An access control method and apparatus
By adopting an access control method based on user identity, the problem of policy management caused by the replacement of communication equipment is solved, and flexible policy configuration and efficient access control are achieved, reducing memory resource overhead and management workload.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2024-12-24
- Publication Date
- 2026-06-26
Smart Images

Figure CN122293348A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to an access control method and device. Background Technology
[0002] With the rapid development of network technology, network security and quality of service (QoS) issues are becoming increasingly prominent. For example, if a company's critical server resources are accessed arbitrarily, confidential information can easily be leaked, creating security risks. In modern network communication, access control is a crucial means of ensuring network security and compliance.
[0003] In existing technologies, access control policies are typically configured based on Internet Protocol (IP) addresses to manage user access permissions. When the communication equipment accessing the network is changed or replaced, a new access control policy needs to be configured for the new IP address because the new communication equipment is assigned a new IP address. As the number of communication devices increases, the number of configured access control policy entries also increases, making policy management increasingly difficult. Summary of the Invention
[0004] This application provides an access control method and device that enables the network device to match the same user identity and policy information when receiving data packets from different communication devices of the same user, since the access control policy is configured based on the user identity rather than the network address of the communication device. This eliminates the need to reconfigure policy information for the new network address and prevents policy entries from increasing due to the change of network address, thereby reducing the difficulty of policy management.
[0005] To achieve the above objectives, the embodiments of this application adopt the following technical solutions:
[0006] Firstly, an access control method is provided, applied to a network device. In this method, the network device receives a first data packet from a first communication device. The first data packet includes a first network address, which is the network address of the first communication device. When the network device determines, based on a mapping relationship, that the first network address corresponds to a first user identifier, and that the access control policy contains first policy information matching the first user identifier, the network device processes the first data packet according to the first policy information. The mapping relationship includes the correspondence between different network addresses and user identifiers, and the access control policy includes multiple policy information entries, each including a correspondence between a user identifier and a packet processing operation.
[0007] In the aforementioned access control method, through this mapping relationship, the network device can accurately map the source network address in the received data packet to the corresponding user identity identifier, thereby achieving user-level access control. After receiving a first data packet from any first communication device, if the network device determines, based on the mapping relationship, the first user identity identifier corresponding to the first network address in the first data packet, and the access control policy contains first policy information matching the first user identity identifier, then the data packet is processed according to the first policy information. When a user changes communication devices, since the access control policy is configured based on the user identity identifier rather than the communication device's network address, the network device can match the same user identity identifier and the same policy information when receiving data packets from different communication devices of the same user. This avoids the need to add configuration policy information for the network address of each new communication device accessing the network, reducing the need to reconfigure policies due to network address changes. It eliminates the need for policy approval and updates, effectively reducing memory space usage, minimizing TCAM resource overhead, alleviating management workload, and improving enterprise operation and maintenance efficiency.
[0008] When security groups are defined, the mapping relationship includes the correspondence between different network addresses and user and group identifiers. This mapping relationship determines the user and group identifiers corresponding to the network addresses in data packets. When a user within the same group changes their communication device, resulting in a change in their network address, the same policy information can still be matched based on the user's group identifier and corresponding user identifier, avoiding the need to reconfigure policies for changes in network addresses within security group policy configurations.
[0009] Furthermore, configuring policies based on user identities allows for setting policies for individual users, increasing the flexibility of policy configuration. At the same time, the intuitiveness of user identities makes the relationship between policy information and users clearer and easier to understand when viewing policies, facilitating policy management and improving policy maintenance efficiency.
[0010] In one possible implementation, the network device receives a second data packet from a second communication device. The second data packet includes a second network address, which is the network address of the second communication device. If, based on a mapping relationship, it is determined that the second network address corresponds to a first user identifier, the network device processes the second data packet according to the first policy information in the access control policy that matches the first user identifier.
[0011] In this implementation, when a user switches from a first communication device to a second communication device, since both the mapping relationship and access control policy are configured based on the user's identity identifier rather than the network address, the network device determines, based on the second data packet sent by the user's second communication device, that the user's identity identifier corresponding to the second network address in the second data packet is still the first user's identity identifier. Furthermore, if the access control policy contains first policy information matching the first user's identity identifier, the second data packet is processed according to the first policy information. After the user changes communication devices, the second communication device continues to process data packets according to the first policy information. Therefore, there is no need to reconfigure the access control policy for the second network address of the second communication device. Determining the user's identity identifier through the mapping relationship, independent of the network address, ensures that the access control policy remains consistent and access permissions are unaffected when the network address changes due to the user switching between different communication devices. This reduces the need for policy reconfiguration due to communication device changes, simplifies policy management, and improves the flexibility of policy configuration.
[0012] In one possible implementation, when the mapping relationship includes the correspondence between different network addresses, user identifiers, and group identifiers, and the policy information includes the correspondence between group identifiers and user identifiers used to indicate the source of the packet and the packet processing operation, and the user identifier includes a normal state or an ambiguous state, the network device receives a third data packet from a third communication device. The third data packet includes a third network address, which is the network address of the third communication device. If, based on the mapping relationship, it is determined that the third network address corresponds to a first group identifier, and the access control policy contains second policy information matching the first group identifier, and the user identifier in the second policy information is ambiguous, the network device processes the third data packet according to the second policy information; or, based on the mapping relationship, it is determined that the third network address corresponds to a first group identifier and a second user identifier, and the access control policy contains third policy information matching the first group identifier and the second user identifier. If the third policy information includes a normal second user identifier, the network device processes the third data packet according to the third policy information.
[0013] In this implementation, the network device determines the user identity identifier and group identifier corresponding to the network address in the data packet based on the mapping relationship. When the access control policy of the network device includes an ambiguous user identity identifier in the policy information matching the group identifier corresponding to the data packet, the network device performs access control processing on the data packet according to the policy information matching the group identifier. As long as the group identifier matches, it is not necessary to consider whether the user identity identifier matches; the data packet is processed directly according to the policy information matching the group identifier. If the access control policy of the network device includes a normal user identity identifier in the policy information matching the group identifier, the data packet is processed according to the policy information matching both the group identifier and the user identity identifier. In this case, both the group identifier and the user identity identifier must match for the data packet to be processed according to the policy information matching both the group identifier and the user identity identifier.
[0014] In one possible implementation, the network device receives a fourth data packet from a fourth communication device. The fourth data packet includes a fourth network address, which is the network address of the fourth communication device. If, based on a mapping relationship, it is determined that the fourth network address corresponds to a first set of identifiers and a second user identity identifier, the network device processes the fourth data packet using third policy information that matches the first set of identifiers and the second user identity identifier and includes the normal state of the second user identity identifier.
[0015] In this implementation, after a privileged user within a group replaces the third communication device with the fourth, the user identity and group identity corresponding to the network address of the data packet still correspond to the second and third policy information. Therefore, after a privileged user changes communication devices, the network device can determine the existing access control policy information based on the mapping relationship, without needing to configure policy information for the new communication device's network address. This reduces the need to reconfigure policies due to network address changes and lowers the difficulty of policy management. Simultaneously, it allows users to maintain the same access permissions on different communication devices, enhancing the flexibility of policy configuration.
[0016] In one possible implementation, the network device receives a fifth data packet from a fifth communication device. The fifth data packet includes a fifth network address, which is the network address of the fifth communication device. If, based on a mapping relationship, the fifth network address corresponds to a first set of identifiers, the network device processes the fifth data packet according to second policy information that matches the first set of identifiers and includes a user identity identifier in an ambiguity state. If, however, the fifth network address corresponds to both the first set of identifiers and a third user identity identifier, the third user identity identifier does not match the normal state second user identifier in the third policy information.
[0017] In this implementation, by establishing the mapping between group identifiers and network addresses, non-privileged users within a group can still enjoy the general rights of their group after device replacement, while preventing unauthorized privileged access and enhancing network access security. Establishing the mapping between group identifiers, user identity identifiers, and network addresses allows special users within the group to enjoy additional access controls. By differentiating user identity states (normal and ambiguous states) in the policy, more granular access control is provided, enhancing the flexibility of policy configuration and improving maintenance efficiency.
[0018] In one possible implementation, the user identifier is a unique digital identifier for the user. The normal state is a digital identifier, while the ambiguous state differs from the digital state. Alternatively, the ambiguous user identifier is empty.
[0019] In one possible implementation, the access control policy is stored in a three-state content addresser (TCAM), where each storage location in the TCAM is in a state of 0, 1, or irrelevant. When the state of each storage location corresponding to the user identifier in the access control policy is 0 or 1, the user identifier is in a normal state. When the state of the storage location corresponding to the user identifier in the access control policy is irrelevant, the user identifier is in an ambiguous state.
[0020] In one possible implementation, the network device obtains personal information of different users from a server, or obtains personal information of different users in response to a configuration operation. Then, the network device generates user identifiers for different users based on their personal information, establishes a mapping relationship between different network addresses and user identifiers, and transforms the user's personal information in the initial access control policy based on the user identifiers to obtain the aforementioned access control policy. The initial access control policy is configured based on the user's personal information. The policy information in the initial access control policy includes the correspondence between the user's personal information and message processing operations. The access control policy obtained after the network device transforms the user's personal information into user identifiers also includes the correspondence between the user identifiers and message processing operations.
[0021] This implementation method can flexibly obtain the personal information of different users, generate user identity identifiers based on the personal information of different users, construct mapping relationships and access control policies, and improve the efficiency of access control.
[0022] In one possible implementation, the network device obtains the mapping relationship and access control policy from the server.
[0023] Alternatively, network devices obtain user identifiers for different users from the server. The network devices then generate a mapping relationship between different network addresses and user identifiers, and transform the user's personal information in the initial access control policy based on the user identifiers to obtain the access control policy.
[0024] In this implementation, the mapping relationship and access control policy or user identity are obtained through the server, making the configuration of the mapping relationship and policy more flexible.
[0025] In one possible implementation, the network device includes a control plane and a forwarding plane. The control plane obtains personal information of different users from the server, or obtains personal information of different users in response to a configuration operation. The control plane generates user identifiers for different users based on their personal information, and establishes a mapping relationship between different network addresses and user identifiers. Furthermore, the control plane transforms the user's personal information in the initial access control policy based on the user identifiers to obtain the access control policy.
[0026] Alternatively, the control plane obtains the mapping relationships and access control policies from the server.
[0027] Alternatively, the control plane can obtain user identifiers for different users from the server, generate a mapping relationship between different network addresses and user identifiers, and generate access control policies based on user identifiers.
[0028] The control plane then sends the mapping relationship and access control policy to the forwarding plane. Based on this mapping relationship, the forwarding plane determines that the first network address corresponds to the first user identity, and that the access control policy contains first policy information that matches the first user identity, and then processes the first data packet according to the first policy information.
[0029] Alternatively, after obtaining the personal information of different users, the control plane generates access control policies based on this information. The control plane then sends the mapping relationship and the user information in the access control policies to the forwarding plane after converting them into user identifiers. The forwarding plane, based on this mapping relationship, determines that the first network address corresponds to the first user identifier, and that the access control policy contains first policy information matching the first user identifier. In this case, the forwarding plane processes the first data packet according to the first policy information.
[0030] In this implementation, by separating the control plane from the forwarding plane, network devices can process received data packets more flexibly. The control plane centrally manages the personal information and user identification of different users, mapping relationships, and access control policies, thereby improving security; the forwarding plane performs access control processing on data packets according to the policy information matched to the data packets, improving data packet processing efficiency and enhancing network performance and security.
[0031] In one possible implementation, the network device includes a forwarding plane. The forwarding plane obtains mapping relationships and access control policies from the server. When the network device determines, based on the mapping relationship, that a first network address corresponds to a first user identifier, and the access control policy contains first policy information matching the first user identifier, it processes the first data packet according to the first policy information.
[0032] In this implementation, the forwarding plane obtains the mapping relationship and access control policy from the control plane in the independently existing network management server, which simplifies the network device structure, reduces the cost of network devices, and enhances the unified management and maintenance efficiency of access control policies.
[0033] In a second aspect, an electronic device is provided, comprising: a memory and one or more processors; the memory and the processors are coupled; wherein the memory stores computer program code, the computer program code including computer instructions, which, when executed by the processor, cause the electronic device to perform the access control method described in any of the first aspects above.
[0034] Thirdly, a computer-readable storage medium is provided, including computer instructions that, when executed on an electronic device, cause the electronic device to perform the access control method described in any of the first aspects above.
[0035] Fourthly, a computer program product is provided that, when run on a computer, causes the computer to execute the access control method described in any of the first aspects above.
[0036] The technical effects of any of the design methods in the second to fourth aspects can be found in the technical effects of different design methods in the first aspect, and will not be repeated here. Attached Figure Description
[0037] Figure 1 This is a schematic diagram of an access control method based on IP address configuration policies;
[0038] Figure 2 This is a schematic diagram of an access control method based on group identifier configuration policy;
[0039] Figure 3 A schematic diagram of an access control system provided in an embodiment of this application;
[0040] Figure 4This application provides a schematic diagram of the structure of an access control system according to an embodiment of the present application.
[0041] Figure 5 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;
[0042] Figure 6 A flowchart illustrating an access control method provided in an embodiment of this application;
[0043] Figure 7 A schematic diagram illustrating a network device receiving data packets, provided as an embodiment of this application;
[0044] Figure 8 This is a schematic diagram illustrating a strategy information matching method provided in an embodiment of this application;
[0045] Figure 9 A schematic diagram illustrating an access control method provided in an embodiment of this application;
[0046] Figure 10 A schematic diagram illustrating another access control method provided in an embodiment of this application;
[0047] Figure 11 This is a schematic diagram of a TCAM matching process;
[0048] Figure 12 A schematic diagram illustrating another strategy information matching method provided in this application embodiment;
[0049] Figure 13 A schematic diagram illustrating another strategy information matching method provided in this application embodiment;
[0050] Figure 14 This is a schematic diagram of another access control method provided in an embodiment of this application. Detailed Implementation
[0051] The technical solutions of the embodiments of this application will be described below with reference to the accompanying drawings. In the description of the embodiments of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B; "and / or" in this text is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Furthermore, in the description of the embodiments of this application, "multiple" refers to two or more than two.
[0052] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this embodiment, unless otherwise stated, "a plurality of" means two or more.
[0053] In the embodiments of this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of the words "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner.
[0054] With the development of internet technology, network security and QoS issues have become increasingly important. In the era of modern network communication, implementing effective access control mechanisms has become a key part of building network security barriers and ensuring compliant operations.
[0055] Today, more and more employees are no longer limited to using only one communication device to access the corporate network. Instead, an employee often owns multiple communication devices, such as computers, mobile phones, and tablets. For companies with extremely high management requirements, access control for employees is often exceptionally strict, striving to achieve the principle of least privilege. Taking the financial industry as an example, policy control in this industry is typically based on IP address-based access control policies to manage user access permissions. Specifically, this method configures corresponding policies for the IP addresses of each communication device connected to the network, enabling strict access control management of resources that users attempt to access. In this way, even in complex network environments, it ensures that only authorized user IP addresses can access specific server resources, thereby enhancing network security.
[0056] When employees change workstations or communication devices and obtain new IP addresses, the new IP addresses may lack policy information, preventing employees from accessing any applications. To address this, companies with high control requirements typically employ IT management systems or access control systems. When an employee obtains a new IP address, they must proactively request access; only after administrator approval can the new IP address's policy information be issued to network devices.
[0057] For example, see Figure 1When user A switches from phone 1 to phone 2 and obtains a new IP address of 192.1.1.6, the network device receives the new IP address 192.1.1.6. The access control policy does not contain any policy information allowing the new IP address 192.1.1.6 to access 10.1.1.0 / 24; therefore, user A cannot access 10.1.1.0 / 24 via phone 2 with IP address 192.1.1.6. Therefore, the network device needs to reconfigure a policy for the new IP address 192.1.1.6, allowing devices with IP address 192.1.1.6 to access 10.1.1.0 / 24. After configuring this policy, user A is allowed to access address 10.1.1.0 / 24 via phone 2.
[0058] Furthermore, since IP addresses themselves do not have intuitive real-world meaning, it is difficult to directly associate IP addresses in policy entries with specific users when viewing policies. Therefore, to ensure the readability and understandability of policies, it is usually necessary to add descriptive information to policy entries so that it is clear what user or device each IP address represents, thereby ensuring that the policy can be understood.
[0059] The aforementioned access control scheme based on IP address policy configuration requires reconfiguration of individual policy entries whenever an IP address changes, leading to a surge in the number of policies, straining network device memory, and increasing management complexity. Furthermore, the method of having employees proactively request permissions for new IP addresses, followed by administrator approval and policy issuance, increases the management workload and is inefficient. Additionally, the addition and management of descriptive information within policy entries relies on administrators' personal habits, potentially resulting in misunderstandings of policies and maintenance difficulties.
[0060] In some cases, the above-mentioned method of policy matching based on IP address is suitable for situations where there is a lack of scientific planning for employee permission groups, or for access control needs where it is difficult to divide security groups.
[0061] Related technologies also include security group-based policy configuration methods. This method divides users into groups, ensuring that users within a group maintain appropriate access permissions regardless of changes in their IP addresses. Similarly, when a user owns multiple communication devices, all these devices belong to the user's security group. Therefore, regardless of changes in the communication devices accessing the network, the user can maintain consistent access control policies across all their communication devices.
[0062] Understandably, network devices store a mapping between IP addresses and security group identifiers. When a network device receives a data packet, it determines how to process it based on this mapping. The network device matches the group identifier corresponding to the IP address in the data packet with policy entries. Based on the matched policy information, the network device executes the appropriate policy and processes the data packet accordingly. For example, a data packet may include an IP address and a destination address.
[0063] For example, such as Figure 2 In (a) of the diagram, user A belongs to security group 201. User A connects communication devices 1 (phone 1), 2 (phone 2), and a computer to the network. Phone 1 has an IP address of 192.1.1.5, phone 2 has an IP address of 192.1.1.6, and the computer has an IP address of 192.1.2.2. The network device includes the mapping between IP addresses and group identifiers, as well as access control policies based on group identifiers. The network device includes a control plane and a forwarding plane. The control plane of the network device distributes the access control policies based on group identifiers to the forwarding plane for storage. The access control policies include policy information allowing all users with group identifier 201 to access the 10.1.1.0 / 24 address. Simultaneously, the control plane of the network device distributes the mapping between the IP addresses of phone 1, phone 2, and the computer and group identifier 201 to the forwarding plane. Since the forwarding plane contains the policy information for group identifier 201, the network device processes the data packets sent by phone 1, phone 2, and the computer according to the policy corresponding to group identifier 201.
[0064] When User A changes their network access device from mobile phone 1 to a computer, the network device receives data packets sent by the computer. Based on the IP address 192.1.2.2 sent by the communication device, it determines the corresponding group identifier to be 201. If a policy matching group identifier 201 exists in the network device, then the network device will still process the data packets sent by the computer according to the policy matching group identifier 201, allowing User A to access the 10.1.1.0 / 24 address using the computer. In other words, when User A changes from mobile phone 1 to computer, the network device matches the policy information for group identifier 201 in all received data packets based on the IP address. Therefore, regardless of how User A accesses the network, all three communication devices owned by User A (including mobile phone 1, mobile phone 2, and computer) belong to the group identifier 201 corresponding to User A, and thus can match the policy information corresponding to group identifier 201, allowing access to the 10.1.1.0 / 24 address.
[0065] If a user within a group needs special access permissions, then those permissions must be configured individually for that user based on their IP address. Specifically, the network device reconfigures a policy based on the IP address of the communication device used by that user.
[0066] For example, see Figure 2 In section (b), the access control policy of the network device allows all users within group ID 201 to access the 10.1.1.0 / 24 address, but disallows access to the 10.1.2.0 / 24 address. However, if user A within the group needs to access the 10.1.2.0 / 24 address using mobile phone 1, an additional policy needs to be configured, combining user A's computer's IP address and group ID 201, to allow user A to access the 10.1.2.0 / 24 address using mobile phone 1. Alternatively, if user A within the group needs to access the 10.1.2.0 / 24 address using mobile phone 2, an additional policy needs to be configured, combining user A's mobile phone 2's IP address and group ID 201, to allow user A to access the 10.1.2.0 / 24 address using mobile phone 2. In this access control policy, the source IP address is " / ", indicating that the policy information does not contain a source IP address and is not restricted by a source IP address.
[0067] The above-described policy configuration scheme based on security groups ensures that all group members adhere to the same group policy rules. When special permissions need to be set for individual users within the group, additional policy rules must be created by combining IP addresses with the group identifier. Furthermore, when a user's IP address changes, the policy needs to be reconfigured based on the new IP address, increasing the number of policy entries, straining network device storage space, and increasing the difficulty of policy management and maintenance. Similarly, when an IP address changes, employees must proactively request permissions for the new IP address, and administrators must approve and issue the policy, increasing the management workload and reducing efficiency. Additionally, policy entries based on IP addresses require corresponding descriptive information, and the addition and management of these descriptions depend on the administrator's personal habits, potentially leading to misunderstandings of the policy and maintenance difficulties. Moreover, group identifier policies cannot be set for individual users within the group, resulting in poor policy configuration flexibility.
[0068] This application provides an access control method in which a network device receives a first data packet from a first communication device. The first data packet includes a first network address, which is the network address of the first communication device. That is, the first network address is the source network address of the data packet. When the network device determines, based on a mapping relationship, that the first network address corresponds to a first user identity identifier, and there is first policy information in the access control policy that matches the first user identity identifier, it performs access control processing on the first data packet according to the first policy information. The mapping relationship includes the correspondence between different network addresses and user identity identifiers. The access control policy includes multiple policy information entries, which include the correspondence between user identity identifiers and data packet processing operations. The user identity identifier in the policy information is the source user identity identifier corresponding to the source network address of the data packet, and can be used to indicate the source of the data packet. Alternatively, the policy information can be understood as including the correspondence between the source user identity identifier and the packet processing operation.
[0069] Through this mapping relationship, network devices can accurately map the source network address in received data packets to the corresponding user identity, thus achieving user-level access control. When a user changes communication devices, since the access control policy is configured based on the user identity rather than the communication device's network address, the network device can match the same user identity and policy information when receiving data packets from different communication devices of the same user. This avoids the need to add configuration policy information for the network address of each new communication device accessing the network, reducing the need to reconfigure policies due to network address changes. It eliminates the need for policy approval and updates, effectively reducing memory space usage, minimizing TCAM resource overhead, alleviating management workload, and improving enterprise operation and maintenance efficiency.
[0070] When security groups are defined, the mapping relationship includes the correspondence between network addresses, user identifiers, and group identifiers. Network devices use this mapping relationship to determine the user identifier and group identifier corresponding to the network address in a data packet. When a user within the same group changes their communication device, resulting in a change in their network address, the network device can still match the same policy information based on the user's group identifier and corresponding user identifier, avoiding the need to reconfigure policies when network addresses change in security group policy configurations.
[0071] Furthermore, configuring policies based on user identities allows for setting policies for individual users, increasing the flexibility of policy configuration. At the same time, the intuitiveness of user identities makes the relationship between policy information and users clearer and easier to understand when viewing policies, facilitating policy management and improving policy maintenance efficiency.
[0072] The access control method provided in this application can be applied to access control systems.
[0073] First, let's introduce the access control system.
[0074] Figure 3 A schematic diagram of an access control system provided in an embodiment of this application is shown. Figure 3 As shown, the access control system includes network devices and multiple communication devices. The network devices and communication devices establish a communication connection. The communication devices send data packets to the network devices, and the network devices perform corresponding access control processing on the received data packets according to the mapping relationship and access control policies. Furthermore, the access control system may also include a server. The network devices establish a communication connection with the server. The network devices can obtain personal information (such as user accounts, user names, or user identification IDs) or user identity identifiers from the server, and the server can authenticate user identities, etc.
[0075] Specifically, the mapping relationships and access control policies of network devices can be obtained in various ways. In some embodiments, the network device obtains the personal information of different users from the server, generates different user identity identifiers based on the personal information of different users, and then generates a mapping relationship based on different network addresses and user identity identifiers. Furthermore, the network device generates an access control policy based on the user identity identifier, or, based on the user identity identifier, transforms the user's personal information in the initial access control policy to generate the access control policy. The initial access control policy is configured based on the user's personal information. The policy information in the initial access control policy includes the correspondence between the user's personal information and message processing operations. The access control policy obtained after the network device transforms the user's personal information into a user identity identifier also includes the correspondence between the user identity identifier and message processing operations.
[0076] In other embodiments, the network device may also obtain personal information of different users in response to a configuration operation, and generate user identifiers for different users based on their personal information. Then, a mapping relationship is generated between different network addresses and user identifiers. Furthermore, the network device generates an access control policy based on the user identifiers, or, based on the user identifiers, transforms the user's personal information in the initial access control policy to generate the access control policy.
[0077] This allows for the flexible acquisition of personal information from different users, the generation of user identifiers based on this information, the construction of mapping relationships and access control policies, and the improvement of access control efficiency.
[0078] In other embodiments, the network device directly obtains the mapping relationship and access control policy from the server. Obtaining the mapping relationship and access control policy from the server improves policy matching efficiency.
[0079] Once the network device obtains the mapping relationship and access control policy, it receives data packets sent from the communication device. Based on the mapping relationship, it determines that the source network address in the data packet corresponds to the user identity identifier, and if there is policy information in the access control policy that matches the user identity identifier, it performs access control processing on the data packet according to the matching policy information.
[0080] In the scheme where policy matching is based on user identity identifiers, the mapping relationship includes the correspondence between different network addresses and user identity identifiers. In the grouped scenario, the mapping relationship includes the correspondence between different network addresses and both user identity identifiers and group identifiers. In the grouped scenario, the mapping relationship may also include a first correspondence between network addresses and user identity identifiers, and a second correspondence between network addresses and group identifiers. Network devices can also obtain the first and second correspondences respectively.
[0081] In some embodiments, when obtaining personal information of different users from the server, such as user accounts (e.g., A or B) or user names, the network device generates corresponding user identifiers based on the different user accounts or user names. When obtaining user IDs (e.g., 10001) from the server, the network device uses the user IDs as user identifiers.
[0082] In some embodiments, the network device includes a forwarding plane and a control plane. See also Figure 4 In (a) of the diagram, the control plane of the network device establishes a communication connection with the server, obtains personal information of different users from the server, generates user identifiers for different users based on their personal information, then generates a mapping relationship between different network addresses and user identifiers, and finally generates access control policies based on the user identifiers. Alternatively, in response to a configuration operation, the control plane of the network device obtains personal information of different users, generates user identifiers for different users based on their personal information, generates a mapping relationship between different network addresses and user identifiers, and finally generates access control policies based on the user identifiers. The control plane then sends the mapping relationship and access control policies to the forwarding plane.
[0083] Alternatively, the network device's control plane obtains the mapping relationships and access control policies from the server. Or, the network device's control plane obtains the user identifiers for different users from the server, then generates mapping relationships based on different network addresses and user identifiers, and generates access control policies based on the user identifiers. The control plane then sends the mapping relationships and access control policies to the forwarding plane.
[0084] Alternatively, after obtaining the personal information of different users, the control plane generates an initial access control policy based on this information. The control plane then converts the user's personal information in the initial access control policy into a user identifier, resulting in the aforementioned access control policy. Finally, the control plane sends the mapping relationship and access control policy to the forwarding plane.
[0085] Alternatively, after obtaining the personal information of different users, the control plane generates access control policies based on these individual user profiles. The control plane then sends the mapping relationships and access control policies to the forwarding plane. Specifically, when sending these policies, the control plane converts the user's personal information within the access control policies into user identifiers before forwarding them.
[0086] After obtaining the mapping relationship and access control policy, the control plane sends them to the forwarding plane. The forwarding plane receives data packets sent by the communication device. Based on the mapping relationship, it determines the user identity corresponding to the source network address in the data packet. If the access control policy contains policy information that matches the user identity corresponding to the source network address in the data packet, the forwarding plane processes the data packet according to the matching policy information.
[0087] By separating the control plane from the forwarding plane, network devices can process received data packets more flexibly. The control plane centrally manages user identities, mapping relationships, and access control policies, improving security; while the forwarding plane performs access control processing on data packets according to the policy information matched to the data packets, improving data packet processing efficiency and enhancing network performance and security.
[0088] In other embodiments, the network device includes a forwarding plane but does not include a control plane. See also Figure 4In (b) of the diagram, the forwarding plane obtains the mapping relationship and access control policy from the network management server where the control plane resides. The network management server where the control plane resides can be any device, server, or cloud management system containing device control information, existing independently of the network device where the forwarding plane resides. Based on the mapping relationship and access control policy obtained from the control plane in the network management server, the forwarding plane in the network device determines the first user identity identifier corresponding to the first network address used as the source network address in the received data packet. If a first policy information matching the first user identity identifier exists in the access control policy, the data packet is processed according to the first policy information. The forwarding plane obtains the mapping relationship and access control policy from the independently existing control plane in the network management server, simplifying the network device structure, reducing network device costs, and enhancing the unified management and maintenance efficiency of access control policies.
[0089] In one possible implementation, such as Figure 4 As shown, the forwarding plane of a network device includes a processor and memory. For example, the processor may include a network processor (NP) or an application-specific integrated circuit (ASIC). Based on the mapping relationship, the processor determines the correspondence between the source network address and the user identity in the data packet, and whether there is policy information in the access control policy in the memory that matches the user identity. The processor then processes the data packet according to the matching policy information.
[0090] The communication device in this application embodiment can be understood as a computer device with communication functions. For example, it can be a user equipment, user terminal, or mobile terminal. Specifically, the communication device can be a tablet computer, mobile phone, laptop computer, smart screen, television, in-vehicle equipment, netbook, personal digital assistant (PDA), wearable device, augmented reality (AR) / virtual reality (VR) device, personal computer, or terminal device in a 5G communication network or a communication network after 5G. This application embodiment does not limit the specific device form of the communication device.
[0091] The network devices in the aforementioned access control system can be devices with access control functions. For example, they can be network devices such as switches, routers, gateways, and firewalls, or controllers in the network, or other types of devices with access control functions. This application does not limit the specific type of network device. The network device includes mapping relationships and access control policies. Based on this, the network device can perform access control processing on received data packets, such as QoS policies, MQC, packet filtering, or security policies.
[0092] For example, the server in the access control system described above may be an AAA server and / or a network management server, used to perform the functions related to the server. This application does not limit the specific form of the server in the access control system.
[0093] The communication equipment and network equipment in the embodiments of this application can adopt, for example... Figure 5 The structure of the communication device shown, or including Figure 5 The components shown. (As shown) Figure 5 As shown, the communication device 50 may include one or more processors 501, memory 502 and communication interface 503.
[0094] The memory 502, communication interface 503, and processor 501 are coupled together. For example, the memory 502, communication interface 503, and processor 501 can be coupled together via bus 504.
[0095] Processor 501 may be a processor or controller, such as a central processing unit (CPU), a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in connection with the embodiments of this application. The processor may also be a combination that implements computational functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0096] The communication interface 503 is used to communicate with other devices or communication networks, such as Ethernet, RAN, and wireless local area networks (WLAN). The communication interface 503 can also be a transceiver circuit located within the processor 501, used to implement signal input and signal output for the processor. In this embodiment, the communication interface 503 can be used to send and receive communication data such as data packets.
[0097] Memory 502 can be a device with storage function. For example, it can be read-only memory (ROM) or other types of static storage devices capable of storing static information and instructions; random access memory (RAM) or other types of dynamic storage devices capable of storing information and instructions; electrically erasable programmable read-only memory (EEPROM); compact disc read-only memory (CD-ROM) or other optical disc storage; optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.); magnetic disk storage media or other magnetic storage devices; or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited to these. Memory can exist independently and be connected to the processor via bus 504. Memory can also be integrated with the processor.
[0098] For example, memory 502 can be used to store mapping relationships and access control policies. For instance, the access control policy can be in a ternary content addressable memory (TCAM).
[0099] The memory 502 is also used to store computer execution instructions for implementing the scheme of this application, and the execution is controlled by the processor 501. The processor 501 is used to execute the computer execution instructions stored in the memory 502, thereby implementing the access control method provided in the embodiments of this application.
[0100] Alternatively, in this embodiment, the processor 501 may execute the processing-related functions of the access control method provided in the following embodiments of this application, and the communication interface 503 may be responsible for communicating with other devices or communication networks. This embodiment does not specifically limit this.
[0101] The computer execution instructions in the embodiments of this application may also be referred to as application code, and the embodiments of this application do not specifically limit this.
[0102] Bus 504 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The aforementioned bus 504 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 5 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0103] In some embodiments, processor 501 may include one or more CPUs.
[0104] In some embodiments, the communication device 50 may include multiple processors. Each of these processors may be a single-core processor or a multi-core processor. The processors may include, but are not limited to, at least one of the following: a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a microcontroller unit (MCU), or an artificial intelligence processor, and other computing devices that run software. Each computing device may include one or more cores for executing software instructions to perform calculations or processing.
[0105] For example, the processor may include an NP or an ASIC, etc.
[0106] In some embodiments, the communication device 50 may further include an output device 505 and an input device 506. The output device 505 communicates with the processor 501 and can display information in various ways. For example, the output device 505 may be a liquid crystal display (LCD), a light-emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. The input device 506 communicates with the processor 501 and can receive user input in various ways. For example, the input device 506 may be a mouse, keyboard, touchscreen device, or sensing device, etc.
[0107] based on Figure 5When the communication device 50 shown implements the access control method in the embodiments of this application, the memory is used to store mapping relationships and access control policies. Based on the mapping relationship, the processor determines the user identity identifier corresponding to the source network address in the data packet, and whether there is policy information in the access control policy in the memory that matches the user identity identifier, and processes the data packet according to the matching policy information.
[0108] The access control method provided in this application embodiment will be described below with reference to the accompanying drawings, taking a switch with the above-described network device as an example. Figure 6 As shown, the method may include the following steps S601-S602.
[0109] S601, The network device receives a first data packet from the first communication device, the first data packet including a first network address.
[0110] Network devices include access control devices within a network responsible for forwarding, processing, or managing data packets. For example, a network device can be a switch, or a router, firewall, or gateway—devices with access control functions. Network devices are responsible for receiving and processing data packets from different communication devices and performing access control processing.
[0111] The first data packet is generated by the first communication device and sent to the network device. The first data packet includes, but is not limited to, the network address of the first communication device and the destination network address. The network address of the first communication device is represented as the first network address (i.e., the source network address of the first data packet). The first network address can be an IP address (i.e., the source IP address) or a MAC address (i.e., the source MAC address), etc.
[0112] For example, see Figure 7 The first communication device is a computer, the first user identity is the user identity of user A, the identity is 10001, and the first network address is the network address of the computer, the first network address is 192.1.2.2.
[0113] In some embodiments, in response to a user's request for network resources, the first communication device generates a first data packet corresponding to the request and sends the first data packet to the network device. The network device receives the first data packet from the first communication device. For example, in response to a user opening a webpage to access an enterprise server, the first communication device generates a first data packet corresponding to the webpage opening operation and sends it to the network device, which then receives the first data packet from the first communication device.
[0114] S602. When the network device determines that the first network address corresponds to the first user identity based on the mapping relationship, and there is first policy information in the access control policy that matches the first user identity, the network device processes the first data packet according to the first policy information.
[0115] A user identity identifier is a unique identifier used to identify a user; different users have different user identity identifiers. User identity identifiers are independent of communication devices, and the same user can use multiple communication devices. For example, a user identity identifier can be a user ID or an identifier represented in numerical form.
[0116] Mapping relationships are used to represent the correspondence between network addresses and user identifiers. Different communication devices owned by the same user correspond to the same user identifier in the network device mapping relationship.
[0117] For example, Table 1 shows a mapping relationship. User A owns a laptop (network address 192.1.1.5) and a tablet (network address 192.1.1.6). In the mapping relationship of the laptop and the tablet on the network device, the corresponding user identity is user A's user identity 10001.
[0118] Table 1
[0119] Network address User Identity Authentication 192.1.1.5 10001 192.1.1.6 10001 192.1.1.7 10001 192.1.1.8 10002 192.1.2.2 10002 … …
[0120] As shown in Table 1, in the mapping relationship, the same user identity can correspond to multiple network addresses. For example, user identity 10001 corresponds to three network addresses: 192.1.1.5, 192.1.1.6, and 192.1.1.7. The same user identity 10002 corresponds to two network addresses: 192.1.1.8 and 192.1.2.2.
[0121] Access control policies include multiple policy information entries. Policy information represents access control rules that match user identities. For example, policy information contains a mapping between the user identity of the data packet's origin and the packet processing operation (such as permit and deny). The user identity in the policy information can be understood as the source user identity, that is, the user identity corresponding to the source network address of the data packet, which can be used to indicate the source of the data packet. Access control policies and their policy information can be configured for different users according to access control requirements. Network devices perform access control processing on data packets according to the matched policy information, such as allowing or denying packets, marking packet priorities, and recording traffic for billing purposes.
[0122] For example, Table 2 shows an access control policy. The access control policy includes policy information such as denying user ID 10001 access to destination address 10.1.1.0 / 24, and allowing user ID 10002 to access destination address 10.1.1.0 / 24.
[0123] Table 2
[0124] User Identity Authentication Destination address … Message processing operations 10001 10.1.1.0 / 24 … reject 10002 10.1.1.0 / 24 … allow … … … …
[0125] In some embodiments, the network device generates an initial access control policy based on the personal information of different users. The initial access control policy includes the correspondence between the personal information of different users and message processing operations. For example, a user's personal information may be a user account, user name, or user employee ID. The network device transforms the user's personal information in the initial access control policy based on the user's identity identifier to obtain the aforementioned access control policy.
[0126] For example, Table 3 shows an initial access control policy. The initial access control policy includes policy information such as denying user A access to the destination address 10.1.1.0 / 24 and allowing user B to access the destination address 10.1.1.0 / 24.
[0127] Table 3
[0128] User account Destination address … Message processing operations A 10.1.1.0 / 24 … reject B 10.1.1.0 / 24 … allow … … … …
[0129] Network devices determine the corresponding policy information by matching the source network address in the data packet with the user's identity identifier, and then perform access control processing on the data packet according to the matched policy information. For example, if the policy information indicates that access to network resources is permitted, the network device allows the user to access the network resources based on the policy information. Conversely, if the policy information indicates that a denial action is performed, the network device blocks the data packet from passing through, denying the user access to network resources. For instance, if a user with a specific identity identifier attempts to access unauthorized network resources, data packets from that user will be rejected.
[0130] For example, if the policy information includes limiting the download speed of the network address 192.168.1.10 to 10Mbps, then when a network device receives a data packet requesting to download resources from the network address 192.168.1.10, if it determines the user identity corresponding to the network address 192.168.1.10 in the data packet based on the mapping relationship, and if there is policy information matching the user identity, then it will perform the corresponding bandwidth limiting processing on the data packet sent from the network address 192.168.1.10 according to the matching policy information.
[0131] In this embodiment, when a first user sends a first data packet through any first communication device, the first data packet includes a first network address, which is the network address of the first communication device. The first network address is the source network address of the first data packet. After receiving the first data packet from the first communication device, the network device determines the first user identity identifier corresponding to the first network address of the first data packet based on the mapping relationship. Here, the first user identity identifier can also be understood as the user identity identifier corresponding to the first data packet. Simultaneously, if the network device's access control policy contains first policy information matching the first user identity identifier, the first data packet is processed according to the first policy information.
[0132] In other words, for any communication device and data packet, the network device uses the mapping relationship between network addresses and user identifiers, along with access control policies based on those user identifiers, to perform access control processing on the data packets. This ensures that communication devices of users who comply with the policies can access network resources, enhancing access security. Since the access control policy is based on user identifiers rather than network addresses, even if the communication device changes and the corresponding network address changes, as long as the user identifier remains the same, there is no need to add new policy information for the network address of the newly connected communication device. This reduces the need to reconfigure policies due to network address changes, lowering the complexity of policy management. Simultaneously, it allows users to maintain the same access permissions on different communication devices, enhancing the flexibility of policy configuration.
[0133] When the first user changes the first communication device to the second communication device, see [link to relevant documentation]. Figure 8 The second communication device sends a second data packet to the network device. The second data packet includes a second network address, which is the network address of the second communication device. The second network address is also the source network address of the second data packet. The network device receives the second data packet from the second communication device. Based on the aforementioned mapping relationship, and if it determines that the second network address in the second data packet also corresponds to the first user identifier, it processes the second data packet according to the first policy information in the access control policy that matches the first user identifier.
[0134] In other words, the first network address and the second network address correspond to the same user identity. When the first user changes from the first communication device to the second communication device, since the mapping relationship and access control policy are configured based on the user identity rather than the network address, the first user's second network address corresponds to the first user identity. The second data packet is processed according to the first policy information matched with the first user identity in the access control policy. After the first user changes communication devices, the second communication device continues to process data packets according to the first policy information. Therefore, there is no need to reconfigure the access control policy for the second communication device.
[0135] By identifying user identities through mapping relationships, this approach does not rely on network addresses. It ensures that access control policies remain consistent and access permissions are unaffected when users switch between different communication devices and their network addresses change. This reduces the need to reconfigure policies due to changes in communication devices, simplifies policy management, and improves the flexibility of policy configuration.
[0136] For example, see Figure 9 The network device's access control policy contains Policy Information 1 and Policy Information 2. Policy Information 1 indicates that user ID 10001 is denied access to destination address 10.1.1.0 / 24, while Policy Information 2 indicates that user ID 10002 is allowed to access destination address 10.1.1.0 / 24. The network device receives a first data packet from user A's first communication device. The first data packet contains the first network address 192.1.1.5 of the first communication device. Based on a mapping relationship, the network device determines that the identifier of user A corresponding to the first network address 192.1.1.5 is 10001. Simultaneously, the network device's access control policy contains Policy Information 1 (corresponding to the first policy information) that matches user A's first user ID 10001. That is, Policy Information 1 denies user A access to destination address 10.1.1.0 / 24. Therefore, the network device processes the first data packet according to Policy Information 1, rejecting the first data packet and disallowing access to the target address.
[0137] like Figure 9As shown, the first communication device and the second communication device correspond to the same user A with the same user identity. The network device receives a second data packet sent by the second communication device, which includes the second network address of the second communication device, 192.1.1.7. Based on the mapping relationship, the network device determines that the identifier of user A corresponding to the second network address 192.1.1.7 in the second data packet is 10001. At the same time, the access control policy in the network device contains policy information 1 that matches the first user identity 10001 of user A. Based on policy information 1, the network device denies the first user identity 10001 access to the destination address 10.1.1.0 / 24. That is, policy information 1 denies user A access to the destination address 10.1.1.0 / 24 and denies the second communication device access to the destination address 10.1.1.0 / 24.
[0138] In other words, if user A changes between N (an integer greater than 1) communication devices, causing a change in the source network address of the data packets, then no matter how large the value of N is, the same policy information can be matched based on user A's user identity. This reduces the number of policy information entries to one-N when the policy is configured based on IP address, thus realizing the network address change caused by the same user changing communication devices.
[0139] Therefore, when a user changes their communication equipment, causing a change in the source network address of the data packet, the network device can still determine the user's identity based on the new source network address and match the policy information corresponding to that user's identity. The matched policy information remains unchanged before and after the change of communication equipment, and there is no need to reconfigure the policy for the new network address. The policy entries will not increase due to the change of network address, saving the memory space occupied by the network device and reducing the difficulty of policy management.
[0140] At the same time, it allows the same user to maintain the same access permissions on different communication devices, enhancing the flexibility of policy configuration.
[0141] like Figure 9 As shown, communication device a corresponds to a different user identity and a different user than the first communication device. Communication device a corresponds to user B. When the network device receives a data packet sent by communication device a, it determines, based on the mapping relationship, that the user identity corresponding to the source network address in the data packet is 10002. Simultaneously, the access control policy in the network device contains policy information 2 that matches the user identity 10002 of user B. Policy information 2 allows the data packet corresponding to user identity 10002 to access the target address 10.1.1.0 / 24. The user identity corresponding to this data packet and network address matches policy information 2, but does not match policy information 1.
[0142] Therefore, access control policies are matched and processed at the user identity level. Network devices process data packets based on policy information matched with the user identity corresponding to the source network address in the data packet. Different data packets are processed according to the policy information matched with the user identity, and access control is not performed according to policy information that does not match the user identity.
[0143] In other implementations, users can be grouped, with each group corresponding to a group identifier. The group identifier is assigned to the entire group of users, allowing all users within the group to have the same access control policy and enabling the same processing to be applied to different users within the group. The same group identifier can correspond to multiple policy messages. In this case, the pre-defined mapping relationship includes the correspondence between different network addresses, user identifiers, and group identifiers.
[0144] In this context, the group identifier in the access control policy can be understood as the source group identifier, which is the group identifier corresponding to the source network address and source user identity of the data packet, and can be used to indicate the source of the data packet.
[0145] Furthermore, individual users within a group can have privileges. The corresponding access control policies include a general policy for all users in the group and a privileged policy for privileged users within the group. In the access control policy, the general policy corresponds to the group identifier, while the privileged policy corresponds to both the group identifier and the user identity identifier of the privileged user.
[0146] In some embodiments, a general policy includes a mapping between group identifiers and message processing operations, which does not include user identity identifiers. A privileged policy includes a mapping between group identifiers, user identity identifiers, and message processing operations.
[0147] The network device determines the group identifier of the user's packet based on the source network address in the data packet, according to the mapping relationship. This yields the group identifier corresponding to the data packet. If the policy information matched based on the group identifier only includes the group identifier and not the user identity identifier, the network device performs access control processing on the data packet based on this policy information. In this case, the access control policy of the network device that includes the group identifier but excludes the user identity identifier is a general policy. If the policy information matched based on the group identifier does not include the user identity identifier, as long as the group identifier matches, the user identity identifier is not considered, and the data packet is processed directly according to this policy information.
[0148] In one possible design, the user identity is empty when the policy information does not include the user identity. For example, a special symbol can be used to represent an empty user identity. For instance, it can be represented by " / ".
[0149] Network devices determine the user's identity and the group identifier of the user's packet based on the source network address in the data packet, according to a mapping relationship. This yields the user's identity and group identifier for the data packet. If the policy information matching the group identifier of the data packet includes both the group identifier and the user's identity, and the user's identity in the data packet also matches the user's identity in the policy information, then the network device performs access control processing on the data packet based on that policy information. In this case, the network device's access control policy that matches the data packet and includes both the group identifier and the user's identity is a privileged policy.
[0150] In other embodiments, the policy information in the access control policy includes a group identifier and a user identity identifier indicating the source of the data packet, and a mapping between them and the data packet processing operation. The user identity identifier in the access control policy can include a normal state and a vague state. The vague state indicates the state when the policy information does not contain a specific user identity identifier. Access control policies include general policies and privileged policies. General policies include a group identifier, a vague user identity identifier, and a mapping between them and the packet processing operation. Privileged policies include a group identifier, a normal user identity identifier, and a mapping between them and the packet processing operation.
[0151] In one possible design, when the user identifier in the policy information is empty, the user identifier in the policy information is in an ambiguous state. For example, a preset special symbol can be used to represent an empty user identifier. For example, " / " can be used. In another possible design, the ambiguous user identifier in the policy information can also use a preset character identifier. For example, "*", " / ", "-", etc. For example, when the user identifier in the policy information is represented by "*", the storage location corresponding to the user identifier can be understood as an irrelevant state. For example, an irrelevant state indicates that the storage location of the user identifier is "*". For example, the user identifier in the policy information is represented as "*****". This application does not limit the specific implementation form of the ambiguous user identifier in the policy information.
[0152] In one possible implementation, the network device determines the group identifier corresponding to the data packet based on a mapping relationship. When the access control policy contains policy information that matches the group identifier corresponding to the data packet, and the user identity identifier in the policy information is fuzzy, the network device processes the data packet according to that policy information. In this case, the matched policy information is a general policy.
[0153] In one possible design, when there is policy information in the access control policy that matches the group identifier corresponding to the data packet, and the user identity identifier in the policy information is ambiguous, the system no longer matches whether the user identity identifier corresponding to the data packet matches the policy information, and directly processes the data packet according to the policy information.
[0154] In another possible design, the fuzzy user identifier in the access control policy corresponds to any user identifier in the data packet. When there is policy information in the access control policy that matches the group identifier corresponding to the data packet, and the user identifier in the policy information is fuzzy, the network device determines that the fuzzy user identifier matches the user identifier corresponding to the data packet, and thus processes the data packet according to the policy information.
[0155] For example, the access control policy includes a policy that restricts the download speed of all users within group ID 201 to 10 Mbps. In this policy information, the user identifier within the policy information containing group ID 201 is ambiguous. When a network device receives a data packet requesting to download resources from group ID 201, it determines, based on the mapping relationship, that the policy information matching group ID 201 does not include the user identifier. Therefore, the network device performs the corresponding bandwidth limiting processing on data packets sent by all users within group ID 201 according to the policy information matching group ID 201.
[0156] In one possible design, when performing policy matching, the network device can combine the network address corresponding to the data packet with the user's identity identifier in the form of a group key to query the access control policy for policy information that matches that key. For example, see... Figure 10 Access control policies are stored in the TCAM. Network devices query the TCAM using a key to find policy information that matches the user identity identifier corresponding to the data packet. Furthermore, the bit-masking feature of the TCAM is used to achieve a fuzzy representation of the user identity identifier in the access control policy, thereby enabling policy information matching. In this embodiment, the access control policy is not limited to being stored in the TCAM; other memories with similar characteristics capable of representing fuzzy user identity identifiers can also be used.
[0157] For example, group keys can use special characters to concatenate network addresses and user identifiers, such as network address:user identifier; or network address-user identifier; or they can use JSON or other structured data formats, such as {"user_only": "12345", "dest_ip": "10.1.1.0 / 24"}, etc. Here, user_only represents the user identifier, and dest_ip represents the destination address.
[0158] Each entry in the TCAM represents a policy information entry. Network devices can leverage TCAM's ability to query policy information using group keys to quickly match policy information. Specifically, when a network device receives a data packet, it combines the group identifier and user identity identifier corresponding to the data packet into a key, and then compares this key with all entries in the TCAM. If a matching entry is found, the processing operation for that entry is executed.
[0159] Specifically, each storage location of TCAM has three states: 0, 1, and "*" (representing an irrelevant state, a masked user identifier, and an ambiguous user identifier). The "*" can match either 0 or 1. See the example below. Figure 11 The value "1000" can match four entries in TCAM: "1000", "10*0", "*000", and "****". Therefore, based on TCAM's fuzzy matching capability, in this embodiment, when the user identifier in the access control policy stored in TCAM is represented by "*", this fuzzy user identifier can match any user identifier corresponding to the data packet, thus providing a more flexible matching method. When multiple entries match the key corresponding to the data packet, the matching result can also be determined according to priority.
[0160] For example, see Figure 10The access control policies stored in TCAM include four policy information entries. After receiving a data packet, the network device determines the user identity identifier 10001 and group identifier 201 corresponding to the network address of the data packet based on the mapping relationship. The network device matches each policy information entry of the access control policy with a key. When the key includes group identifier 201 and user identity identifier 10001, and the access control policy contains policy information 5 that matches group identifier 201 and includes a normal user identity identifier 10001 that matches user identity identifier 10001, then the network device processes the data packet according to policy information 5, allowing the communication device that sent the data packet to access the 10.1.1.0 / 24 address, and allowing the user with user identity identifier 10001 within group identifier 201 to access the 10.1.1.0 / 24 address. Meanwhile, if the access control policy contains policy information 6 and policy information 7 that match group identifier 201, and the user identity identifier in the policy information is an ambiguous state "*****" (which can be understood as a masked user identity identifier), the network device processes the data packet according to policy information 6, allowing the communication device sending the data packet to access the 10.1.2.0 / 24 address and allowing all users within group identifier 201 to access the 10.1.2.0 / 24 address; and processes the data packet according to policy information 7, denying the communication device sending the data packet access to the 10.1.1.0 / 24 address and denying all users within group identifier 201 access to the 10.1.1.0 / 24 address.
[0161] After determining the user identity and group identity corresponding to the data packet, the network device uses the user identity and group identity to form a key and matches it in the access control policy. This enables the device to quickly perform policy lookup based on the user identity in the case of groups, quickly match the policy of the corresponding user, and improve matching efficiency.
[0162] In another possible implementation, the network device determines the group identifier and user identity identifier corresponding to the data packet based on the mapping relationship. When the access control policy contains policy information that matches the group identifier corresponding to the data packet, and the user identity identifier in that policy information is in a normal state, and the user identity identifier corresponding to the data packet matches the normal state user identity identifier in that policy information, the data packet is processed according to that policy information. In this case, the matched policy information is a privileged policy.
[0163] In this context, "normal state" refers to the state when the access control policy contains a clearly defined user identifier. For example, when the state of each storage location corresponding to the user identifier in the access control policy is *, the user identifier is in an ambiguous state; when the state of each storage location corresponding to the user identifier in the access control policy is 0 or 1, the user identifier is in a normal state.
[0164] For example, the access control policy includes limiting the download speed of all users in group ID 201 to 10 Mbps, and limiting the download speed of user A in group ID 201 to 10 Mbps. When the network device receives a data packet requesting to download resources from group ID 201, it determines the user's group ID based on the mapping relationship, and the policy information that matches the group ID includes the user's identity ID. The network device performs corresponding bandwidth limiting processing on the data packets of other users in group ID 201 except for user A according to the matching policy information, while removing the bandwidth limiting processing on the data packets sent by user A in group ID 201.
[0165] In other words, for policy information that includes a normal user identity identifier, both the group identifier and the user identity identifier corresponding to the data packet must match the group identifier and the normal user identity identifier in the policy information (a match is indicated when they match) before the data packet can be processed according to the policy information. If the group identifier corresponding to the data packet matches the group identifier in the policy information, but the user identity identifier corresponding to the data packet does not match the normal user identity identifier in the policy information, then the policy information has not been hit, the data packet does not match the policy information, and the data packet cannot be processed according to the policy information.
[0166] Network devices determine the user identity and group identity corresponding to the source network address in the received data packet through mapping relationships, and query the access control policies to find matching general policies and privileged policies, so that privileged users within the group can have special rights while having general rights within the group.
[0167] For example, see Figure 10 The network device includes personal information of different users, such as user accounts, user group identifiers, user IDs, and user positions. Group identifier 201 includes user A and user B from the R&D department, and group identifier 202 includes user C from the finance department. User A is the department head of group identifier 201. The network device uses user IDs as user identifiers. Based on the group identifiers, the network device matches policy information 3 (third target policy) and policy information 4 (second target policy). Policy information 3 allows user A to have privileged access to the destination address 10.1.1.0 / 24. Policy information 4 allows all users in group identifier 201 (including user A and user B) to access the address 10.1.2.0 / 24. Therefore, all users within group identifier 201 can be matched with policy information 3 and policy information 4.
[0168] Based on this, in the access control method provided in this application embodiment, a network device receives a third data packet from a third communication device. If, based on a mapping relationship, it is determined that the third network address in the third data packet corresponds to a first set of identifiers, and the access control policy contains second policy information matching the first set of identifiers, and the user identity identifier in the second policy information is fuzzy, the third data packet is processed according to the second policy information. Here, the third network address is the network address of the third communication device.
[0169] For example, see Figure 10 The network device receives a third data packet from a third communication device corresponding to user identity identifier 10001. Based on the mapping relationship, the network device determines that the third network address 192.1.1.5 in the third data packet corresponds to the first group identifier 201, and that the access control policy contains policy information 4 (corresponding to the second policy information) that matches the first group identifier 201 and the fuzzy user identity identifier "*****". The network device then processes the third data packet according to the second policy information.
[0170] The access control method provided in this application embodiment further includes processing the third data packet according to the third policy information if the network device determines that the third network address corresponds to the first group identifier and the second user identity identifier based on the mapping relationship, and the access control policy contains third policy information that matches the first group identifier and the second user identity identifier, and the third policy information includes the second user identity identifier in a normal state.
[0171] For example, see Figure 10 When the network device determines, based on the mapping relationship, that the third network address 192.1.1.5 corresponding to the data packet corresponds to the first group identifier 201 and the second user identity identifier 10001, and there is policy information (corresponding to the third policy information) in the access control policy that matches the first group identifier 201 and the normal state second user identity identifier 10001, the third data packet is processed according to the third policy information.
[0172] like Figure 10As shown, user identifier 10001 matches policy information 3 and policy information 4. Policy information 3 allows the user with identifier 10001 and group identifier 201 to access destination address 10.1.1.0 / 24. In this case, user identifier "10001" is in a normal state. Policy information 4 allows the user with group identifier 201 to access destination address 10.1.2.0 / 24. In this case, user identifier "*****" is in an ambiguous state, and all users within group identifier 201 match policy information 4. Therefore, user A's identifier 10001 matches policy information 3 and policy information 4, allowing access to destination addresses 10.1.1.0 / 24 and 10.1.2.0 / 24.
[0173] In addition, such as Figure 10 As shown, the third and fourth communication devices correspond to the same user identity and the same user. The fifth communication device corresponds to a different user identity and a different user than the third communication device. The network devices perform access control processing based on the different user identities.
[0174] Subsequently, if the second user changes the third communication device to a fourth communication device, see [link to relevant documentation]. Figure 12 The corresponding source network address changes from the third network address to the fourth network address. The network device receives the fourth data packet from the fourth communication device. Based on the mapping relationship, and determining that the fourth network address corresponds to the first group of identifiers and the second user identity identifier, it processes the fourth data packet using third policy information that matches the first group of identifiers and the second user identity identifier, and includes the normal state second user identity identifier. The third network address and the fourth network address correspond to the same user identity identifier. The fourth data packet includes the fourth network address, which is the network address of the fourth communication device. Privileged users within the group retain their privileged status after changing communication devices. Determining the user identity identifier and the matching policy through the mapping relationship ensures that the same access control policy applies. When a user changes devices, the network device can determine the existing access control policy information based on the user identity identifier, eliminating the need to configure policy information for the new communication device's network address. This reduces the need to reconfigure policies due to network address changes and lowers the difficulty of policy management. Simultaneously, it allows the same user to maintain the same access permissions on different communication devices, enhancing the flexibility of policy configuration.
[0175] For example, see Figure 10User A changes the third communication device to the fourth communication device, and the corresponding source network address changes from the third network address 192.1.1.5 to the fourth network address 192.1.1.6. User A's identifier is 10001, and the user belongs to group identifier 201. In the access control policy, policy information 3 allows the user with group identifier 201 and user identity identifier 10001 to access the 10.1.1.0 / 24 address; policy information 4 allows all users with group identifier 201 to access the 10.1.2.0 / 24 address; and policy information 5 denies all users with group identifier 201 access to the 10.1.1.0 / 24 address. Based on the mapping relationship, the network device determines that the fourth network address 192.1.1.6 corresponds to the second group identifier 201. Furthermore, if the access control policy contains policy information 3 (third policy information) matching the second group identifier 201 and the normal user identity identifier "10001", and policy information 4 (second target policy) matching the second group identifier 201 and the ambiguous user identity identifier "*****", the network device processes the fourth data packet according to policy information 3 and policy information 4. In other words, regardless of how the network address of a privileged user within the group changes, the network device still processes data packets according to the policy information matched before the change. There is no need to configure new policy information for the changed network address, nor is it necessary to perform cumbersome operations such as policy approval and updates due to adding policies. This saves network device memory space, facilitates policy management, and improves policy maintenance efficiency.
[0176] When a third user sends a fifth data packet to the network device via a fifth communication device, the network device receives the fifth data packet from the fifth communication device. Based on the mapping relationship, and determining that the fifth network address corresponds to the first set of identifiers, the network device processes the fifth data packet according to the second policy information, which matches the first set of identifiers and includes a user identity identifier with an ambiguity. Here, the fifth communication device can be a regular user within the group with a common policy; the third user and the second user correspond to the same set of identifiers; the second user is a privileged user, and the third user is a regular user. By ensuring that regular users (such as the third user) can only enjoy common group rights and cannot enjoy privileges, the network device enhances the security of network access.
[0177] For example, see Figure 10 User B (the third user) sends a fifth data packet to the network device through the fifth communication device. The network device receives the fifth data packet from the fifth communication device, determines that the fifth network address in the fifth data packet corresponds to the first set of identifiers, and processes the fifth data packet according to the policy information 4 (second policy information) that matches the first set of identifiers and the fuzzy user identity identifier.
[0178] Meanwhile, when the fifth network address corresponds to the first set of identifiers and the third user identity identifier, the third user identity identifier does not match the normal state second user identifier in the third policy information, and the network device does not process the fifth data packet according to policy information 3 (third policy information). The fifth data packet includes the fifth network address, which is the network address of the fifth communication device.
[0179] By matching policies using group identifiers and user identity identifiers, non-privileged users within a group can still enjoy the general rights of their group after changing devices, while preventing non-privileged users from gaining special access permissions, thus enhancing network access security. Furthermore, it allows privileged users within the group to obtain special access permissions. By differentiating user identity states (normal and ambiguous states) in the policy, more granular access control is provided, enabling the distinction and implementation of general rights for ordinary users and special rights for privileged users, enhancing the flexibility of policy configuration and improving maintenance efficiency.
[0180] For ease of understanding, the following is in conjunction with the appendix. Figure 13 This paper provides a general overview of the access control method under grouped conditions provided in the embodiments of this application. For example, see [link to relevant documentation]. Figure 13 Within the same group of identifiers, there are two users: a second user and a third user. The second user is a privileged user within the group, while the third user is a regular user. The network device receives a third data packet sent by the third network device of the second user and, based on the mapping relationship, determines the first group identifier corresponding to the third network address in the third data packet. When the access control policy contains second policy information that matches the first group identifier corresponding to the data packet, and the user identity identifier in the policy information is ambiguous, the third data packet is processed according to the second policy information. Simultaneously, if the access control policy contains third policy information that matches both the first group identifier corresponding to the data packet and the normal second user identity identifier, the network device processes the third data packet according to the third policy information. By determining the correspondence between network addresses, group identifiers, and user identity identifiers, privileged users within a group can possess both general and special rights within that group identifier.
[0181] When the second user changes their communication equipment, the network device receives a fourth data packet from the fourth communication device. Based on the mapping relationship, the network device determines that the fourth network address in the fourth data packet corresponds to the first group of identifiers. If the access control policy contains second policy information that matches the first group of identifiers corresponding to the data packet, and the user identity identifier in the policy information is ambiguous, the fourth data packet is processed according to the second policy information. Simultaneously, based on the mapping relationship, if the network device determines that the fourth network address corresponds to the first group of identifiers and the second user identity identifier, it processes the fourth data packet according to the third policy information that matches the first group of identifiers and the normal second user identity identifier. Even if the network address changes, privileged users within the group still retain the general and special rights under their respective group identifiers.
[0182] Similarly, when a network device receives a fifth data packet from a fifth communication device of a third user, it determines a first set of identifiers corresponding to the fifth network address in the fifth data packet based on the mapping relationship. The network device processes the fifth data packet according to second policy information that matches the first set of identifiers and includes an ambiguous user identity identifier. If the fifth network address corresponds to both the first set of identifiers and the third user identity identifier, but the third user identity identifier does not match the normal second user identity identifier in the third policy information, the network device does not process the fifth data packet according to the third policy information. Therefore, the third user can be matched with the same second policy information as the second user (general policy), but cannot be matched with the second user's third policy information (privileged policy).
[0183] Furthermore, when there is no access control policy that matches the network address, the network device discards the data packet and does not process it.
[0184] In other embodiments, the mapping relationship includes the correspondence between different network addresses and user identifiers and group identifiers. Policy information includes the correspondence between group identifiers and user identifiers used to indicate the source of a packet and packet processing operations. The user identifier in the policy information can be normal, ambiguous, or empty. A network device receives a data packet from a communication device. If, based on the mapping relationship, it is determined that the data packet corresponds to a first group identifier, and the access control policy contains second policy information matching the first group identifier, and the user identifier in the second policy information is ambiguous or empty, the network device processes the third data packet according to the second policy information. And / or, if, based on the mapping relationship, it is determined that the data packet corresponds to a first group identifier and a second user identifier, and the access control policy contains third policy information matching the first group identifier and the second user identifier, and the third policy information includes a normal second user identifier, the third data packet is processed according to the third policy information. Thus, the user identifier and group identifier corresponding to the data packet are determined through the mapping relationship, and policy information is matched to the data packet. When the access control policy contains policy information that matches the group identifier corresponding to the data packet, and the user identifier in the policy information is fuzzy or empty, the network device determines that the fuzzy user identifier matches the user identifier corresponding to the data packet, and thus processes the data packet according to the policy information. When the access control policy contains policy information that matches the group identifier corresponding to the data packet, and the normal user identifier in the policy information matches the user identifier corresponding to the data packet, the data packet is processed according to the policy information.
[0185] In the above embodiments, during the process of obtaining the mapping relationship, the network device can first obtain the user identity identifiers of different users, and then generate a mapping relationship based on different network addresses and user identity identifiers. There are multiple ways for the network device to obtain the user identity identifiers.
[0186] In some embodiments, the network device obtains user identification identifiers from the server. The network device establishes a communication connection with the server and obtains the identifiers of different users from the server. For example, the identifiers of different users in the server may be personal information of different users obtained in response to configuration operations (such as user employee number or user identity (ID)). The server may include network resources and is capable of verifying user identity, authorizing users, and billing user behavior, ensuring secure access to network resources. For example, the server may be an AAA server or other servers that support the above functions. This application does not limit the specific form of the server. An AAA server is a service system used for user authentication, authorization, and accounting in a network environment. This system can also manage employee information of an enterprise, including but not limited to employee employee numbers, accounts, passwords, departments, and positions.
[0187] In one possible implementation, when a network device receives a data packet from a communication device, it initiates an authentication request to the server. Authentication methods include, but are not limited to, authentication via username / password. After successful authentication, the server sends a response message to the network device, including but not limited to authorization messages, accounting messages, or other synchronization messages containing user personal information. Accordingly, the network device obtains the user's identity identifier from the response message sent by the server.
[0188] In some embodiments, a network device receives data packets from multiple communication devices and initiates authentication requests for multiple users to a server. After the multiple users are authenticated, the server sends the user identity identifiers corresponding to the multiple users to the network device. Accordingly, the network device receives the user identity identifiers corresponding to the multiple users from the server.
[0189] For example, a network device receives data packets sent by user A and user B. The network device sends an authentication request to a server, which authenticates the data packets based on the personal information of users A and B. After successful authentication, the server sends the user identifiers of user A and user B to the network device. Based on the user identifiers sent by the server, the network device determines that the user identifier corresponding to the network address of user A's data packet is 10001 and the user identifier corresponding to the network address of user B's data packet is 10002. (See [link to relevant documentation]). Figure 9 If the network device has policy information 1 that matches user A's user identity 10001 and policy information 2 that matches user B's user identity 10002, it will deny user A's data packets from passing through, but allow user B's data packets to pass through. Therefore, user A cannot access the destination address 10.1.1.0 / 24, while user B can access the destination address 10.1.1.0 / 24.
[0190] In some embodiments, the network device obtains the personal information of different users from the server, or obtains the identifiers of different users, and then performs access control processing on the data packets received from the communication device. Since the user identifiers are obtained directly locally on the network device, the number of requests to obtain them from the server each time a packet is received is reduced, which speeds up the acquisition of user identifiers and the determination of user identifiers corresponding to network addresses, thereby improving the response speed of access control.
[0191] In one possible implementation, network devices periodically or as needed synchronize the personal information or user identifiers of different users on the server to the local machine, ensuring the real-time updating and accurate synchronization of the personal information or identifiers of different users.
[0192] In other embodiments, after receiving data packets from a communication device, the network device obtains the personal information of different users from the server to generate user identity identifiers for different users, or obtains user identity identifiers for different users from the server.
[0193] After obtaining the user identifiers of different users, network devices generate a mapping relationship between different network addresses and user identifiers. This mapping relationship allows network devices to flexibly respond to changes in user network addresses. Regardless of which communication device a user uses, as long as their user identifier remains unchanged, the network device can accurately determine the corresponding access control policy. The mapping relationship indicates which network address corresponds to which user identifier. For example, the mapping relationship can be seen in Table 1 above or can be represented as follows:
[0194] 192.168.1.10->10001 (User A)
[0195] 192.168.1.20->10002 (User B)
[0196] Furthermore, after obtaining the user identifiers of different users, access control policies can be generated based on these identifiers. According to different access control policies, corresponding QoS policies or operations can be executed on the user's data packets, such as access control, traffic monitoring, or billing, to accurately process the data packets.
[0197] For example, see Figure 14The access control policy contains different access control permissions, allowing user ID 10001 to access destination address 10.1.1.0 / 24, while disallowing user ID 10002 to access destination address 10.1.1.0 / 24. The network device obtains different users' personal information from the server, or obtains different users' personal information in response to configuration operations, and generates different user IDs based on the different users' personal information. The network device configures corresponding access control policies based on the different user IDs, so that upon receiving data packets from users A and B, it determines that the network address 192.1.1.5 of user A's data packet corresponds to user ID 10001, and that there is policy information in the access policy that matches user ID 10001. The data packet is processed according to the processing operation of the matching policy information, thus denying user A access to destination address 10.1.1.0 / 24. Furthermore, the network device determines that the user identity identifier corresponding to the network address 192.1.1.8 of user B's data packet is 10002, and there is policy information in the access policy that matches user identity identifier 10002. The data packet is processed according to the processing operation of the matching policy information, so that user B is allowed to access the destination address 10.1.1.0 / 24.
[0198] For example, in an access control policy, both users B and C are allowed to access network resources, but user B is configured with a higher QoS action. Based on this access control policy, when the network device receives data packets from users B and C, it determines the user identity corresponding to the network address of each data packet. This allows the network device to prioritize user B's data packets over user C's data packets based on the matched policy information.
[0199] For example, in an access control policy, both users D and E use network resources, but their billing policies differ. Based on this access control policy, the network device receives data packets from users D and E and determines the user identifiers corresponding to the network addresses of their data packets. The network device then matches the identifiers of users D and E to their respective billing policies, monitors and records their network usage, such as data traffic and connection duration, to ensure accurate billing of users D and E's network usage.
[0200] In this embodiment, through mapping, the network device can accurately map the source network address in the received data packet to the corresponding user identity identifier, thereby providing access control management at the user level and realizing user-level access control. When a user changes communication devices, because the policy is based on the user identity identifier rather than the communication device's network address, the network device can match the same policy information when receiving data packets sent by different communication devices of the same user. This avoids the problem of needing to configure access control policies for the network address of the new communication device every time it accesses the network, reducing the need to reconfigure policies due to changes in network addresses. This effectively reduces memory space usage, reduces TCAM resource overhead, reduces management workload, and improves enterprise operation and maintenance efficiency.
[0201] When security groups are defined, the mapping relationship includes the correspondence between network addresses, user identifiers, and group identifiers. Network devices use this mapping relationship to determine the user identifier and group identifier corresponding to the network address in the data packet. When a user within the same group changes their communication device, resulting in a change in their network address, the same policy information can still be matched based on the user's group identifier and corresponding user identifier, avoiding the need to reconfigure policies when network addresses change in security group policy configuration.
[0202] Furthermore, configuring policies based on user identities allows for setting policies for individual users, increasing the flexibility of policy configuration. At the same time, the intuitiveness of user identities makes the relationship between policy information and users clearer and easier to understand when viewing policies. Users can directly view policy information based on user management, facilitating policy management and improving policy maintenance efficiency.
[0203] This application also provides a computer-readable storage medium storing computer program code. When the processor executes the computer program code, the electronic device executes the relevant method steps in the above method embodiments.
[0204] This application also provides a computer program product that, when run on a computer, causes the computer to execute the relevant method steps described in the above method embodiments.
[0205] The electronic devices, computer storage media, or computer program products provided in this application are all used to execute the corresponding methods provided above. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods provided above, and will not be repeated here.
[0206] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0207] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0208] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0209] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0210] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, in essence, or the part that contributes, or all or part of the technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0211] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An access control method, characterized in that, Applied to network devices, the method includes: Receive a first data packet from a first communication device, the first data packet including a first network address, the first network address being the network address of the first communication device; If, based on the mapping relationship, it is determined that the first network address corresponds to the first user identity identifier, and the access control policy contains first policy information that matches the first user identity identifier, the first data packet is processed according to the first policy information; wherein, the mapping relationship includes the correspondence between different network addresses and user identity identifiers; the access control policy includes multiple policy information; the policy information includes a user identity identifier used to indicate the source of the packet, and the correspondence between packet processing operations.
2. The method according to claim 1, characterized in that, The method further includes: Receive a second data packet from a second communication device, the second data packet including a second network address, the second network address being the network address of the second communication device; If, based on the mapping relationship, it is determined that the second network address corresponds to the first user identity, the second data packet is processed according to the first policy information in the access control policy that matches the first user identity.
3. The method according to claim 1, characterized in that, The method further includes: The mapping relationship includes the correspondence between different network addresses, user identifiers, and group identifiers; the policy information includes group identifiers and user identifiers used to indicate the source of packets, as well as the correspondence between packet processing operations; the user identifier includes a normal state or an ambiguous state. Receive a third data packet from a third communication device, the third data packet including a third network address, the third network address being the network address of the third communication device; If, based on the mapping relationship, it is determined that the third network address corresponds to the first set of identifiers, and the access control policy contains second policy information matching the first set of identifiers, and the user identity identifier in the second policy information is fuzzy, then the third data packet is processed according to the second policy information; and / or, Based on the mapping relationship, if it is determined that the third network address corresponds to the first group of identifiers and the second user identity identifier, and the access control policy contains third policy information that matches the first group of identifiers and the second user identity identifier, and the third policy information includes the second user identity identifier in a normal state, the third data packet is processed according to the third policy information.
4. The method according to claim 3, characterized in that, The method further includes: Receive a fourth data packet from a fourth communication device, the fourth data packet including a fourth network address, the fourth network address being the network address of the fourth communication device; If, based on the mapping relationship, it is determined that the fourth network address corresponds to the first set of identifiers and the second user identity identifier, the third policy information that matches the first set of identifiers and the second user identity identifier and includes the second user identity identifier in a normal state is used to process the fourth data packet.
5. The method according to claim 3, characterized in that, The method further includes: Receive a fifth data packet from a fifth communication device, the fifth data packet including a fifth network address, the fifth network address being the network address of the fifth communication device; When the fifth network address is determined to correspond to the first set of identifiers based on the mapping relationship, the fifth data packet is processed according to the second policy information that matches the first set of identifiers and includes the fuzzy user identity identifier; when the fifth network address corresponds to the first set of identifiers and the third user identity identifier, the third user identity identifier does not match the normal state second user identifier in the third policy information.
6. The method according to any one of claims 3-5, characterized in that, The user identity identifier is a unique digital identifier for the user; the normal state is a digital state; and the ambiguous state is different from the digital state. Alternatively, the user identity identifier in the fuzzy state is empty.
7. The method according to any one of claims 3-6, characterized in that, The access control policy is stored in a three-state content addresser (TCAM), where each storage location in the TCAM is in a state of 0, 1, or irrelevant. When the state of each storage location corresponding to the user identity in the access control policy is 0 or 1, the user identity is in a normal state. When the state of the storage location corresponding to the user identity in the access control policy includes an irrelevant state, the user identity is in an ambiguous state.
8. The method according to any one of claims 1-7, characterized in that, The method further includes: Obtain personal information of different users from the server, or obtain personal information of different users in response to configuration operations; Generate unique user identifiers based on the individual information of each user; The mapping relationship is generated based on different network addresses and the user identity identifier; and / or, the user's personal information in the initial access control policy is transformed based on the user identity identifier to obtain the access control policy; wherein, the initial access control policy is configured based on the user's personal information.
9. The method according to any one of claims 1-7, characterized in that, The method further includes: Obtain the mapping relationship and the access control policy from the server; or... Obtain user identifiers for different users from the server; generate the mapping relationship between different network addresses and the user identifiers; generate the access control policy based on the user identifiers.
10. The method according to any one of claims 1-7, characterized in that, The network device includes a control plane and a forwarding plane; the method further includes: The control plane obtains the mapping relationship and the access control policy from the server; or, the control plane obtains the user identity identifiers of different users from the server, generates the mapping relationship based on different network addresses and the user identity identifiers, and generates the access control policy based on the user identity identifiers. or, The control plane obtains personal information of different users from the server, or obtains personal information of different users in response to configuration operations; generates user identity identifiers for different users based on their personal information; the control plane generates the mapping relationship between different network addresses and the user identity identifiers; and / or generates the access control policy based on the user identity identifiers. The control plane sends the mapping relationship and the access control policy to the forwarding plane; Alternatively, the control plane generates access control policies based on the personal information of different users, and then sends the mapping relationship and the personal information of the users in the access control policies to the user identity identifier before sending them to the forwarding plane. When, based on the mapping relationship, it is determined that the first network address corresponds to the first user identity, and the access control policy contains first policy information matching the first user identity, the first data packet is processed according to the first policy information, including: When the forwarding plane determines, based on the mapping relationship, that the first network address corresponds to the first user identity identifier, and the access control policy contains first policy information that matches the first user identity identifier, it processes the first data packet according to the first policy information.
11. The method according to any one of claims 1-7, characterized in that, The network device includes a forwarding plane; the method further includes: The forwarding plane obtains the mapping relationship and the access control policy from the server; When, based on the mapping relationship, it is determined that the first network address corresponds to the first user identity, and the access control policy contains first policy information matching the first user identity, the first data packet is processed according to the first policy information, including: When the forwarding plane determines, based on the mapping relationship, that the first network address corresponds to the first user identity identifier, and the access control policy contains first policy information that matches the first user identity identifier, it processes the first data packet according to the first policy information.
12. An electronic device, characterized in that, include: A memory, one or more processors; the memory is coupled to the processors; wherein the memory stores computer program code, the computer program code including computer instructions, which, when executed by the processor, cause the electronic device to perform the access control method as described in any one of claims 1-11.
13. A computer-readable storage medium, characterized in that, Includes computer instructions that, when executed on an electronic device, cause the electronic device to perform the access control method as described in any one of claims 1-11.
14. A computer program product, characterized in that, When the computer program product is run on a computer, the computer performs the access control method as described in any one of claims 1-11.