into account both authentication security and execution efficiency, step S70 includes: parsing the access request information to obtain key verification data, and matching and verifying the key verification data with the pre-shared key of the corresponding user pre-stored on the server to obtain a first-level verification result; if the first-level verification result is successful, then matching and comparing the biometric data with the biometric template of the corresponding user pre-stored on the server to obtain a second-level verification result; if the second-level verification result is successful, then the access request authentication of the user terminal is determined to be successful; if the first-level verification result is unsuccessful, or the second-level verification result is unsuccessful, then the access request authentication of the user terminal is determined to be unsuccessful.
[0064] It should be understood that key verification data can refer to verification data extracted from the decrypted access request information, used to verify the legitimacy of the pre-shared key. This includes key identifiers, integrity check values generated by the pre-shared key, encrypted check strings, etc., which can be directly matched and verified against the pre-shared key pre-stored on the server. The pre-shared key pre-stored on the server, corresponding to the user, can refer to a valid symmetric key that is exclusively assigned to a legitimate user by the server during the user registration configuration phase, bound to the user's identity information, and pre-stored in the server's local key library. It corresponds to the user's identity and can be automatically revoked in abnormal scenarios. The biometric template pre-stored on the server, corresponding to the user, can refer to a standardized baseline biometric file that is uploaded to the server through an encrypted secure channel during the user registration configuration phase, bound to the user's unique identity information, and pre-stored in the server's local user feature library.
[0065] In its implementation, the first layer of key validity verification is performed. The server standardizes and parses the decrypted access request information, extracting key verification data for key validity verification according to the format rules negotiated during registration. Then, it retrieves the pre-shared key from the server's local trusted key store, uniquely corresponding to the user identified by the key verification data, and performs a two-way matching verification. This verification not only checks the consistency between the key verification data and the pre-shared key but also simultaneously verifies the full-dimensional validity of the pre-shared key, including whether it is within its normal lifecycle, whether it has been marked as abnormally revoked, and whether it matches the user's identity binding relationship. Finally, the first-layer verification result is output. This step has a pre-termination rule: if the first-layer verification result is a failure, the entire authentication process is terminated directly, and no further operations are performed. Only when the first-layer verification result is a success is the subsequent second-layer biometric comparison operation triggered, thus avoiding unnecessary computational overhead in the process.
[0066] Next, a second-layer identity uniqueness comparison is performed. This step is triggered only if the first-layer verification passes. Based on the unique user identity locked by the first-layer verification, the server retrieves the standardized biometric template pre-stored for that user in the local trusted user feature database. The real-time biometric data obtained by decryption is compared with the template to calculate the feature point matching degree. The calculated matching degree value is then compared with the comparison threshold (e.g., 95%) agreed upon during the registration phase. Finally, the second-layer verification result is output: if the matching degree is ≥95%, the comparison is considered passed; if the matching degree is <95%, the comparison is considered failed.
[0067] Finally, a positive or negative authentication decision is executed. Only when both the first-layer verification result and the second-layer verification result are met simultaneously will the server ultimately determine that the user terminal's access request has been authenticated, triggering the subsequent authorization process: Through the firewall rule management unit, a temporary access rule corresponding to the target port is added to the user terminal's source IP. The rule's validity period follows the 30-minute configuration negotiated during the registration phase, completing this positive authentication authorization. If either the first-layer verification result is "failed" or the second-layer verification result is "failed comparison," regardless of whether the other step succeeds, the server directly determines that the user terminal's access request has failed authentication, immediately rejects the access request, and does not grant the user terminal any port permissions for the target network. Simultaneously, depending on the type of verification failure, corresponding exception handling procedures can be triggered: for example, a first-layer verification failure triggers an illegal scanning alarm, while a second-layer verification failure triggers a key leakage warning and automatic key revocation.
[0068] Furthermore, in order to complete the pre-initialization process before initiating access authentication, before receiving the converged authorization protocol packet sent by the user terminal, the method further includes: receiving the user's identity information and biometric template uploaded by the user terminal through an encrypted secure channel; negotiating encryption verification parameters with the user terminal and allocating a pre-shared key to the user according to the negotiation result; and storing the identity information, the biometric template, and the pre-shared key on the server side.
[0069] Understandably, a biometric template refers to a standardized feature file generated by the client after extracting standardized feature values and formatting the collected baseline biometric data. This file conforms to a preset format standard and is stored in the user's feature database on the server side as a comparison benchmark for subsequent real-time biometric verification. For example, a fingerprint template uploaded by an employee to the server. An encrypted secure channel refers to a dedicated, trusted data transmission channel established between the client and server, protected by an encryption protocol throughout the process. Specifically, it can refer to an encrypted channel within an enterprise's intranet, preventing the theft, tampering, or eavesdropping of transmitted data, and ensuring the security of core sensitive data such as user identity information and biometric templates. User identity information refers to the registration information used to identify the user's legitimate identity, including employee ID, name, department, and terminal device fingerprint. This information serves as the basis for the server to allocate pre-shared keys to users, establish user access baselines, and bind biometric templates.
[0070] In its implementation, the server takes the registration configuration request initiated by the user terminal in a trusted intranet environment as the trigger entry point. First, it receives the user's legitimate identity information and standardized biometric template uploaded by the user terminal through a pre-established encrypted secure channel, completing the trusted registration of the user's identity and the collection of biometric comparison benchmarks, ensuring the security of sensitive data transmission throughout the process. Next, the server and the user terminal conduct two-way encryption verification parameter negotiation to complete the two-way confirmation of core parameters such as encryption and decryption algorithms, data formats, comparison thresholds, and authorization rules required for subsequent authentication, ensuring that the rules at both ends are completely matched. At the same time, based on the user's legitimate identity and permission level, a pre-shared key bound to the identity is exclusively assigned to the user, completing the core credential configuration of the fwknop native authentication system. Finally, the server establishes a mapping and binding relationship between the user's identity information, biometric template, and pre-shared key, storing them in a trusted secure storage environment on the server, forming a complete user authentication file corresponding to "user identity - biometric comparison benchmark - authentication key", completing the entire pre-registration configuration closed loop.
[0071] Reference Figure 3 , Figure 3 This is a flowchart illustrating the third embodiment of the access authentication method of this application, based on the above. Figure 2 The second embodiment shown presents a third embodiment of the access authentication method of this application.
[0072] In the third embodiment, after step S70, the method further includes: Step S80: Collect the multidimensional behavioral features corresponding to this visit.
[0073] It should be understood that multidimensional behavioral characteristics can refer to a multidimensional data set that is associated with the entire SPA packet access request and can quantify the attributes of user access behavior, including behavioral characteristics such as source IP, device fingerprint, access time, access frequency, access duration, and target resource address.
[0074] In the specific implementation, the original behavioral data related to this access is captured from the received fusion SPA packet, network transport layer data, and terminal interaction metadata in multiple dimensions. The capture dimensions follow the preset rules and cover the following dimensions: (1) Network layer characteristics: the source IP address, IP location, and whether it is in the user's trusted IP list; (2) Terminal layer characteristics: the device fingerprint of the user terminal, including terminal model, operating system version, hardware unique identifier hash, and terminal security environment status; (3) Time dimension characteristics: the specific trigger time of this access, whether it is within the user's normal office hours, and the requested access duration; (4) Frequency dimension characteristics: the cumulative number of accesses by the user and the corresponding key within the day, and the time interval between adjacent accesses; (5) Access target characteristics: the target intranet server IP, target port, and requested permission scope of this access. Subsequently, the captured raw behavioral data is standardized, cleaned, formatted, and deduplicated to remove invalid and redundant data. In accordance with the input format requirements of the preset machine learning fusion model, a standardized multidimensional behavioral feature dataset is generated. At the same time, this standardized dataset is synchronously archived to the user's historical access database for subsequent iterative optimization of the machine learning fusion model and dynamic updates of the normal access behavior baseline, thus preserving a complete chain of evidence for tracing security incidents.
[0075] Step S90: Identify abnormal access behavior based on the multidimensional behavioral features and the preset machine learning fusion model.
[0076] It is understandable that a pre-set machine learning fusion model can refer to a machine learning model that has been pre-trained in supervised mode using historical normal user access data. Abnormal access behavior can refer to access behavior that deviates from the baseline of normal user access behavior, does not conform to the user's historical legitimate access patterns, and poses a high risk of key theft / identity impersonation. Examples include access via untrusted IP addresses, access via unfamiliar devices, access outside of working hours, and high-frequency abnormal access.
[0077] In the specific implementation, a pre-loaded machine learning fusion model that has completed supervised training is preloaded, and multi-dimensional behavioral features are input into the pre-loaded machine learning fusion model to obtain the abnormal access behavior output by the pre-loaded machine learning fusion model.
[0078] This embodiment synchronously collects multi-dimensional network behavior features associated with fusion authorization protocol packets, and constructs an anomaly detection system based on a machine learning fusion model, thereby realizing real-time identification of abnormal key usage and improving the efficiency of abnormal access behavior identification.
[0079] Furthermore, in order to adapt to the personalized access habits of different users and reduce the false interception rate of legitimate access, step S90 includes: performing standardized preprocessing on the multi-dimensional behavioral features to obtain feature data to be detected; inputting the feature data to be detected into a preset machine learning fusion model, comparing the feature data to be detected with the baseline of the normal access behavior of the corresponding user through the preset machine learning fusion model to obtain the behavioral abnormality degree of this access; if the behavioral abnormality degree is greater than or equal to the abnormal judgment threshold, then the access is determined to be abnormal access behavior; if the behavioral abnormality degree is less than the abnormal judgment threshold, then the access is determined to be normal access behavior.
[0080] It should be understood that standardized preprocessing refers to the process of standardizing multi-dimensional behavioral features, which may include data cleaning, feature encoding, normalization, and format regularization to eliminate noise interference and dimensional differences in the original data. The feature data to be detected refers to a standardized feature dataset that, after standardized preprocessing, conforms to the input format requirements of a preset machine learning fusion model. The normal access behavior baseline refers to a set of standardized benchmark thresholds that characterizes the regularity of a user's normal access behavior, bound to the user's identity identifier, based on the user's historical legitimate access data, and generated through learning by a preset machine learning fusion model. These thresholds include trusted IP ranges, normal office hours (e.g., 8:00-18:00), daily average access frequency thresholds (e.g., ≤3 times), and a database of commonly used device fingerprints. The abnormality degree refers to a standardized value output by the preset machine learning fusion model that quantifies the degree to which the current access behavior deviates from the user's normal access behavior baseline. A higher value indicates a greater degree of deviation and a higher risk of anomaly. The anomaly judgment threshold refers to a pre-set critical abnormality degree value used to distinguish between normal and abnormal access behavior. It is a standardized judgment scale for the model's output results and can be flexibly adjusted according to the enterprise's security level requirements and the importance of the accessed resources.
[0081] In the specific implementation, data cleaning is performed to remove invalid, redundant, erroneous, and null data from the original multidimensional behavioral features, such as incomplete device fingerprints, invalid IP addresses, and repeatedly collected frequency data, thus eliminating the interference of dirty data on the model's calculation results. Feature encoding is performed to standardize the encoding of non-numerical classification features, such as converting features like "whether the source IP is in the trust list," "whether the access time is during office hours," and "whether the device fingerprint is in the common database" into 0 / 1 numerical features that the model can recognize. One-hot encoding is performed on multi-classification features such as IP location and device type to ensure that the data is properly encoded. All features can be quantified and calculated by the model; normalization is performed to map numerical features of different dimensions and value ranges to a standardized range of 0-1, such as access frequency, time offset, and access duration, to eliminate the impact of differences in the dimensions of features of different dimensions on the model weight allocation and prevent high-level features from overshadowing the role of low-level, high-risk features; finally, feature regularization is performed to sort and encapsulate the processed features in strict accordance with the input dimensions, feature order, and format requirements of the preset machine learning fusion model, generating uniform, dimensionally matched, and non-redundant and non-missing feature data to be detected.
[0082] First, the runtime environment is pre-loaded. On one hand, a pre-trained supervised machine learning fusion model is retrieved and loaded. This model is pre-trained based on historical normal access data of all enterprise users and fine-tuned for each user's personalized access habits. On the other hand, the normal access behavior baseline bound to the user in this access is retrieved from the trusted user behavior database on the server. This baseline includes the user's trusted IP list, frequently used device fingerprint database, normal office hours, and daily average access frequency threshold, among other benchmark rules. Subsequently, the model compares each dimension of the feature data to be detected with the corresponding benchmark rules in the normal access behavior baseline one by one, calculating the feature deviation of each dimension. For example, if the source IP is not on the trusted list, the deviation of that dimension is 100%, and if the access time is 2 AM, the deviation of the time dimension is 90%. Finally, based on the pre-trained weight coefficients, the model performs a weighted fusion calculation of the feature deviation of each dimension. Among them, the weight coefficients of high-risk dimensions such as untrusted IP, non-working time, and unfamiliar devices are higher and have a greater impact on the final result. The final output is a standardized quantitative value, namely the abnormality of this visit. The higher the value, the greater the degree of deviation of this visit from the user's normal access pattern and the greater the probability of abnormal risk.
[0083] The calculated abnormal behavior score is compared with a pre-set anomaly threshold, for example, a threshold of 60 points set by the enterprise based on security requirements. When the abnormal behavior score is ≥60 points, the model directly outputs that the access is an abnormal access behavior. When the abnormal behavior score is <the anomaly threshold, for example, a calculated abnormal behavior score of 25 points, which is lower than the preset threshold of 60 points, the model directly outputs that the access is a normal access behavior.
[0084] Furthermore, in order to provide an algorithmic model and judgment benchmark for subsequent abnormal access behavior identification, before receiving the fusion authorization protocol packet sent by the user terminal, the method further includes: collecting legal access behavior data of the target user within a preset historical period, and extracting multi-dimensional historical behavior features from the legal access behavior data; performing standardized preprocessing on the multi-dimensional historical behavior features to obtain a model training sample set; training an initial machine learning model based on the model training sample set to obtain a preset machine learning fusion model; and constructing a normal access behavior baseline and an abnormal judgment threshold corresponding to the target user based on the statistical distribution law of the multi-dimensional historical behavior features.
[0085] Understandably, the target user refers to a legitimate employee of the company who has completed registration and configuration, filed their identity information and biometric template, obtained a dedicated pre-shared key, and needs to access enterprise intranet resources through the FWKNOP system. The preset historical period refers to a pre-defined historical time window used to collect data on users' legitimate access behavior, for example, 6 months. Legitimate access behavior data refers to the full log data of remote access initiated by the target user within the preset historical period through the FWKNOP system or compliant channels within the enterprise intranet, which has passed identity verification and poses no security risks. Multidimensional historical behavior features refer to a set of multidimensional features extracted from the legitimate access behavior data that can quantify the patterns of the target user's historical access behavior, such as source IP, device fingerprint, access time, access frequency, access duration, target resource address, and access port. The model training sample set refers to a standardized sample set that meets the requirements for initial machine learning model training after standardized preprocessing, divided into a training set and a validation set. The initial machine learning model can refer to a basic machine learning model with a pre-defined architecture that has not been trained on data specific to the target user. For example, a supervised anomaly detection fusion model adapted to multi-dimensional behavioral feature fusion analysis is the basic carrier for generating a pre-defined machine learning fusion model.
[0086] In the specific implementation, firstly, the server collects full legal access behavior data of the target user within a preset historical period (e.g., the past 6 months) from the enterprise intranet trusted access log system and the fwknop historical authentication log system. The collection scope is limited to remote access logs that have passed identity verification, have no security alarms, and have been confirmed as compliant by the administrator. All unauthorized abnormal access data is removed to ensure the purity of the training data source. Subsequently, the server extracts full multi-dimensional historical behavior features from the legal access behavior data according to the preset feature dimension rules, covering the following dimensions: (1) Network layer features: source IP address of historical access, I P location, trusted IP range; (2) terminal layer features: fingerprint of the terminal device used in historical access, terminal model, operating system version, hardware identifier hash; (3) time dimension features: distribution of trigger time of historical access, access time period pattern, distribution of single access duration; (4) frequency dimension features: historical daily average number of accesses, weekly average access frequency, distribution of time interval between adjacent accesses; at the same time, supplementary access target features are extracted, including the target server IP, target port, and resource permission range of historical access, forming a complete multi-dimensional historical behavior feature dataset, providing full basic data for subsequent preprocessing, model training, and baseline construction.
[0087] First, data cleaning is performed to remove missing, duplicate, and outlier values (such as test data with a single access duration exceeding 72 hours) from the feature set, correct erroneous data, and eliminate interference from dirty data on model training. Second, feature encoding is performed to standardize non-numerical categorical features, such as converting features like "whether the source IP is in the trusted segment" and "whether the device is a commonly used terminal" into 0 / 1 numerical features, and performing one-hot encoding for multi-category features such as IP location and device model to ensure that all features can be quantified and calculated by the model. Then, normalization is performed to map numerical features with different dimensions and value ranges (such as average daily access count, access duration, and time offset) to a standardized range of 0-1 using a min-max normalization algorithm, eliminating the difference in dimensions between features of different dimensions and preventing high-level features from overshadowing the weights of low-level, high-risk features. Finally, sample balancing and partitioning are performed to ensure balanced sample distribution through oversampling / undersampling, and then the standardized samples are divided into training and validation sets in an 8:2 ratio to generate the model training sample set, providing compliant and high-quality input materials for model training.
[0088] First, the server loads a pre-set initial machine learning model. This model is a supervised anomaly detection fusion model adapted for FWKNOP single-package authorization scenarios, combining the feature importance learning capability of random forests with the anomaly probability calculation capability of logistic regression, specifically optimized for the fusion analysis of multi-dimensional behavioral features. Then, the training set from the model training sample set is input into the initial machine learning model to perform supervised training: the model automatically learns the mapping relationship between each dimension of features and access behavior compliance, and calculates the weight coefficient of each dimension of features (where high-risk dimensions such as untrusted IPs, non-working hours, and unfamiliar devices are automatically classified). The model parameters are continuously iterated and optimized to reduce training error (with higher weights). After training, the model is validated using a validation set in the sample set. The model's accuracy, recall, and precision are calculated. If the validation metrics do not meet the preset requirements (e.g., accuracy ≥ 99%, recall ≥ 99.5%), the model hyperparameters are adjusted and the model is retrained until the model meets the requirements. Finally, the trained, validated, and optimized model is solidified into a preset machine learning fusion model for the target user and deployed to the real-time inference module of the AI anomaly detection unit to provide core algorithm support for subsequent real-time anomaly identification.
[0089] First, the server performs statistical analysis on the multi-dimensional historical behavioral characteristics, calculating the statistical distribution patterns of each dimension, including mean, median, variance, 95% confidence interval, and frequency distribution interval. For example, the 95% distribution interval for historical user access time is calculated to be 8:00-18:00, the upper limit of the 95% confidence interval for average daily access frequency is 3 times, and the 95% distribution range of source IPs is the enterprise intranet IP range and employee home IP range. Then, based on the statistical distribution patterns of each dimension, a baseline of normal access behavior specific to the target user is constructed, setting clear compliance boundary thresholds for each dimension, including trust I... The system comprises a P-list, a frequently used device fingerprint database, normal office hours, daily access frequency limits, maximum duration of a single access, and the scope of compliant access targets, forming a complete and quantifiable set of baseline rules. Finally, based on model validation results and statistical distribution patterns, anomaly detection thresholds are set. If the abnormality level of the behavior is greater than or equal to the threshold, it is considered abnormal access behavior; otherwise, it is considered normal access behavior. The normal access behavior baseline, anomaly detection threshold, and target user identity information, pre-shared keys, and biometric templates are bound together and stored in a trusted database on the server side to provide a judgment benchmark for subsequent real-time anomaly identification.
[0090] Furthermore, in order to ensure that abnormal risks are quickly blocked and reduce operation and maintenance costs, after step S90, the method further includes: if the access request authentication fails or abnormal access behavior is identified, the access connection is rejected; a preset automated handling process is triggered, and the access is handled based on the preset automated handling process.
[0091] It should be understood that "denying this access connection" can refer to the server-side's underlying network access permission blocking operation for requests that fail authentication or involve abnormal access. This means not granting the user terminal any port permissions on the target network, thus blocking its network connection to protected resources within the internal network. "Preset automated handling process" can refer to a set of pre-configured, fully automated handling rules on the server side, bound to the risk level.
[0092] In the specific implementation, for scenarios where access request authentication fails: regardless of whether key verification or biometric comparison fails, the server immediately terminates the entire authentication process, does not open any port permissions of the target network to the source IP address of the user terminal, silently discards the received fusion SPA packet, and does not return any detailed message containing the reason for authentication failure (to prevent attackers from using the returned information to perform system fingerprinting and key brute-force attacks); at the same time, in the local trusted log system, it fully records all data such as the source IP, device fingerprint, access time, authentication failure type, and target resource address of this access, retaining tamper-proof audit and traceability evidence.
[0093] For scenarios where abnormal access behavior is detected: In this scenario, the user has passed two-factor authentication, and the server has generated temporary firewall access rules to be issued. At this time, the rule issuance process should be terminated immediately, all port permissions to be opened should be withdrawn, and the access connection should be rejected. At the same time, all network sessions between the user's terminal source IP and the target network should be blocked immediately, and no data packets should be allowed to enter the internal network environment. Simultaneously, in the local log system, complete data such as the full-dimensional behavioral characteristics of this abnormal access, the abnormality degree value, the abnormality type, and the matching deviation from the baseline rule should be recorded to form a security event archive record.
[0094] Simultaneously, it triggers a pre-defined automated handling process of "anomaly detection - key revocation - rule cleanup - alarm push", replacing traditional manual operation, ensuring that abnormal risks are quickly blocked, and reducing operation and maintenance costs.
[0095] Furthermore, in order to flexibly combine and execute various risk handling procedures according to the risk level, the triggering of the preset automated handling procedure and the handling of this access based on the preset automated handling procedure includes at least one of the following: revoking the pre-shared key associated with this access and marking the pre-shared key as abnormally disabled; clearing the temporary access rules associated with the pre-shared key in the firewall and closing the corresponding open ports; generating abnormal alarm information based on the abnormal feature data corresponding to this access and pushing the abnormal alarm information to the management terminal.
[0096] It is understandable that revocation can refer to the operation of permanently invalidating the target pre-shared key. After the operation is executed, the binding relationship between the key and the user's identity will be released, and all authorized configurations of the key will be cleared. An abnormal disabled state can refer to the server marking a pre-shared key with a permanently disabled attribute in the keystore after it has been revoked. After marking, any access request initiated using that key, regardless of whether it contains legitimate biometric data, will be directly judged as authentication failure. A firewall can refer to a network security protection device deployed at the target network entry point, responsible for port control, access rule enforcement, and network session blocking. Temporary access rules can refer to firewall access rules dynamically added by the server for users after successful authentication, which are valid for a limited time and are bound to the user's exclusive pre-shared key. An open port can refer to the service port of the target internal network server temporarily opened by the firewall for authenticated legitimate users, only open to the authenticated source IP address. Anomaly feature data can refer to the behavioral feature dataset that triggered the anomaly judgment during this access, including the anomaly trigger time, source IP address, device fingerprint, anomaly type, behavioral anomaly degree value, target accessed resources, access time / frequency, etc. Anomaly alert information can refer to standardized alert content generated based on anomaly characteristic data, containing full details of the anomaly and the results of executed actions. The management end can refer to the operation and maintenance management terminals and channels used by enterprise IT administrators, including email systems, security operation and maintenance platforms, etc.
[0097] In the specific implementation, based on the parsing results and authentication verification process of this integrated SPA package, the pre-shared key associated with this access, as well as the user identity information bound to this key, are locked to prevent accidental operation from affecting the key use of other legitimate users. Subsequently, the pre-shared key is immediately revoked, removing the binding relationship between the key and the user identity from the server-side trusted key store, clearing all authorization configurations and access permissions of the key, and making the key permanently invalid. At the same time, the pre-shared key is marked as abnormally disabled in the trusted key store, and this status is synchronized to other systems on the server to form a system-wide status synchronization. After the status marking is completed, any subsequent SPA package access request initiated using this key, regardless of whether it contains legitimate biometric data, will be directly judged as authentication failure, completely blocking the subsequent illegal use of the key from the root.
[0098] Based on the revoked pre-shared key identifier, the firewall rule base is searched for temporary access rules bound to that key, including temporary authorization rules to be issued for this access, historical temporary access rules that have already taken effect, and associated IP whitelist rules. Then, all retrieved associated temporary access rules are immediately cleaned up in batches, and the intranet access authorization corresponding to the key is revoked. At the same time, the target service port temporarily opened for the key in the firewall is closed, all established TCP / UDP network sessions corresponding to the key are terminated, and the network entry point for attackers to access the target intranet through the key is cut off. After the rule cleanup is completed, the firewall is restored to the default state of all ports being closed, and the network attack surface is continuously reduced.
[0099] Extract all anomaly characteristic data corresponding to this access, including anomaly trigger time, source IP address, IP location, device fingerprint, anomaly type (e.g., access from an untrusted IP during non-working hours), anomaly score, target access resource address and port, and results of executed key revocation and rule cleanup. Then, generate standardized anomaly alarm information according to a pre-defined tiered alarm template, classifying it into high, medium, and low alarm levels based on anomaly risk. Anomaly access behavior that bypasses two-factor authentication is marked as a high-risk alarm by default. Finally, push the anomaly alarm information to the IT administrator's management console in real time through pre-configured enterprise channels, and simultaneously archive the alarm information to the server's local security event database, retaining tamper-proof audit records to support subsequent tracing and handling operations such as user identity verification, key leakage investigation, and new key redistribution.
[0100] Furthermore, in order to manage permissions throughout their entire lifecycle and continuously optimize protection capabilities, after step S90, the method further includes: if the access request is authenticated and no abnormal access behavior is detected, generating a temporary access control rule based on the access request information and configuring a corresponding authorized access validity period for the temporary access control rule; issuing the temporary access control rule to the firewall for execution, opening the target access port corresponding to the access request information, and granting the user terminal access to the corresponding intranet resources; automatically clearing the corresponding temporary access control rule in the firewall and closing the target access port when the authorized access validity period expires; storing the multi-dimensional behavioral features corresponding to this access in the legitimate access behavior dataset to update the normal access behavior baseline of the corresponding user, and incrementally optimizing the preset machine learning fusion model.
[0101] It should be understood that temporary access control rules can refer to time-limited firewall access rules bound to user identity and pre-shared keys. These rules only apply to the source IP address of the current access and only open the specified target port, serving as authorization credentials for legitimate users to access internal network resources. The authorized access validity period refers to the pre-configured duration of the temporary access control rule, calculated from the date the rule is issued to the firewall; the rule automatically expires after the timeout. The target access port can be the port specified in the user's access request information, the port on which the internal network server provides services to the outside world.
[0102] In its implementation, the firewall rule management unit extracts the authorization parameters for this access from the decrypted access request information. These parameters include the user terminal's source IP address, the target intranet server IP, the target access port, and the user's requested access duration. Based on these extracted authorization parameters, a temporary access control rule is generated, bound to the user's identity and a dedicated pre-shared key. This rule follows the zero-trust least privilege principle: it only applies to the user terminal's source IP, allows access only to the specified target intranet server IP, and only opens the requested target access port; all other ports and intranet resources remain blocked. Finally, a corresponding authorized access validity period is configured for this temporary access control rule. The validity period follows a preset rule negotiated between the client and server during registration (e.g., 30 minutes), and the validity period does not exceed the user's requested access duration. The validity period begins the moment the rule is issued to the firewall, ensuring precise access control.
[0103] The generated temporary access control rules are distributed in real time to the firewall at the enterprise intranet entry point via an encrypted management channel. Upon receiving the rules, the firewall takes effect and executes them. Subsequently, based on the temporary access control rules, the firewall temporarily opens the target access port specified in the access request information (such as port 22 for SSH remote management) only for the source IP address of the user terminal, establishing a dedicated temporary network communication channel between the user terminal and the target intranet server, thus granting the user terminal access to the corresponding intranet resources. At the same time, the firewall keeps all other ports closed except for the target access port, continuously narrowing the network attack surface and fully preserving the core protection advantage of fwknop's port concealment. Finally, the server synchronously records the rule's effective time, the authorized access validity period, the associated user identity and pre-shared key information, and retains an immutable full-process audit log.
[0104] The server monitors the authorized access validity period of temporary access control rules in real time and tracks the remaining validity period of the rules synchronously through a timer. When the authorized access validity period expires, an automatic rule cleanup process is triggered without any manual intervention. Subsequently, a rule cleanup command is sent to the firewall through an encrypted management channel, automatically removing the temporary access control rule corresponding to this access from the firewall. Upon receiving the command, the firewall executes it immediately, closing the previously temporarily opened target access port and terminating all established TCP / UDP network sessions between the user terminal and the target internal network server. Regardless of whether the user is currently performing an access operation, all access permissions are immediately revoked. Finally, the firewall is restored to its default state of complete port closure and stealth. The server records the rule cleanup time, execution results, and retains a complete audit log.
[0105] The multi-dimensional behavioral features collected during this visit, including source IP, device fingerprint, access time, access frequency, access duration, and target resource address, are tagged as "legitimate access" and stored in the corresponding user's exclusive legitimate access behavior dataset. This completes the accumulation of user access behavior data, providing material for baseline updates and model optimization. Subsequently, based on the updated legitimate access behavior dataset, the statistical distribution patterns of each dimension of features are recalculated, dynamically updating the user's normal access behavior baseline. For example, newly added home IPs of users are included in the trusted IP list, the normal working hours of users are adjusted, and the daily average access frequency threshold is updated to automatically adapt to normal changes in user access habits. Finally, based on the newly added legitimate access samples, the preset machine learning fusion model is incrementally optimized. Only the feature weight parameters of the model are adjusted in small batches with lightweight iterations without changing the core architecture of the model. Under the premise of not affecting the original anomaly recognition capability of the model, the accuracy of the model in recognizing normal user access behavior is continuously improved, and the false alarm rate of legitimate access is reduced, forming a positive cycle of "legitimate access - data accumulation - baseline update - model optimization".
[0106] For ease of understanding, the following examples are provided, but they are not intended to limit this application. As an example, the core idea of the access authentication method in this application is as follows: This application addresses the core pain points of existing FWKNOP technology, namely "insecure single-key authentication, difficulty in detecting anomalies, delayed handling, and inefficient management," and proposes an integrated technical approach of "multi-factor authentication enhancement + AI intelligent monitoring + fully automated handling." The core logic is as follows: (1) Enhanced authentication layer: Without changing the core transmission process of the fwknop protocol, a new biometric collection and encryption embedding module is added to build a dual authentication system of "pre-shared key + biometrics". By utilizing the uniqueness and non-replicability of biometrics, the security of identity authentication is improved from the root. (2) Monitoring layer intelligence: Synchronously collect multi-dimensional network behavior features (source IP, device fingerprint, access time / frequency, etc.) associated with SPA packets, build an anomaly detection system based on machine learning fusion model, establish a baseline of normal user access behavior, and realize real-time identification of abnormal key use; (3) Closed-loop processing layer: Design an automated processing flow of “anomaly detection - key revocation - rule cleanup - alarm push” to replace traditional manual operation, ensure that anomaly risks are quickly blocked, and reduce operation and maintenance costs.
[0107] The overall system architecture of the access authentication method in this application is as follows: This application's system adopts a client-server distributed architecture, achieving functional decoupling through modular design. Each module collaborates to complete the entire protection chain from authentication to monitoring to handling. The specific architecture is as follows: (1) Client module (terminal side): The core is the "biometric feature acquisition unit" and the "SPA packet encryption generation unit". The biometric feature acquisition unit is responsible for collecting the user's real-time biometric features (fingerprint) through the terminal sensor (fingerprint sensor); the SPA packet encryption generation unit is responsible for encrypting the biometric features using an asymmetric encryption algorithm, embedding the encrypted data into the SPA packet extension field, and encrypting the access request information (target port, access duration, etc.) in conjunction with the pre-shared key, and finally generating a fused SPA packet and sending it to the server.
[0108] (2) Server-side module (core protection side): It contains 7 functional units to form a complete protection closed loop: ① SPA packet parsing unit: receives fused SPA packets, completes data decryption and format parsing, and separates key authentication data and biometric data; ② Multi-factor authentication unit: executes the "key verification + biometric comparison" two-layer authentication logic to ensure the legitimate identity of the access subject; ③ Behavioral feature collection unit: collects multi-dimensional behavioral data of this access in real time (source IP, device fingerprint, access time, access frequency, etc.); ④ AI anomaly detection unit: based on the trained fusion model, compares the real-time behavioral features with the normal access baseline to identify abnormal access behavior; ⑤ Key management unit: responsible for the full life cycle management of keys, the core of which is automatic revocation and marking in abnormal scenarios; ⑥ Firewall rule management unit: dynamically adds or cleans up firewall access rules according to the authentication results and anomaly detection results; ⑦ Alarm push unit: when an anomaly occurs, pushes alarm information containing anomaly details (such as anomaly time, source IP, device information, etc.) to the administrator to support source tracing and handling.
[0109] An example of the access authentication method in this application is as follows (taking "remote management scenario based on enterprise intranet" as an example): The following describes the specific implementation process of this application in the context of a real-world scenario of remote management of an enterprise's intranet server. Scenario requirement: Enterprise employees need to ensure access security and prevent unauthorized access caused by key leakage when remotely accessing the intranet server via external terminals.
[0110] 1. Pre-configuration stage: (1) Client configuration: Employees enter their fingerprint template on their office terminal (laptop, equipped with fingerprint sensor) and upload it to the user feature database on the server through the encrypted channel of the enterprise intranet; at the same time, the IT administrator assigns a dedicated pre-shared key to the employee, and the client and the server negotiate to determine that the encryption algorithm is RSA-2048 and the biometric comparison threshold is set to 95% (that is, fingerprint matching degree ≥ 95% is considered legal).
[0111] (2) Server-side configuration: Collect the normal remote access data of the enterprise in the past 6 months (including the employee's commonly used access IP, office hours 8:00-18:00, daily access frequency ≤3 times, etc.) to train the model and establish the baseline of the employee's normal access behavior; configure firewall rules and policies: the authorization rule is valid for 30 minutes (that is, after a single authentication is passed, normal access is allowed within 30 minutes, and it will automatically expire after the timeout), and automatically clean up all associated rules when an anomaly occurs.
[0112] 2. Client-side SPA packet generation and sending stage: When an employee initiates a remote access request from an external terminal: 1) The client's biometric collection unit collects the employee's real-time fingerprint image through a fingerprint sensor; 2) The SPA packet encryption generation unit encrypts the real-time fingerprint image using an encryption algorithm and embeds the encrypted fingerprint data into the extended field of the SPA packet (the field is identified as "bio_data"); 3) At the same time, the access request information (target intranet server IP: 192.168.1.100, target port: 22, access duration: 20 minutes) is encrypted using a pre-shared key to generate core authentication data; 4) The client sends the SPA packet, which integrates "encrypted fingerprint data + core authentication data", to the server corresponding to the enterprise firewall.
[0113] 3. Server-side multi-factor authentication stage: After receiving the SPA packet, the server-side SPA packet parsing unit decrypts the "bio_data" field with the private key to obtain real-time fingerprint data, and decrypts the core authentication data with the pre-shared key to obtain access request information; 2) The multi-factor authentication unit performs two-layer verification: the first layer verifies whether the key in the core authentication data is consistent with the key pre-stored on the server, and the verification passes; the second layer compares the real-time fingerprint data with the fingerprint template pre-stored by the employee, and if the matching degree is 98% (≥95% threshold), the dual authentication is determined to be successful.
[0114] 4. Feature Acquisition and AI Anomaly Detection Stage: (1) The behavior feature collection unit collects the behavior data of this visit in real time: source IP (employee's home network IP: 220.181.xxx.xxx, which has been entered into the trusted IP list), device fingerprint (laptop model: MateBook14, operating system: Windows11), access time (10:30, within office hours), access frequency (this is the first access of the day). (2) The AI anomaly detection unit inputs the above real-time features into the fusion model and compares them with the preset normal access baseline to determine that the access behavior is normal.
[0115] 5. Verification of abnormal scenarios (key theft): Suppose an employee's pre-shared key is stolen by an attacker, who then attempts to gain access via an untrusted IP address (113.200.xxx.xxx): (1) The attacker forges access information containing a legitimate key and generates an SPA packet to send to the server (without legitimate biometric signature). (2) During multi-factor authentication on the server side, the key verification passes, but the biometric comparison fails due to the lack of valid biometric data, and access is directly denied. (3) If an attacker obtains employee fingerprint simulation data through illegal means and generates a fusion SPA package: after the biometric comparison is passed, the behavior feature collection unit collects that the source IP is an untrusted IP and the access time is 2:00 am (non-office hours), and the AI anomaly detection unit determines it as an abnormal access; (4) The key control unit shall immediately revoke the employee’s pre-shared key, mark it as an “abnormal key” and disable it; (5) The firewall rule management unit cleans up all access rules associated with the key; the alarm push unit pushes alarms to the IT administrator via email and WeChat, including: abnormal time (2:05 am), source IP (113.200.xxx.xxx), abnormal type (untrusted IP + access outside office hours), and the administrator promptly contacts the employee to verify, reassign the key and investigate the cause of the key leakage.
[0116] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the access authentication method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.
[0117] This application also provides an access authentication device, please refer to... Figure 4 The access authentication device is applied to a user terminal, and the access authentication device includes: The acquisition module 10 is used to collect the user's biometric data in response to an access request to the target network, and to encrypt the biometric data to obtain encrypted biometric data. Encryption module 20 is used to encrypt the access request information corresponding to the access request using a pre-shared key to obtain encrypted access request information; The fusion module 30 is used to embed the encrypted biometric data into the extended fields corresponding to the authorization protocol packet, and to generate a fused authorization protocol packet by combining the encrypted access request information. The sending module 40 is used to send the converged authorization protocol packet to the server corresponding to the target network, so that the server can authenticate the access request according to the converged authorization protocol packet.
[0118] The access authentication device provided in this application, employing the access authentication method in the above embodiments, can solve the technical problem that related access authentication technologies typically use a single pre-shared key for access authentication, resulting in easy breach of protection and insufficient security after the key is stolen. Compared with the prior art, the beneficial effects of the access authentication device provided in this application are the same as those of the access authentication method provided in the above embodiments, and other technical features in the access authentication device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.
[0119] In addition, this application also provides an access authentication device, please refer to... Figure 5 The access authentication device is applied to the server, and the access authentication device includes: The receiving module 50 is used to receive a converged authorization protocol packet sent by a user terminal, wherein the extended field of the converged authorization protocol packet contains encrypted biometric data, and the converged authorization protocol packet also includes encrypted access request information encrypted with a pre-shared key; The decryption module 60 is used to decrypt the encrypted biometric data and the encrypted access request information respectively to obtain the biometric data and the access request information. The verification module 70 is used to verify the biometric data and the access request information respectively, and to authenticate the access request of the user terminal based on the verification results.
[0120] The access authentication device provided in this application, employing the access authentication method in the above embodiments, can solve the technical problem that related access authentication technologies typically use a single pre-shared key for access authentication, resulting in easy breach of protection and insufficient security after the key is stolen. Compared with the prior art, the beneficial effects of the access authentication device provided in this application are the same as those of the access authentication method provided in the above embodiments, and other technical features in the access authentication device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.
[0121] This application provides an access authentication device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform the access authentication method in Embodiment 1 above.
[0122] The following is for reference. Figure 6 The diagram illustrates a structural schematic of an access authentication device suitable for implementing embodiments of this application. The access authentication device in these embodiments may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 6 The access authentication device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0123] like Figure 6As shown, the access authentication device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in ROM (Read Only Memory) 1002 or a program loaded from storage device 1003 into RAM (Random Access Memory) 1004. RAM 1004 also stores various programs and data required for the operation of the access authentication device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via bus 1005. Input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to I / O interface 1006: input devices 1007 including, for example, touch screens, touchpads, keyboards, mice, image sensors, microphones, accelerometers, gyroscopes, etc.; output devices 1008 including, for example, LCDs (Liquid Crystal Displays), speakers, vibrators, etc.; storage devices 1003 including, for example, magnetic tapes, hard disks, etc.; and communication devices 1009. Communication device 1009 allows the access authentication device to communicate wirelessly or wiredly with other devices to exchange data. While the figures show access authentication devices with various systems, it should be understood that implementing or having all of the systems shown is not required. More or fewer systems may be implemented alternatively.
[0124] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.
[0125] The access authentication device provided in this application, employing the access authentication method described in the above embodiments, can solve the technical problem that related access authentication technologies typically use a single pre-shared key for access authentication, resulting in easy breaches of protection and insufficient security after the key is stolen. Compared with the prior art, the beneficial effects of the access authentication device provided in this application are the same as those of the access authentication method provided in the above embodiments, and other technical features of this access authentication device are the same as those disclosed in the previous embodiment method, and will not be repeated here.
[0126] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0127] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0128] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the access authentication method in the above embodiments.
[0129] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, RAM (Random Access Memory), ROM (Read Only Memory), EPROM (Erasable Programmable Read Only Memory), or flash memory, optical fiber, CD-ROM (CD-Read Only Memory), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0130] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described access authentication method. This addresses the technical problem that related access authentication technologies typically use a single pre-shared key for access authentication, resulting in vulnerabilities in protection and insufficient security once the key is stolen. Compared to existing technologies, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the access authentication method provided in the above embodiments, and will not be elaborated upon here.
[0131] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the access authentication method as described above.
[0132] The computer program product provided in this application can solve the technical problem that related access authentication technologies typically use a single pre-shared key for access authentication, which leads to the vulnerability of the key to breaches and insufficient security. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the access authentication method provided in the above embodiments, and will not be repeated here.
[0133] The above description is only a part of the embodiments of this application and does not limit the scope of this application. All equivalent structural transformations made under the technical concept of this application and using the content of this application specification and drawings, or direct / indirect applications in other related technical fields, are included within the protection scope of this application.
[0134] It should be noted that the data collection, tag management, rule setting, and push decision-making processes involved in this application are designed to work with other technical features to solve technical problems. They do not involve or support any illegal activities. Any data processing that may violate laws and regulations (such as unauthorized collection of privacy data, generation of discriminatory tags, setting unfair rules, or pushing illegal information) is not within the scope of protection of this application's technical solution. Of course, the user data in this application will be encrypted, anonymized, or de-identified before storage to ensure user data security.
[0135] This application discloses A1, an access authentication method, which is applied to a server and includes: The system receives a converged authorization protocol packet sent by a user terminal, wherein the extended field of the converged authorization protocol packet contains encrypted biometric data, and the converged authorization protocol packet also includes encrypted access request information encrypted with a pre-shared key. The encrypted biometric data and the encrypted access request information are decrypted respectively to obtain the biometric data and access request information. The biometric data and the access request information are verified respectively, and the access request of the user terminal is authenticated based on the verification results.
[0136] A2. The access authentication method as described in A1, wherein verifying the biometric data and the access request information respectively, and authenticating the access request of the user terminal based on the verification results, includes: The access request information is parsed to obtain key verification data, and the key verification data is matched and verified with the pre-shared key of the corresponding user pre-stored on the server to obtain the first-level verification result; If the first layer of verification results in a successful verification, the biometric data is matched and compared with the biometric template of the corresponding user pre-stored on the server to obtain the second layer of verification result. If the second-layer verification result is a successful comparison, then the user terminal's access request authentication is deemed successful. If the first layer of verification results in failure, or the second layer of verification results in failure to match, then the user terminal's access request authentication is deemed unsuccessful.
[0137] A3. The access authentication method as described in A2, before receiving the converged authorization protocol packet sent by the user terminal, further includes: Receive user identity information and biometric templates uploaded by user terminals through an encrypted secure channel; Negotiate encryption verification parameters with the user terminal, and allocate a pre-shared key to the user based on the negotiation result; The identity information, the biometric template, and the pre-shared key are stored on the server.
[0138] A4. The access authentication method as described in any one of A1 to A3, further comprising, after verifying the biometric data and the access request information respectively, and authenticating the access request of the user terminal based on the verification results: Collect multidimensional behavioral features corresponding to this visit; Abnormal access behavior is identified based on the multidimensional behavioral features and the preset machine learning fusion model.
[0139] A5. The access authentication method as described in A4, wherein identifying abnormal access behavior based on the multi-dimensional behavioral features and a preset machine learning fusion model includes: The multidimensional behavioral features are standardized and preprocessed to obtain the feature data to be detected; The feature data to be detected is input into a preset machine learning fusion model. The preset machine learning fusion model compares the feature data to be detected with the baseline of the normal access behavior of the corresponding user to obtain the abnormality of the behavior of this access. If the abnormality of the behavior is greater than or equal to the abnormality judgment threshold, then this access is determined to be an abnormal access behavior; If the abnormality level of the behavior is less than the abnormality judgment threshold, then the current access is determined to be a normal access behavior.
[0140] A6. The access authentication method as described in A5, before receiving the converged authorization protocol packet sent by the user terminal, further includes: Collect legitimate access behavior data of target users within a preset historical period, and extract multidimensional historical behavior features from the legitimate access behavior data; The multidimensional historical behavior features are standardized and preprocessed to obtain the model training sample set; The initial machine learning model is trained based on the model training sample set to obtain a preset machine learning fusion model; Based on the statistical distribution patterns of the multidimensional historical behavior characteristics, a baseline for normal access behavior and anomaly detection thresholds for the target user are constructed.
[0141] A7. The access authentication method as described in A4, after identifying abnormal access behavior based on the multi-dimensional behavioral features and the preset machine learning fusion model, further includes: If the access request fails authentication or abnormal access behavior is detected, the access connection will be rejected. A preset automated processing procedure is triggered, and the access is processed based on the preset automated processing procedure.
[0142] A8. The access authentication method as described in A7, wherein triggering a preset automated processing procedure and processing the access based on the preset automated processing procedure includes at least one of the following: Revocation operation is performed on the pre-shared key associated with this access, and the pre-shared key is marked as abnormally disabled; Clean up any temporary access rules in the firewall associated with the pre-shared key and close the corresponding open ports; An anomaly alarm is generated based on the abnormal feature data corresponding to this access, and the anomaly alarm is pushed to the management terminal.
[0143] A9. The access authentication method as described in A4, after identifying abnormal access behavior based on the multi-dimensional behavioral features and the preset machine learning fusion model, further includes: If the access request is successfully authenticated and no abnormal access behavior is detected, a temporary access control rule is generated based on the access request information, and a corresponding authorized access validity period is configured for the temporary access control rule. The temporary access control rule is sent to the firewall for execution, opening the target access port corresponding to the access request information, and granting the user terminal access to the corresponding intranet resources. When the authorized access period expires, the corresponding temporary access control rule in the firewall is automatically cleared and the target access port is closed. The multidimensional behavioral features corresponding to this visit are stored in the legitimate access behavior dataset to update the normal access behavior baseline of the corresponding user, and the preset machine learning fusion model is incrementally optimized.
[0144] This application also discloses B10, an access authentication method applied to a user terminal, the access authentication method comprising: In response to an access request to a target network, the user's biometric data is collected and encrypted to obtain encrypted biometric data. The access request information corresponding to the access request is encrypted using a pre-shared key to obtain the encrypted access request information; The encrypted biometric data is embedded into the extended fields corresponding to the authorization protocol packet, and combined with the encrypted access request information to generate a fused authorization protocol packet; The converged authorization protocol packet is sent to the server corresponding to the target network, so that the server authenticates the access request based on the converged authorization protocol packet.
[0145] B11. The access authentication method as described in B10, further comprising, before collecting the user's biometric data in response to an access request for a target network and encrypting the biometric data to obtain the encrypted biometric data: In response to a user's registration configuration request, the system collects the user's baseline biometric data and generates a biometric template that conforms to a preset format standard. The user's identity information and biometric template are uploaded to the server corresponding to the target network through an encrypted secure channel; Negotiate encryption verification parameters with the server to obtain the pre-shared key assigned to the user by the server.
[0146] This application also discloses C12, an access authentication device applied to a server, the access authentication device comprising: The receiving module is used to receive a converged authorization protocol packet sent by a user terminal, wherein the extended field of the converged authorization protocol packet contains encrypted biometric data, and the converged authorization protocol packet also includes encrypted access request information encrypted with a pre-shared key; The decryption module is used to decrypt the encrypted biometric data and the encrypted access request information respectively to obtain the biometric data and the access request information. The verification module is used to verify the biometric data and the access request information respectively, and to authenticate the access request of the user terminal based on the verification results.
[0147] C13. In the access authentication device as described in C12, the verification module is further configured to parse the access request information to obtain key verification data, and match and verify the key verification data with the pre-shared key of the corresponding user pre-stored on the server to obtain a first-level verification result; if the first-level verification result is successful, the biometric data is matched and compared with the biometric template of the corresponding user pre-stored on the server to obtain a second-level verification result; if the second-level verification result is successful, the access request authentication of the user terminal is determined to be successful; if the first-level verification result is unsuccessful, or the second-level verification result is unsuccessful, the access request authentication of the user terminal is determined to be unsuccessful.
[0148] C14. The access authentication device as described in C13, further comprising: The storage module is used to receive the user's identity information and biometric template uploaded by the user terminal through an encrypted secure channel; negotiate encryption verification parameters with the user terminal and allocate a pre-shared key to the user according to the negotiation result; and store the identity information, the biometric template and the pre-shared key on the server side.
[0149] C15. An access authentication device as described in any one of C12 to C14, wherein the access authentication device further comprises: The identification module is used to collect multi-dimensional behavioral features corresponding to this visit; and to identify abnormal access behavior based on the multi-dimensional behavioral features and a preset machine learning fusion model.
[0150] C16. The access authentication device as described in C15, wherein the identification module is configured to perform standardized preprocessing on the multidimensional behavioral features to obtain feature data to be detected; input the feature data to be detected into a preset machine learning fusion model, and compare the feature data to be detected with the baseline of normal access behavior of the corresponding user through the preset machine learning fusion model to obtain the behavioral abnormality degree of the current access; if the behavioral abnormality degree is greater than or equal to the abnormality judgment threshold, the current access is determined to be abnormal access behavior; if the behavioral abnormality degree is less than the abnormality judgment threshold, the current access is determined to be normal access behavior.
[0151] This application also discloses D17, an access authentication device applied to a user terminal, the access authentication device comprising: The acquisition module is used to collect the user's biometric data in response to an access request to the target network, and to encrypt the biometric data to obtain encrypted biometric data. The encryption module is used to encrypt the access request information corresponding to the access request using a pre-shared key to obtain the encrypted access request information; The fusion module is used to embed the encrypted biometric data into the extended fields corresponding to the authorization protocol packet, and to generate a fused authorization protocol packet by combining the encrypted access request information. The sending module is used to send the converged authorization protocol packet to the server corresponding to the target network, so that the server can authenticate the access request according to the converged authorization protocol packet.
[0152] This application also discloses E18, an access authentication device, the access authentication device comprising: a memory, a processor, and an access authentication program stored in the memory and executable on the processor, wherein the access authentication program, when executed by the processor, implements the access authentication method as described above.
[0153] This application also discloses F19, a storage medium storing an access authentication program, which, when executed by a processor, implements the access authentication method as described above.
[0154] This application also discloses G20, a computer program product including an access authentication program that, when executed by a processor, implements the access authentication method as described above.
Claims
1. An access authentication method, characterized in that, The access authentication method is applied to the server, and the access authentication method includes: The system receives a converged authorization protocol packet sent by a user terminal, wherein the extended field of the converged authorization protocol packet contains encrypted biometric data, and the converged authorization protocol packet also includes encrypted access request information encrypted with a pre-shared key. The encrypted biometric data and the encrypted access request information are decrypted respectively to obtain the biometric data and access request information. The biometric data and the access request information are verified respectively, and the access request of the user terminal is authenticated based on the verification results.
2. The access authentication method as described in claim 1, characterized in that, The step of verifying the biometric data and the access request information respectively, and authenticating the access request of the user terminal based on the verification results, includes: The access request information is parsed to obtain key verification data, and the key verification data is matched and verified with the pre-shared key of the corresponding user pre-stored on the server to obtain the first-level verification result; If the first layer of verification results in a successful verification, the biometric data is matched and compared with the biometric template of the corresponding user pre-stored on the server to obtain the second layer of verification result. If the second-layer verification result is a successful comparison, then the user terminal's access request authentication is deemed successful. If the first layer of verification results in failure, or the second layer of verification results in failure to match, then the user terminal's access request authentication is deemed unsuccessful.
3. The access authentication method as described in claim 2, characterized in that, Before receiving the converged authorization protocol packet sent by the user terminal, the method further includes: Receive user identity information and biometric templates uploaded by user terminals through an encrypted secure channel; Negotiate encryption verification parameters with the user terminal, and allocate a pre-shared key to the user based on the negotiation result; The identity information, the biometric template, and the pre-shared key are stored on the server.
4. The access authentication method as described in any one of claims 1 to 3, characterized in that, After verifying the biometric data and the access request information respectively, and authenticating the user terminal's access request based on the verification results, the method further includes: Collect multidimensional behavioral features corresponding to this visit; Abnormal access behavior is identified based on the multidimensional behavioral features and the preset machine learning fusion model.
5. An access authentication method, characterized in that, The access authentication method is applied to a user terminal, and the access authentication method includes: In response to an access request to a target network, the user's biometric data is collected and encrypted to obtain encrypted biometric data. The access request information corresponding to the access request is encrypted using a pre-shared key to obtain the encrypted access request information; The encrypted biometric data is embedded into the extended fields corresponding to the authorization protocol packet, and combined with the encrypted access request information to generate a fused authorization protocol packet; The converged authorization protocol packet is sent to the server corresponding to the target network, so that the server authenticates the access request based on the converged authorization protocol packet.
6. An access authentication device, characterized in that, The access authentication device is applied to the server, and the access authentication device includes: The receiving module is used to receive a converged authorization protocol packet sent by a user terminal, wherein the extended field of the converged authorization protocol packet contains encrypted biometric data, and the converged authorization protocol packet also includes encrypted access request information encrypted with a pre-shared key; The decryption module is used to decrypt the encrypted biometric data and the encrypted access request information respectively to obtain the biometric data and the access request information. The verification module is used to verify the biometric data and the access request information respectively, and to authenticate the access request of the user terminal based on the verification results.
7. An access authentication device, characterized in that, The access authentication device is applied to the user terminal, and the access authentication device includes: The acquisition module is used to collect the user's biometric data in response to an access request to the target network, and to encrypt the biometric data to obtain encrypted biometric data. The encryption module is used to encrypt the access request information corresponding to the access request using a pre-shared key to obtain the encrypted access request information; The fusion module is used to embed the encrypted biometric data into the extended fields corresponding to the authorization protocol packet, and to generate a fused authorization protocol packet by combining the encrypted access request information. The sending module is used to send the converged authorization protocol packet to the server corresponding to the target network, so that the server can authenticate the access request according to the converged authorization protocol packet.
8. An access authentication device, characterized in that, The access authentication device includes: a memory, a processor, and an access authentication program stored in the memory and executable on the processor, wherein the access authentication program, when executed by the processor, implements the access authentication method as described in any one of claims 1 to 4 or 5.
9. A storage medium, characterized in that, The storage medium stores an access authentication program, which, when executed by a processor, implements the access authentication method as described in any one of claims 1 to 4 or 5.
10. A computer program product, characterized in that, The computer program product includes an access authentication program that, when executed by a processor, implements the access authentication method as described in any one of claims 1 to 4 or 5.