Network application access method and related device
By using virtual IP address technology in the security protection system, the virtual IP address of the terminal is encapsulated into the application layer message header of the packet and replaced it with the source IP address field of the IP basic header, the problem of difficulty in realizing user traceability in the existing technology is solved, and the convenience of user traceability and security of intranet IP addresses are realized.
Patent Information
- Application Number
- PCT/CN2024/100000
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-31
- Filing Date
- 2024-06-19
- Publication Date
- 2025-05-08
AI Technical Summary
The prior art is difficult to realize user traceability based on message source IP, especially in remote access scenarios, where the real IP address of the terminal changes dynamically, resulting in difficulty in traceability.
By introducing a virtual IP address in the security protection system, the terminal obtains the virtual IP address corresponding to the user ID when logging in, encapsulates the virtual IP address into the application layer message header of the message, and transmits it to the security protection system. The latter replaces the virtual IP address to the source IP address field in the IP basic header of the message, and transmits it to the server.
It realizes strong binding of the message source IP to the user, reducing the difficulty of traceability of the message source IP to the user based on the message source IP, and hiding the intranet IP address through the virtual IP address, reducing the security risk of IP attacks.
Smart Images

Figure CN2024100000_08052025_PF_FP_ABST
Abstract
Description
Network application access method and related equipment
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on October 31, 2023, with application number 202311438238.8 and invention name “Access method and related equipment for network applications”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of network security, and in particular to a method for accessing network applications and related equipment. Background Art
[0003] With the development of network technology, terminals deployed in one network (such as the extranet) can access network applications provided by servers deployed in another network (such as the intranet) through remote access technology. When remote access is achieved through a secure socket layer virtual private network (SSL VPN), the terminal usually needs to install a virtual network card. A virtual network card is a type of driver software. The virtual network card is used to select an idle intranet IP address from the intranet Internet Protocol (IP) address pool and configure the intranet IP address to the terminal. The terminal uses the configured intranet IP address as the source IP address to access network applications.
[0004] However, it is difficult to achieve traceability when using the above method, and it is difficult to trace the user who initiated the access through the content of the message.
[0005] Summary of the Invention
[0006] The present invention provides a method and related devices for accessing network applications, which help reduce the difficulty of tracing the source IP address of a message to the user. The technical solution is as follows.
[0007] In a first aspect, a method for accessing a network application is provided, which is applied to a network system. The network system includes a terminal, a security protection system, and a server that provides the network application. The terminal is deployed in a first network, and the server is deployed in a second network. The security protection system is used to protect the security of the server. The method includes: the security protection system receives a first message from the terminal, the first message includes an application layer message header, the application layer message header in the first message carries a first virtual IP address corresponding to a user identifier, the user identifier is the identifier of a user logged in on the terminal, and the first virtual IP address is an IP address in the second network; the security protection system obtains a second message based on the first message, the second message includes an IP basic header, and the source IP address field in the IP basic header in the second message carries the first virtual IP address; the security protection system sends the second message to the server.
[0008] Since the application layer message header of the message initiated by the terminal carries the first virtual IP address corresponding to the user ID logged in on the terminal, and the source IP address field in the IP basic header of the message sent by the security protection system to the server based on the message carries the first virtual IP address, the first virtual IP address carried by the source IP address of the message sent to the server by the security protection system can locate the corresponding user ID, which is equivalent to strongly binding the source IP of the message from the network server to the user, thereby reducing the difficulty of tracing the source to the user based on the source IP of the message.
[0009] In addition, since the virtual IP address serving as the source IP address belongs to the IP address of the second network where the server is located, when it is necessary to forward the return message from the server, only one return route needs to be configured for each user's virtual IP address. For example, the destination IP address of the return route is the IP address segment of the protection network including the virtual IP address, and the next hop of the return route is the IP address of the security protection system. It is no longer necessary to configure the return route separately for the real IP address of each terminal, thereby reducing the complexity of configuring the return route and reducing the network overhead of publishing the return route.
[0010] In some embodiments, the first message also includes an IP basic header encapsulated in the outer layer of the application layer message header, and the security protection system obtains the second message based on the first message, including: the security protection system uses the first virtual IP address to replace the content of the source IP address field in the IP basic header in the first message to obtain the second message.
[0011] Since the security protection system performs the action of replacing the source IP, it is equivalent to that when the message is forwarded through the security protection system, the source IP address of the message can be changed from the IP address of the first network to the IP address of the second network. In this way, during the transmission of the message in the first network, the source IP address of the IP basic header does not need to carry the IP address in the second network, so that the device in the first network cannot perceive the IP address in the second network based only on the source IP address carried in the IP basic header. This is equivalent to hiding the digital assets (IP address) of the second network, thereby reducing the security risks caused by IP attacks.
[0012] In some embodiments, the first message belongs to a first session, which is a session established between a terminal and a security protection system. The security protection system obtains a second message based on the first message, including: the security protection system uses the first virtual IP address to replace the content of the source IP address field in the IP basic header in subsequent messages of the first message in the first session to obtain the second message.
[0013] In some embodiments, before the security protection system receives the first message from the terminal, the method also includes: the security protection system receives an authentication request message from the terminal, the authentication request message includes a user identifier; the security protection system authenticates the terminal based on the authentication request message; in response to the terminal passing the authentication, the security protection system obtains a first virtual IP address based on the user identifier; during the authorization process of the terminal, the security protection system sends the first virtual IP address to the terminal.
[0014] Since the virtual IP address is issued to the terminal based on the authentication result, the terminal's authentication is used as a prerequisite for issuing the virtual IP address, which improves the credibility of the IP address to a certain extent. Terminals that have not passed identity authentication cannot use the virtual IP address to access network applications, reducing the risk of attacks launched by forged source IP addresses and improving the security of intranet applications.
[0015] In addition, because the security protection system performs virtual IP address allocation without the need for terminals to perform virtual IP address allocation, the risk of leaking internal network addresses is reduced, and the risk of attackers sniffing the virtual network card through the physical network card to steal data and deduce the network architecture or new vulnerabilities in the network card program are reduced, thereby reducing the risk of being attacked and affecting the security of the entire organization.
[0016] In some embodiments, the security protection system obtains the first virtual IP address based on the user identifier, including: the security protection system searches for a target correspondence based on the user identifier to obtain the first virtual IP address, where the target correspondence includes the user identifier and the first virtual IP address.
[0017] The above implementation method facilitates the unified management and planning of the corresponding relationship between user identifiers and virtual IP addresses by the security protection system.
[0018] In some embodiments, the security protection system obtains the first virtual IP address based on the user identifier, including: the security protection system sends the user identifier to a third-party authentication system; the security protection system receives the first virtual IP address from the third-party authentication system.
[0019] Since the correspondence between the user ID and the virtual IP address is saved by a third-party authentication system, there is no need for the security protection system to save the correspondence between the user ID and the virtual IP address, thereby saving the storage resources occupied by the correspondence between the user ID and the virtual IP address in the security protection system.
[0020] In some embodiments, the security protection system sends a first virtual IP address to the terminal, including: the security protection system sends the first virtual IP address and a list of resources that the security protection system authorizes the user to access to the terminal, the resource list including an identifier of the network application, an identifier of a server corresponding to the identifier of the network application, an IP address of a software defined perimeter (SDP) gateway, and a port number of the SDP gateway, and the terminal can access the network application based on the IP address of the SDP gateway and the port number of the SDP gateway.
[0021] Since the first virtual IP address and the resource list are sent to the terminal together, it is equivalent to sending two types of resources to the terminal at the same time through one authorization process. One type of resource is the virtual IP address of the access subject (terminal), and the other type of resource is the identifier of the access object (network application and SDP gateway), thereby improving the overall efficiency of the authorization process.
[0022] In some embodiments, the authentication request message includes a hypertext transfer protocol (HTTP) request message, and the security protection system sends a first virtual IP address and a list of resources that the security protection system authorizes the user to access to the terminal, including: the security protection system sends an HTTP response message corresponding to the HTTP request message to the terminal, and the response body in the HTTP response message carries the first virtual IP address and the resource list.
[0023] Since the security protection system encapsulates the first virtual IP address and the resource list into the same message, the terminal can obtain both the first virtual IP address and the resource list from the received message, thereby improving the overall efficiency of obtaining the first virtual IP address and the resource list.
[0024] In some embodiments, the first message is a hypertext transfer protocol connect (HTTP connect) message, the application layer message header is an HTTP header, the HTTP header includes an X-Forwarded-For (XFF) field, and the first virtual IP address is carried in the X-Forwarded-For field.
[0025] By using the XFF field to carry the virtual IP address of the terminal, for example, using the XFF field to carry the virtual IP address of the SDP client, the function of the XFF field matches the definition of the XFF field in the standard. Any network device (such as an SDP gateway) between the client and the server can know that the content of the XFF field includes the client's IP address based on the field name of the XFF field, so that the solution can reuse the message format of the HTTP header provided in the existing standard, which is more compatible with the standard and reduces the implementation complexity.
[0026] In some embodiments, the first message also includes an IP basic header encapsulated in the outer layer of the application layer message header, and the source IP address field in the IP basic header in the first message carries the IP address of the terminal. After the security protection system receives the first message from the terminal, the method also includes: the security protection system saves the session relationship, and the session relationship includes the IP address of the terminal and the first virtual IP address.
[0027] Since the session relationship is saved, when the security protection system receives a return message from the server, the security protection system searches for the session relationship based on the virtual IP address carried in the return message, and can obtain the IP address of the terminal, thereby forwarding the return message to the terminal based on the IP address of the terminal, thereby reducing the risk of being unable to route to the terminal when forwarding the return message because the destination IP address in the return message is a virtual IP address.
[0028] In addition, when the security protection system receives subsequent messages from the terminal, the security protection system searches for the session relationship based on the IP address of the terminal carried in the subsequent messages, and can obtain the virtual IP address, thereby replacing the source IP address in the subsequent messages based on the virtual IP address, and forwarding the subsequent messages with the source IP address replaced with the virtual IP address to the server, so that there is no need to require subsequent messages initiated by the terminal to carry the virtual IP address, which helps to save message transmission overhead.
[0029] In some embodiments, after the security protection system sends the second message to the server, the method also includes: the security protection system receives a third message from the server, the third message includes an IP basic header, and the destination IP address field in the IP basic header in the third message carries the first virtual IP address; the security protection system searches for the session relationship based on the first virtual IP address to obtain the IP address of the terminal; the security protection system obtains a fourth message based on the IP address of the terminal and the third message, the fourth message includes an IP basic header, and the destination IP address field in the IP basic header in the fourth message carries the IP address of the terminal; the security protection system sends the fourth message to the terminal.
[0030] Because the source IP address of the uplink data message is replaced by the first virtual IP address by the security protection system, the server will return a return message with the first virtual IP address as the destination IP address. The security protection system replaces the destination IP address in the return message from the first virtual IP address to the terminal's IP address so that the message can be forwarded to the terminal based on the terminal's IP address, reducing the risk of message transmission interruption due to the first virtual IP address being unreachable on the Internet.
[0031] In some implementations, the terminal includes an SDP client, and the security protection system includes an SDP controller and an SDP gateway operating in an access proxy mode.
[0032] In some implementations, the network system further includes an audit and tracing system. After the security protection system sends the second message to the server, the method further includes: the audit and tracing system determining a user identifier based on the first virtual IP address.
[0033] In the second aspect, a method for accessing a network application is provided, which is applied to a network system. The network system includes a terminal, a security protection system, and a server that provides the network application. The terminal is deployed in a first network, and the server is deployed in a second network. The security protection system is used to protect the security of the server. The method includes: the terminal sends an authentication request message to the security protection system, and the authentication request message includes a user identifier, which is the identifier of the user logged in to the terminal; in the process of authorizing the terminal, the terminal receives a first virtual IP address corresponding to the user identifier from the security protection system, and the first virtual IP address is an IP address in the second network; the terminal generates a first message based on the first virtual IP address, and the first message includes an application layer message header, and the application layer message header in the first message carries the first virtual IP address; the terminal sends the first message to the security protection system.
[0034] The terminal initiates authentication to obtain a virtual IP address corresponding to the user ID. During the process of accessing the network application, the terminal carries the virtual IP address issued during the authorization process in the application layer message header and sends it to the security protection system, so that the security protection system can obtain the first virtual IP address from the application layer message header, and then encapsulate the first virtual IP address into the source IP address field and send it to the server. Since the source IP of the message sent by the security protection system to the server corresponds to the user ID of the terminal login, it is equivalent to strongly binding the source IP of the message to the user, thereby reducing the difficulty of tracing the source to the user based on the source IP of the message.
[0035] In some implementations, the first message is an HTTP connect message, the application layer message header is an HTTP header, the HTTP header includes an X-Forwarded-For field, and the first virtual IP address is carried in the X-Forwarded-For field.
[0036] In some embodiments, the security protection system includes an SDP gateway running based on an access proxy mode, and the terminal receives a first virtual IP address from the security protection system, including: the terminal receives the first virtual IP address from the security protection system and a list of resources that the security protection system authorizes the user to access, the resource list including an identifier of the network application, an identifier of a server corresponding to the identifier of the network application, an IP address of the SDP gateway, and a port number of the SDP gateway, and the terminal can access the network application based on the IP address of the SDP gateway and the port number of the SDP gateway; accordingly, the terminal generates a first message based on the first virtual IP address, including: the terminal generates a first message based on the first virtual IP address A first message is generated by combining the simulated IP address, proxy gateway list and resource list. The first message also includes an IP basic header and a transport layer protocol header. The destination address field of the IP basic header in the first message includes the IP address of the SDP gateway. The destination port number field of the transport layer protocol header in the first message includes the port number of the SDP gateway. The application layer message header in the first message also carries the identifier of the network application and the identifier of the server. The IP basic header is encapsulated in the outer layer of the transport layer protocol header and the application layer message header, and the transport layer protocol header is encapsulated in the outer layer of the application layer message header. The terminal sends the first message to the security protection system, including: the terminal sends the first message to the SDP gateway.
[0037] In some embodiments, the authentication request message includes an HTTP request message, and the terminal receives from the security protection system a first virtual IP address, a list of resources that the security protection system authorizes the user to access, and a list of proxy gateways that the security protection system authorizes the user to access, including:
[0038] The terminal receives an HTTP response message corresponding to the HTTP request message from the security protection system, where the response body in the HTTP response message carries the first virtual IP address, the resource list, and the proxy gateway list.
[0039] In a third aspect, a security protection system is provided, which is provided in a network system. The network system includes a terminal, a security protection system, and a server that provides network applications. The terminal is deployed in a first network, and the server is deployed in a second network. The security protection system is used to protect the security of the server. The security protection system includes:
[0040] a receiving unit, configured to receive a first message from a terminal, the first message including an application layer message header, the application layer message header in the first message carrying a first virtual IP address corresponding to a user identifier, the user identifier being an identifier of a user logged in on the terminal, and the first virtual IP address being an IP address in the second network;
[0041] a processing unit, configured to obtain a second message based on the first message, where the second message includes an IP basic header, and a source IP address field in the IP basic header in the second message carries the first virtual IP address;
[0042] A sending unit is used to send a second message to the server.
[0043] In some embodiments, the first message further includes an IP basic header encapsulated in an outer layer of the application layer message header, and the processing unit is configured to replace the content of the source IP address field in the IP basic header in the first message with the first virtual IP address to obtain the second message; or,
[0044] The first message belongs to a first session, which is a session established between the terminal and the security protection system. The processing unit is used to use the first virtual IP address to replace the content of the source IP address field in the IP basic header in the subsequent message of the first message in the first session to obtain a second message.
[0045] In some embodiments, the receiving unit is further configured to receive an authentication request message from the terminal, the authentication request message including a user identifier;
[0046] The processing unit is further configured to authenticate the terminal based on the authentication request message;
[0047] The processing unit is further configured to obtain a first virtual IP address based on the user identifier in response to the terminal passing the authentication;
[0048] The sending unit is further configured to send the first virtual IP address to the terminal during the authorization process of the terminal.
[0049] In some implementations, the processing unit is configured to search for a target correspondence based on the user identifier to obtain the first virtual IP address, where the target correspondence includes the user identifier and the first virtual IP address.
[0050] In some embodiments, the sending unit is further configured to send the user identification to a third-party authentication system;
[0051] The receiving unit is further configured to receive a first virtual IP address from a third-party authentication system.
[0052] In some embodiments, the sending unit is used to send a first virtual IP address and a list of resources authorized for the user to access by the security protection system to the terminal, the resource list including an identifier of the network application, an identifier of a server corresponding to the identifier of the network application, an IP address of the SDP gateway, and a port number of the SDP gateway. The terminal can access the network application based on the IP address of the SDP gateway and the port number of the SDP gateway.
[0053] In some implementations, the authentication request message includes an HTTP request message, and the sending unit is configured to send an HTTP response message corresponding to the HTTP request message to the terminal, wherein the response body in the HTTP response message carries the first virtual IP address and the resource list.
[0054] In some implementations, the first message is an HTTP connect message, the application layer message header is an HTTP header, the HTTP header includes an X-Forwarded-For field, and the first virtual IP address is carried in the X-Forwarded-For field.
[0055] In some embodiments, the first message further includes an IP basic header encapsulated in an outer layer of the application layer message header, and the source IP address field in the IP basic header in the first message carries the IP address of the terminal. After the security protection system receives the first message from the terminal, the security protection system further includes:
[0056] The storage unit is used to store the session relationship, where the session relationship includes the IP address of the terminal and the first virtual IP address.
[0057] In some embodiments, the receiving unit is further configured to receive a third message from the server, the third message including an IP basic header, the destination IP address field in the IP basic header in the third message carrying the first virtual IP address;
[0058] The processing unit is further configured to search for a session relationship based on the first virtual IP address to obtain an IP address of the terminal; obtain a fourth message based on the IP address of the terminal and the third message, the fourth message including an IP basic header, wherein a destination IP address field in the IP basic header of the fourth message carries the IP address of the terminal;
[0059] The sending unit is further configured to send a fourth message to the terminal.
[0060] In some implementations, the terminal includes an SDP client, and the security protection system includes an SDP controller and an SDP gateway operating in an access proxy mode.
[0061] In a fourth aspect, a terminal is provided, which is provided in a network system. The network system includes a terminal, a security protection system, and a server that provides network applications. The terminal is deployed in a first network, and the server is deployed in a second network. The security protection system is used to protect the security of the server. The terminal includes:
[0062] A sending unit, configured to send an authentication request message to the security protection system, wherein the authentication request message includes a user identifier, which is an identifier of a user who logs in on the terminal;
[0063] A receiving unit, configured to receive a first virtual IP address corresponding to a user identifier from a security protection system during authorization of a terminal, wherein the first virtual IP address is an IP address in a second network;
[0064] a processing unit, configured to generate a first message based on the first virtual IP address, the first message including an application layer message header, the application layer message header in the first message carrying the first virtual IP address;
[0065] The sending unit is further used to send a first message to the security protection system.
[0066] In some implementations, the first message is an HTTP connect message, the application layer message header is an HTTP header, the HTTP header includes an X-Forwarded-For field, and the first virtual IP address is carried in the X-Forwarded-For field.
[0067] In some embodiments, the security protection system includes an SDP gateway operating in an access proxy mode, a receiving unit configured to receive a first virtual IP address from the security protection system and a list of resources that the security protection system authorizes the user to access, the resource list including an identifier of a network application, an identifier of a server corresponding to the identifier of the network application, an IP address of the SDP gateway, and a port number of the SDP gateway, wherein the terminal can access the network application based on the IP address and the port number of the SDP gateway;
[0068] Accordingly, the processing unit is configured to generate a first message based on the first virtual IP address, the proxy gateway list, and the resource list, the first message further comprising an IP basic header and a transport layer protocol header, the destination address field of the IP basic header in the first message comprising the IP address of the SDP gateway, the destination port number field of the transport layer protocol header in the first message comprising the port number of the SDP gateway, the application layer message header in the first message further carrying an identifier of the network application and an identifier of the server, the IP basic header being encapsulated in an outer layer of the transport layer protocol header and the application layer message header, and the transport layer protocol header being encapsulated in an outer layer of the application layer message header;
[0069] The sending unit is configured to send a first message to the SDP gateway.
[0070] In some embodiments, the authentication request message includes an HTTP request message, and the receiving unit is used to receive an HTTP response message corresponding to the HTTP request message from the security protection system, and the response body in the HTTP response message carries the first virtual IP address, resource list and proxy gateway list.
[0071] In the fifth aspect, a security protection system is provided, which includes: a processor, the processor is coupled to a memory, the memory stores at least one computer program instruction, and the at least one computer program instruction is loaded and executed by the processor to enable the security protection system to implement the method provided by the above-mentioned first aspect or any optional method of the first aspect.
[0072] In the sixth aspect, a terminal is provided, the terminal including: a processor, the processor being coupled to a memory, the memory storing at least one computer program instruction, and the at least one computer program instruction being loaded and executed by the processor so that the terminal implements the method provided by the above-mentioned second aspect or any optional method of the second aspect.
[0073] In a seventh aspect, a computer-readable storage medium is provided, which stores at least one instruction. When the instruction is executed on a computer, the computer executes the method provided by the first aspect or any optional method of the first aspect.
[0074] In an eighth aspect, a computer-readable storage medium is provided, which stores at least one instruction. When the instruction is executed on a computer, the computer executes the method provided by the second aspect or any optional method of the second aspect.
[0075] In the ninth aspect, a computer program product is provided, which includes one or more computer program instructions. When the computer program instructions are loaded and executed by a computer, the computer executes the method provided by the first aspect or any optional method of the first aspect.
[0076] In the tenth aspect, a computer program product is provided, which includes one or more computer program instructions. When the computer program instructions are loaded and run by a computer, the computer executes the method provided by the second aspect or any optional method of the second aspect.
[0077] In the eleventh aspect, a chip is provided, comprising a memory and a processor, wherein the memory is used to store computer instructions, and the processor is used to call and run the computer instructions from the memory to execute the method in the above-mentioned first aspect and any possible implementation of the first aspect.
[0078] In the twelfth aspect, a chip is provided, comprising a memory and a processor, wherein the memory is used to store computer instructions, and the processor is used to call and run the computer instructions from the memory to execute the method provided in the above-mentioned second aspect or any optional method of the second aspect.
[0079] In the thirteenth aspect, a network system is provided, which includes the security protection system of the third aspect or any optional method of the third aspect and the terminal of the fourth aspect or any optional method of the fourth aspect.
[0080] In the fourteenth aspect, a network system is provided, which includes the security protection system of the fifth aspect or any optional method of the fifth aspect and the terminal of the sixth aspect or any optional method of the sixth aspect.
[0081] Based on the implementation methods provided in the above aspects, this application can also be further combined to provide more implementation methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0082] FIG1 is a schematic diagram of the architecture of a network system provided in an embodiment of the present application;
[0083] FIG2 is a flow chart of a method for accessing a network application provided in an embodiment of the present application;
[0084] FIG3 is a schematic diagram of accessing a network application in an SDP zero-trust scenario provided by an embodiment of the present application;
[0085] FIG4 is a schematic structural diagram of an SDP gateway provided in an embodiment of the present application;
[0086] FIG5 is a schematic diagram of accessing a network application in an SDP zero-trust scenario provided by an embodiment of the present application;
[0087] FIG6 is a schematic structural diagram of a safety protection system provided in an embodiment of the present application;
[0088] FIG7 is a schematic structural diagram of a terminal provided in an embodiment of the present application;
[0089] FIG8 is a schematic structural diagram of a safety protection system provided in an embodiment of the present application;
[0090] FIG9 is a schematic structural diagram of a terminal provided in an embodiment of the present application. DETAILED DESCRIPTION
[0091] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0092] The following is an explanation of some terminology concepts involved in the embodiments of this application.
[0093] (1) First network and second network
[0094] Some embodiments of the present application are applied to scenarios where data communication is performed across networks, for example, scenarios where source IP address conversion is performed when transmitting messages between two networks. In order to distinguish and describe different networks, "first network" is used below to describe the network where the terminal is located, and "second network" is used to describe the network where the server is located. The first network is, for example, an untrusted network. In one example, the first network is the Internet, a mobile communication data network, a public wireless local area network (WLAN) network, or a local area network (such as a home intranet). The second network is, for example, a trusted network. For example, the second network is a local area network. The local area network is also called a private network or an intranet. In one example, the second network is an enterprise intranet or a school intranet. This embodiment focuses on the scenario where the server is in an intranet as an example for explanation.
[0095] (2) Real IP address and virtual IP address
[0096] A real IP address is also called a physical IP address. A real IP address refers to an IP address that is directly bound to the hardware that supports communication in a device (such as a physical network card or network interface). For example, a real IP address is the IP address configured by the network interface of a device. For example, when the destination IP address of a message carries the real IP address of a device, the message can be forwarded to the network interface bound to the real IP address on the device through IP routing based on the real IP address, and enter the device from the network interface. A virtual IP address is a concept relative to a real IP address. A virtual IP address refers to an IP address that is not directly bound to hardware. For example, a virtual IP address is created and managed by the management plane of the network (such as a controller, such as an SDP controller). A real IP address can be routed within a wide area network, while a virtual IP address can be routed within a controlled network. For example, in an embodiment of the present application, a virtual IP address can only be routed within the protection network where the SDP gateway is located.
[0097] (3) User ID
[0098] In the embodiments of the present application, the form of the user identification is, for example, any data that can identify the user and can be processed by a computer. The user identification can also be referred to as an identity credential, which is used to prove the user's identity. For example, the user identification includes an account number and / or a password. An account number is, for example, a user name, an email address, an ID number, a work number, or the name of the department to which the user belongs. In another example, the user identification includes a biometric feature of the user. The biometric feature includes at least one of a facial image, a feature vector of a facial image, a fingerprint feature, or a voiceprint feature. In another example, the user identification includes a text message (such as a verification code). In another example, the user identification includes a certificate (public key). In another example, the user identification includes a text message (such as a verification code). In another example, the user identification includes a device identification of a terminal used by the user. The device identification of the terminal is, for example, a unique terminal identification. The device identification of the terminal includes the terminal's media access control (MAC) address, the terminal's IP address, the terminal's international mobile subscriber identity (IMSI), the terminal's mobile station international ISDN number (MSISDN), or the terminal's international mobile equipment identity (IMEI). The terminal's device ID uniquely identifies the terminal. It's generated based on the terminal's hardware parameters. For example, the terminal uses the serial number of the terminal's main hard drive, the MAC address of the network card, and / or the serial number of the central processing unit (CPU) as the primary key information. This information is then combined with the current timestamp and a hash value generated from a random number to generate the terminal's device ID.
[0099] (4) Outbound and return trips
[0100] In this embodiment, outbound and return refer to two data transmission directions. Outbound refers to the transmission direction with the terminal as the source and the server as the destination, while return refers to the transmission direction with the terminal as the destination and the server as the source. For example, an outbound message refers to a message sent from the terminal to the server, and a return message refers to a message sent from the server to the terminal. Outbound messages are also called uplink messages. Return messages are also called downlink messages. The outbound route is the routing table entry whose destination IP address is the IP address of the server. The return route is the routing table entry whose destination IP address is the IP address of the terminal.
[0101] (5) Network applications
[0102] Network applications are also called network resources. Network applications refer to applications that terminals need to access remotely through the network. Network applications are provided by, for example, a server or a server cluster. When a terminal accesses a network application, it needs to interact with the server. For example, when a user triggers an operation on a network application, the terminal sends an access request to the server in response to the user's operation. The server processes the access request and returns a response result to the terminal. For example, network applications are applications based on a client / server (C / S) architecture or applications based on a browser / server (B / S). As examples, network applications include world wide web (web) applications, email applications, file storage and sharing applications, remote desktop applications, or instant messaging applications.
[0103] (6) Terminal
[0104] A terminal refers to a hardware device that supports human-computer interaction. Terminal types include, but are not limited to, mobile phones, tablets, laptops, desktop computers, automobiles, vehicle-mounted terminals, wearable devices, and handheld game consoles. A terminal is also referred to as user equipment (UE), smart terminal, mobile terminal, user device, or terminal equipment. In this embodiment, the terminal primarily serves as an access subject and is deployed on the first network.
[0105] (7) Safety protection system
[0106] The security protection system is used to protect the security of servers that provide network applications. Optionally, the security protection system includes multiple devices working together. Alternatively, the security protection system can be a single device. For example, the security protection system is a network device. In some embodiments, the security protection system includes a network device and a controller.
[0107] The network device mainly acts as an intermediary between the terminal and the server. The network device is used to forward messages between the terminal and the server. The network device can also be called a forwarding device or a communication device. The network device is deployed between the first network and the second network. For example, the network device is deployed at the boundary of the second network. For example, the network device is the entry node of the second network device. The network device includes but is not limited to firewalls, security gateways (such as routers or switches), intrusion detection system (IDS) type devices, intrusion prevention system (IPS) type devices, unified threat management (UTM) devices, anti-virus (AV) devices, anti-distributed denial-of-service attack (DDoS) devices, and next-generation firewalls (NGFW) integrated with one or more of them.
[0108] The controller is used to authenticate the terminal and authorize the terminal based on the authentication results. The controller may also be referred to as an authentication node. In some embodiments, the controller is a general-purpose computing device that implements the controller's functions by running management software. In other embodiments, the controller is a hardware device dedicated to network control and management functions.
[0109] In some embodiments, the network device and controller are implemented in a co-located manner, with the network device and controller integrated into the same physical device. Some embodiments of this application describe the process using the case where the network device and controller are separately located as an example. When the network device and controller are co-located, both the steps performed by the network device and the steps performed by the controller are performed by the device that integrates the network device and controller. For example, when the controller is integrated into the network device, the steps performed by the controller are actually performed by the network device.
[0110] In some embodiments, when the network device and the controller are implemented separately, the network device and the controller are different physical devices that communicate with each other. For example, the network device is provided on a general-purpose network device such as a router, switch, or firewall, or a dedicated network device, while the controller is provided on a server that communicates with the network device. The server implements the functions of the controller by running software that supports the control and management plane functions.
[0111] (8) Hypertext Transfer Protocol Connect (HTTP Connect) Message
[0112] An HTTP connect message is a message used in the Hypertext Transfer Protocol (HTTP) to establish a tunnel. An HTTP connect message is equivalent to a preamble message to a data message (also known as a service message). For example, the method field of the request line in an HTTP connect message includes the string "connect." An HTTP connect message may not carry service data and may not include an HTTP message body.
[0113] (9)X-Forwarded-For(XFF)
[0114] The XFF field is a field in the HTTP header. It was first proposed in RFC7239 in 2014. The XFF field, as defined in the standard, carries the client's IP address for traceability. For a definition of the XFF field, see https: / / datatracker.ietf.org / doc / html / rfc7239.
[0115] (10) SDP (software defined perimeter)
[0116] SDP is a technology that controls terminal access to resources based on identity authentication. SDP creates a policy-based security boundary, isolating protected servers from untrusted networks. SDP hides protected servers behind an SDP gateway, making it difficult for attackers to determine their location, thus increasing the difficulty of attack. SDP technology primarily involves identity authentication, authorization, message forwarding, and registration. The SDP system architecture includes three main components: the SDP client, the SDP gateway, and the SDP controller. Both the SDP client and the SDP gateway are referred to as SDP hosts.
[0117] (11)SDP Client
[0118] The SDP client is software installed on the terminal. It is used to initiate authentication requests to the SDP controller or SDP gateway, thereby performing the identity authentication process. The SDP client is also used to establish an HTTP encrypted tunnel with the SDP gateway to transmit data packets with the SDP gateway via the HTTP encrypted tunnel. Optionally, the SDP client includes a local agent program. The local agent program is used to process packets sent to and from the SDP gateway.
[0119] (12)SDP controller
[0120] The SDP controller is the brain of the SDP protocol. It authenticates the SDP client based on the authentication request from the SDP client and authorizes the SDP client after authentication.
[0121] (13)SDP Gateway
[0122] The SDP gateway is located between the SDP client and the protected server (or web application). It acts as a middleman between the SDP client and the SDP gateway. The SDP client must go through the SDP gateway to access the protected web application. The SDP gateway opens accessible ports to authorized users and closes all ports to unauthorized users.
[0123] (14) Single Packet Authorization (SPA) Authentication
[0124] SPA authentication is an authentication technology primarily used to implement the "authenticate first, then connect" approach in SDP Zero Trust. SPA authentication is also known as knocking authentication, where the door represents a port, and knocking represents accessing the port of an SDP component (SDP gateway and / or SDP controller). SPA authentication serves as a pre-authentication mechanism before connections between SDP components. If the SDP client passes SPA authentication, equivalent to the SDP client successfully knocking on the door, the SDP component (SDP gateway and / or SDP controller) will open the port requested by the SDP client, allowing the SDP client to access the port. If the SDP client fails SPA authentication, equivalent to the SDP client failing to knock on the door, the SDP component (SDP gateway and / or SDP controller) will close the port requested by the SDP client, thereby preventing the SDP client from accessing the SDP component port. According to the SDP specification drafted by the Cloud Security Alliance (CSA), the SPA authentication message typically includes a device identifier (used to identify the terminal running the SDP client), a random number, an SPA key (password), and the IP address of the SDP client. When the SDP client sends the SPA authentication message, the SDP client generates a first SPA key based on the shared key and the random number using the HMAC-based one-time password (HOTP) algorithm defined in RFC4266. The SDP client encapsulates the first SPA key, device identifier, random number, and source IP address into the SPA authentication message and sends it to the SDP controller. After the SDP controller receives the SPA authentication message, the SDP controller generates a second SPA key based on the shared key and the random number carried in the SPA authentication message using the HOTP algorithm. Based on the generated second SPA key, the SDP controller performs a consistency check on the first SPA key carried in the SPA authentication message. If the first SPA key and the second SPA key are consistent, the SDP controller determines that the SDP authentication is successful, and the SDP controller opens the destination port to be accessed by the SDP client, allowing the SDP client to access the port. If the first SPA key and the second SPA key are inconsistent, the SDP controller determines that the SDP authentication is unsuccessful. The SPA authentication message is, for example, a User Datagram Protocol (UDP) message or a Transmission Control Protocol (TCP) message. For the definition of SPA authentication and the content of SPA authentication messages, please refer to the SDP specification drafted by the Cloud Security Alliance (CSA).
[0125] (15)SDP authentication
[0126] SDP authentication is, for example, based on an interface authentication method. In an example of SDP authentication, the SDP client displays an authentication interface. The user triggers an input operation on the authentication interface. The SDP client receives a first user identifier entered on the authentication interface. The SDP client generates an SDP authentication request based on the first user identifier. The SDP authentication request includes the first user identifier. The SDP client generates an SDP authentication request based on the first user identifier. The SDP client sends an SDP authentication request to the SDP controller. The SDP controller receives the SDP authentication request. The SDP controller performs a consistency check based on the first user identifier carried in the SDP authentication request and the second user identifier pre-saved by the SDP controller. If the first user identifier passes the consistency check, the SDP controller determines that the SDP client has passed the SDP authentication. If the first user identifier does not pass the consistency check, the SDP controller determines that the SDP client has not passed the SDP authentication.
[0127] SDP authentication methods include at least one of authentication based on username and / or password, authentication based on certificate (public key), authentication based on biometrics, authentication based on SMS (such as verification code), and authentication based on terminal device identification.
[0128] In the case where the SDP authentication method includes authentication based on a user name and / or password, the first user identifier includes the user name and / or password. In the case where the SDP authentication method includes authentication based on a certificate (public key), the first user identifier includes authentication based on a certificate (public key). In the case where the SDP authentication method includes authentication based on biometrics, the first user identifier includes biometrics. In the case where the SDP authentication method includes authentication based on a text message (such as a verification code), the first user identifier includes a text message (such as a verification code). In the case where the SDP authentication method includes authentication based on a terminal device identifier, the first user identifier includes the terminal device identifier.
[0129] The authentication interface is used to perform SDP authentication. The authentication interface is, for example, a World Wide Web (WWW) interface (webpage). The authentication interface includes an input control and a submit button. The input control is an interface control for inputting a first user identifier, and the submit button is an interface control for confirming submission of the first user identifier to the SDP controller. A user can input the first user identifier by triggering an input operation on the input control. The user can trigger a submit instruction by clicking the submit button. The submit instruction is used to instruct the SDP client to send the first user identifier to the SDP controller. In response to the submit instruction, the SDP client sends the first user identifier received based on the input control to the SDP controller. The authentication interface is, for example, a login interface. For example, the submit button in the authentication interface is a login button.
[0130] For example, when the SDP authentication method includes authentication based on a username and / or password, the authentication interface displayed by the SDP client includes a username input control, a password control, and a submit button. The username input control is a form control for the user to enter a username. The username input control and the password input control are typically input boxes. The password input control is a form control for the user to enter a username. The password input control is typically a text box. The submit button is used to trigger a submit instruction. In an example of SDP authentication based on a username and / or password, the user enters a username in the username input box and a password in the password input box in the authentication interface, and clicks the submit button, thereby triggering a submit instruction. In response to the submit instruction, the SDP client sends the username and password to the SDP controller. The SDP controller authenticates the SDP client based on the username and password received from the SDP client.
[0131] For another example, when the SDP authentication method includes facial image-based authentication, the authentication interface includes a capture button and a submit button. In one example of facial image-based SDP authentication, a user clicks the capture button displayed in the authentication interface, thereby triggering a capture instruction. The SDP client responds to the capture instruction by capturing a facial image. The user clicks the submit button displayed in the authentication interface, thereby triggering a submit instruction. In response to the submit instruction, the SDP client sends the facial image to the SDP controller. The SDP controller authenticates the SDP client based on the facial image received from the SDP client.
[0132] The authentication interface includes a Hypertext Markup Language (HTML) file, a Cascading Style Sheets (CSS) file, and a Javascript file. The interface controls are implemented, for example, by program code.
[0133] The SDP authentication request is, for example, an HTTP request message or a Hypertext Transfer Protocol Secure (HTTPS) request message.
[0134] In some embodiments, an authentication interface for performing SDP authentication is sent by the SDP controller to the SDP client. For example, in response to receiving an authentication request from the SDP client, the SDP controller sends a Javascript file or HTML file of the authentication interface to the SDP client. The SDP client parses the Javascript file or HTML file through a browser to obtain the code for the authentication interface. The SDP client then renders the authentication interface in the browser based on the code for the authentication interface, thereby displaying the authentication interface.
[0135] (16) The relationship between SPA authentication and SDP authentication
[0136] Typically, the SDP controller first performs SPA authentication on the SDP client. If the SDP client passes SPA authentication, the SDP controller further performs SDP authentication on the SDP client. In some embodiments, in the first login scenario, the SDP controller performs SPA authentication on the terminal. If the terminal passes SPA authentication, the SDP controller further performs SDP authentication on the terminal. In scenarios other than the first login, the SDP controller does not need to perform SPA authentication on the SDP client, and the SDP controller performs SDP authentication on the SDP client.
[0137] (17) Message forwarding by SDP gateway
[0138] The SDP gateway's message forwarding process includes both outbound and return forwarding. Outbound message forwarding involves the SDP gateway forwarding messages from the terminal to the server providing the network application. Return message forwarding involves the SDP gateway forwarding messages from the server providing the network application to the terminal. The SDP gateway's message forwarding modes include transparent forwarding and access proxy mode.
[0139] Transparent forwarding mode means that the SDP gateway does not change the source and destination IP addresses of packets during forwarding. For example, when the SDP gateway forwards outbound or return packets, the source IP address of the packets sent by the SDP gateway is the same as the source IP address of the packets received by the SDP gateway, and the destination IP address of the packets sent by the SDP gateway is the same as the destination IP address of the packets received by the SDP gateway.
[0140] Access proxy mode means that the SDP gateway updates the source and destination IP addresses in packets as it forwards them. For example, when the SDP gateway is forwarding outbound or return packets, the source IP address of the packets sent by the SDP gateway may be different from the source IP address of the packets received by the SDP gateway, and the destination IP address of the packets sent by the SDP gateway may be different from the destination IP address of the packets received by the SDP gateway.
[0141] In some embodiments, an encrypted tunnel is established between the SDP gateway and the SDP client, and the message sent by the SDP client to the SDP gateway includes a tunnel header corresponding to the encrypted tunnel. When the SDP gateway receives the message from the SDP client, the SDP gateway first decapsulates the tunnel header, and then adopts the transparent forwarding mode or the access proxy mode to forward the inner message encapsulated in the tunnel header to the server. For example, in the case where the SDP gateway adopts the transparent forwarding mode, after the SDP gateway decapsulates the tunnel header, it does not need to further process the message in the inner layer of the tunnel header, and forwards the inner message to the server based on the IP address of the server carried by the destination IP address in the IP basic header in the inner message. In the case where the SDP gateway adopts the access proxy mode, after the SDP gateway decapsulates the tunnel header, it replaces the destination IP address in the IP basic header in the message in the inner layer of the tunnel header with the IP address of the server, replaces the source IP address in the IP basic header in the message in the inner layer of the tunnel header with the IP address of the SDP gateway, and forwards the inner message after the destination IP address and source IP address are replaced to the server. When the SDP gateway receives a message from the server, if the SDP gateway uses transparent forwarding mode, the SDP gateway does not need to modify the received message, but encapsulates the received message with a tunnel header and then forwards the message containing the tunnel header to the SDP client. If the SDP gateway uses access proxy mode, the SDP gateway replaces the source IP address in the IP basic header of the received message with the IP address of the SDP gateway, replaces the destination IP address in the IP basic header of the received message with the IP address of the terminal, encapsulates the message with the replaced destination IP address and source IP address with a tunnel header, and forwards the message containing the tunnel header, the replaced destination IP address, and the replaced source IP address to the SDP client.
[0142] (18) Third-party authentication system
[0143] A third-party authentication system is, for example, a system having authentication functions other than an SDP controller and an SDP gateway. For example, the third-party authentication system includes an authentication server. For example, the third-party authentication system includes a remote authentication dial-in user service (RADIUS) server, a dynamic host configuration protocol (DHCP) server, a security identifier (SecurID), an active directory (AD), or a lightweight directory access protocol (LDAP) server.
[0144] (19)SDP authorization process
[0145] The SDP authorization process includes the SDP controller sending to the SDP client a list of resources that the SDP controller authorizes the SDP client to access.
[0146] The resource list is used to indicate one or more network resources included in the scope of the SDP client's access rights. For example, the resource list includes the identifiers of one or more network resources that the SDP controller authorizes the SDP client to access. The identifier of the network resource includes, for example, at least one of the IP address of the network resource, the domain name of the network resource, the uniform resource locator (URL) of the network resource, the name of the network resource, and the icon of the network resource. By sending the resource list to the SDP client, the SDP controller is equivalent to authorizing the SDP client to access the network resource corresponding to the identifier of each network resource in the resource list.
[0147] In some embodiments, the resource list includes an application list. The application list includes the identifiers of one or more network applications that the SDP controller authorizes the SDP client to access and the identifier of the server corresponding to the identifier of each network application. The identifier of the network application in the application list includes the icon of the network application and the name of the network application. The identifier of the server in the application list is used to identify the server that provides the corresponding network application. For example, the identifier of the server in the application list includes at least one of the IP address of the server that provides the network application, the domain name of the server that provides the network application, and the URL of the network application. By sending the application list to the SDP client, the SDP controller is equivalent to authorizing the SDP client to access the server corresponding to the identifier of each network application in the application list.
[0148] When the identifier of the network application sent to the SDP client during the SDP controller authorization process includes the IP address of the server providing the network application, the SDP client can access the network application provided by the server through the SDP gateway based on the IP address of the server in the application list. In one possible implementation method for the SDP client to access the network application using the server IP address sent during the authorization process, the SDP client encapsulates the server IP address into the destination IP address field in the IP basic header of the inner layer of the message, or the SDP client encapsulates the server IP address into the HTTP header or HTTP request line of the inner layer message, so that the message sent by the SDP client to the SDP gateway carries the server IP address. Therefore, based on the server IP address carried in the message, the SDP gateway can forward the message from the SDP client to the server, thereby enabling the SDP client to access the network application provided by the server.
[0149] When the network application identifier sent to the SDP client during the SDP controller authorization process includes the network application's domain name, the SDP client can access the network application through the SDP gateway based on the network application's domain name in the application list. For example, when the SDP client accesses the network application, the SDP client obtains the network application's IP address through Domain Name System (DNS) resolution based on the network application's domain name, and then uses the network application's IP address obtained through DNS resolution to access the network application.
[0150] When the identifier of the network application sent by the SDP controller to the SDP client during the authorization process includes the icon of the network application, when the user clicks the icon of the network application displayed on the SDP client, the SDP client can generate an access request in response to the click operation and send the access request to the SDP gateway, thereby triggering the SDP gateway to execute the message forwarding process.
[0151] The URL of the network application sent by the SDP controller to the SDP client during the authorization process may include, for example, the IP address of the network application or the domain name of the network application. For example, as shown in Table 1 below, the URL of an online game is http: / / 192.168.0.1 / index.html, where 192.168.0.1 is the IP address of the server providing the online game. For another example, the URL of an online game is https: / / www.example.com / index.html, where www.example.com is the domain name of the server providing the online game.
[0152] Table 1 Resource list
[0153] In some embodiments, the resource list also includes a proxy gateway list, which includes the identifiers of one or more SDP gateways that the SDP controller authorizes the SDP client to access. The identifier of the SDP gateway in the proxy gateway list is used to identify the SDP gateway that can access the corresponding network application. The SDP client can access the network application based on the identifier of the SDP gateway. For example, an HTTPS encrypted tunnel is established between the SDP client and the SDP gateway, and the identifier of the SDP gateway is encapsulated into the tunnel header corresponding to the HTTPS encrypted tunnel, so that during the forwarding process between the SDP client and the SDP gateway, the identifier of the SDP gateway indicates that the message is to be sent to the SDP gateway or the message comes from the SDP gateway.
[0154] In some implementations in which the SDP client accesses the network application based on the identifier of the SDP gateway, the SDP client establishes an HTTPS encrypted tunnel with the SDP gateway based on the identifier of the SDP gateway, and the SDP client sends a message addressed to the network application to the SDP gateway via the HTTPS encrypted tunnel. As an example, the SDP client encapsulates the identifier of the SDP gateway into a tunnel header corresponding to the HTTPS encrypted tunnel on the outer layer of the message, so that the tunnel header of the message sent from the SDP client to the SDP gateway carries the identifier of the SDP gateway. Therefore, the intermediate node through which the HTTPS encrypted tunnel between the SDP client and the SDP gateway passes can forward the message to the SDP gateway based on the identifier of the SDP gateway.
[0155] In some embodiments, the identifier of the SDP gateway in the proxy gateway list includes the IP address of the SDP gateway and the port number of the SDP gateway. The IP address of the SDP gateway is the IP address of the SDP gateway used to communicate with the SDP client. The port number of the SDP gateway identifies the port of the SDP gateway used to communicate with the SDP client. The terminal can access the network application based on the IP address of the SDP gateway and the port number of the SDP gateway. For example, the IP address of the SDP gateway and the port number of the SDP gateway are both encapsulated into the tunnel header corresponding to the HTTPS encrypted tunnel established between the SDP client and the SDP gateway, so that the message is forwarded between the SDP client and the SDP gateway based on the IP address of the SDP gateway and the port number of the SDP gateway. Optionally, the IP address of the SDP gateway in the proxy gateway list is the virtual IP address of the SDP gateway, and the port number of the SDP gateway in the proxy gateway list is the virtual port number of the SDP gateway.
[0156] In some implementations in which the SDP client accesses the network application based on the IP address and port number of the SDP gateway, during the process of the SDP client accessing the network application, the tunnel header corresponding to the HTTPS encrypted tunnel established between the SDP client and the SDP gateway includes a TCP header and an IP basic header. The SDP client encapsulates the IP address of the SDP gateway into the destination IP address field of the IP basic header in the tunnel header of the outer layer of the message, and the SDP client encapsulates the port number of the SDP gateway into the destination port number field of the TCP header in the tunnel header of the outer layer of the message, so that the tunnel header of the message sent by the SDP client to the SDP gateway carries the IP address and port number of the SDP gateway. Therefore, the intermediate node through which the HTTPS encrypted tunnel between the SDP client and the SDP gateway passes can forward the message to the SDP gateway based on the IP address of the SDP gateway carried in the tunnel header, and the SDP gateway can receive the message from the SDP client based on the virtual port number carried in the message.
[0157] In some embodiments, the resource list issued by the SDP controller during the authorization process includes both an application list and a proxy gateway list. Moreover, the proxy gateway list in the resource list has a mapping relationship with the application list in the resource list. The SDP client can access the network application corresponding to the SDP gateway in the application list based on the identifier of the SDP gateway in the proxy gateway list. For example, the resource list includes a correspondence between the identifier of the network application (the IP address of the server providing the network application or the domain name of the server providing the network application) and the identifier of the SDP gateway (the IP address of the SDP gateway and the virtual port of the SDP gateway).
[0158] Optionally, the resource list adopts the format of key-value (key-value pair), the identifier of the network application is the key of the resource list, and the identifier of the SDP gateway is the value corresponding to the key in the resource list. When the SDP client wants to access a network application, the SDP client uses the identifier of the network application as the key to find the identifier of the SDP gateway corresponding to the network application, and sends the data stream with the network application as the destination to the SDP gateway. Since the identifier of the network application in the resource list is associated with the identifier of the SDP gateway, it is possible to specify which SDP gateway agent each network application passes through, so that the data stream of each network application is forwarded through the corresponding SDP gateway, meeting the needs of more network deployment scenarios.
[0159] As a specific example of a resource list issued by an SDP controller during the authorization process, please refer to Table 2 below. The resource list shown in Table 2 includes the identifiers of two network applications and the identifiers of two SDP gateways corresponding to the two network applications. The patent management system and online game shown in Table 2 are specific examples of two network applications. The resource list includes the corresponding relationship between the URL of the patent management system (https: / / www.mypatent.com / index.html, including the domain name of the patent management system), the IP address of the SDP gateway 10.19.10.100, and the port number 8443 of the SDP gateway. The resource list also includes the corresponding relationship between the URL of the online game (http: / / 192.168.0.1 / index.html, including the IP address of the network application), the IP address of the SDP gateway 10.19.20.200, and the port number 5060 of the SDP gateway.
[0160] Table 2 Resource List
[0161] In conjunction with the specific example provided in Table 2, in some embodiments, after the SDP client receives the application list from the SDP controller, the SDP client displays an icon for the patent management system and an icon for the online game in the interface. The icon for the patent management system displays the URL of the patent management system: https: / / www.mypatent.com / index.html, and the icon for the online game displays the IP address of the online game: http: / / 192.168.0.1 / index.html. When the user clicks on the icon of the patent management system displayed in the interface of the SDP client, the SDP client responds to receiving the user's click operation, and the SDP client obtains the IP address of the server providing the patent management system through DNS based on the URL of the patent management system https: / / www.mypatent.com / index.html. The SDP client encapsulates the IP address of the server of the patent management system into the HTTP header or HTTP request line located in the inner layer of the HTTPS encryption tunnel header in the message. The SDP client encapsulates the IP address 10.19.10.100 of the SDP gateway into the destination address field of the IP basic header contained in the HTTPS encryption tunnel header. The SDP client encapsulates the port number 8443 of the SDP gateway into the destination port number field of the TCP header contained in the HTTPS encryption tunnel header. The SDP client sends the encapsulated message to the SDP gateway so as to access the patent management system through the message.
[0162] In some embodiments, after the SDP controller authenticates the SDP client, the SDP controller also sends the unique identifier of the terminal where the SDP client is located, the destination port number of the SDP gateway, and the IP address of the terminal to the SDP gateway during the authorization process. The unique identifier of the terminal is used by the SDP gateway for verification when forwarding messages from the terminal. The destination port of the SDP gateway refers to the port on the SDP gateway that the terminal is allowed to access. The IP address of the terminal is the source IP address of the traffic allowed to be released by the SDP gateway. When the SDP gateway receives an access request from the SDP client, it can perform a consistency check based on the source IP address of the access request and the IP address of the terminal issued by the SDP controller during the authorization process to determine whether the source IP address of the access request is legal. It can also perform a consistency check based on the destination port number of the access request and the destination port number of the SDP gateway issued by the SDP controller during the authorization process to determine whether the destination port of the access request is legal. If both the source IP address and the destination port are legal, the SDP gateway forwards the access request to the protected network application, thereby allowing the SDP client that sent the access request to access the protected network application.
[0163] As a specific example, when a user clicks on the icon of an online game displayed in the interface of the SDP client, the SDP client responds to receiving the user's click operation, and the SDP client obtains the IP address of the server providing the online game as 192.168.0.1 based on the URL of the online game http: / / 192.168.0.1 / index.html. The SDP client encapsulates the IP address 192.168.0.1 of the server providing the online game into the HTTP header or HTTP request line located in the inner layer of the HTTPS encryption tunnel header in the message, the SDP client encapsulates the IP address 10.19.20.200 of the SDP gateway into the destination address field of the IP basic header contained in the HTTPS encryption tunnel header, the SDP client encapsulates the port number 5060 of the SDP gateway into the destination port number field of the TCP header in the HTTPS encryption tunnel header, and the SDP client sends the encapsulated message to the SDP gateway so as to access the online game through the message.
[0164] (20)SDP registration process
[0165] The SDP registration process may also be referred to as the SDP initial permission configuration or application publishing process. In some embodiments, the SDP registration includes the identifier of the registered network application, the identifier of the server providing the network application, and a list of user identifiers. The identifier of the registered network application includes the network application icon and the name of the network application. The identifier of the registered server includes the server's IP address or the server's domain name. The user identifier list includes the identifier of at least one user with permission to access the network application.
[0166] In one possible implementation of registering a network application identifier, the SDP controller presents a configuration interface to the user. The configuration interface includes input controls such as an input box, a drop-down menu, and a selection button for the network application identifier. The user enters the network application identifier in the input control on the configuration interface. Based on the user's input on the configuration interface, the SDP controller obtains the identifier of the network application to be registered. The implementation of registering other information is similar.
[0167] In some embodiments, the SDP registration further includes registering an identifier of the SDP gateway corresponding to the network application. The identifier of the registered SDP gateway includes the virtual IP address of the SDP gateway that can access the network application and the virtual port number of the SDP gateway that can access the network application. In some embodiments, the identifier of the registered SDP gateway also includes the management IP address of the SDP gateway and the management port of the SDP gateway.
[0168] The SDP gateway's management IP address is the IP address used by the SDP gateway to communicate with the SDP controller. The SDP gateway's management port identifies the port on the SDP gateway that communicates with the SDP controller. Registering the SDP gateway's management IP address and port with the SDP controller facilitates interaction between the SDP controller and the SDP gateway based on these IP addresses and port numbers.
[0169] (21) The relationship between the authentication process (SPA or SDP), authorization process, and registration process in SDP
[0170] The registration process is a preset process before the authentication process and the authorization process. The authentication process and the authorization process depend on the identifier of the network application registered on the SDP controller, the identifier of the server providing the network application, and the user identifier list. During the SDP authentication process, when the SDP controller receives an SDP authentication request from the terminal, the SDP controller uses the user identifier carried in the SDP authentication request to match the registered user identifier list. In response to the user identifier hitting the user identifier list and the first user identifier carried in the SDP authentication request passing the consistency check, the SDP controller can send the identifier of the registered network application and the identifier of the server providing the network application as the content of the resource list to the SDP client during the authorization phase.
[0171] In addition, through the SDP registration process, the management IP address of the SDP gateway and the management port of the SDP gateway are registered on the SDP controller. After the SPA authentication is passed, the SDP controller sends a control signaling to the SDP gateway based on the management IP address of the SDP gateway and the management port of the SDP gateway. The control signaling instructs the SDP gateway to open a virtual port that can access the network application so that the SDP gateway opens the virtual port, thereby allowing the SDP client to send messages sent to the network application to the virtual port of the SDP gateway to access the network application.
[0172] A successful authentication result is a prerequisite for authorization. For example, after an SDP client passes SDP authentication, the SDP controller sends a resource list to the client. If the client fails SDP authentication, the SDP controller refuses to send the resource list to the client, thereby reducing the security risk to the server posed by an unauthorized SDP client obtaining the resource list.
[0173] The following is an example of an application scenario of the embodiment of the present application.
[0174] The embodiment of the present application is applicable to the scenario in which a terminal in the field of network security protection remotely accesses an intranet server through a network device, and is particularly applicable to the scenario in the field of SDP zero trust in which an SDP client accesses a server that provides intranet resources (such as network applications) through an SDP gateway. Since the security protection system replaces the source IP address in the message sent by the terminal to the intranet server with a specific virtual IP address, and the virtual IP address corresponds to the identifier of the user logged in on the terminal, the virtual IP address carried by the source IP address of the message sent by the security protection system to the intranet server can locate the corresponding user identifier, thereby tracing the source to the specific user who accessed the intranet server. Moreover, since the virtual IP address used as the source IP address belongs to the IP address of the intranet, the configuration complexity caused by configuring the return route for the real IP address of each terminal in the Internet is reduced.
[0175] Considering that in remote access scenarios, the terminal's real IP address usually changes dynamically, making it difficult to trace the source based on the terminal's real IP address. For example, in scenarios where a terminal accesses network resources based on a mobile data communication network, according to the 3GPP standard TS23401-i20 "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; General Packet Radio Service (GPRS) enhancements for Evolved Universal Terrestrial Radio Access Network (E-UTRAN) access (Release 18)", when a terminal accesses via Internet Protocol version 6 (IPv6), the network side uses a stateless address allocation mechanism to allocate an IPv6 address to the terminal, causing the terminal's IPv6 address to change dynamically. Therefore, if the source IP address of the message sent by the security protection system to the intranet server is the terminal's real IP address, tracing the source will be difficult. Furthermore, there may be multiple network address translations (NATs) between the terminal and the security protection system, further increasing the difficulty of tracing the source.
[0176] Based on this, in some embodiments of the present application, since the terminal is assigned a virtual IP address corresponding to the user identifier of the terminal login based on the correspondence between the user identifier and the virtual IP address, after the security protection system replaces the source IP address in the message sent by the terminal to the intranet server with the virtual IP address corresponding to the user identifier, the source IP of the message sent to the intranet server is strongly bound to the user, thereby reducing the difficulty of tracing the source to the user based on the source IP of the message.
[0177] Alternatively, if a Secure Sockets Layer Virtual Private Network (SSL VPN) is used where multiple users reuse all IP addresses in an address pool, the IP addresses of different users may be duplicated, making it impossible to locate a specific user based on a single IP address. Based on this, in some embodiments of the present application, the correspondence between user identifiers and virtual IP addresses is such that one virtual IP address corresponds to one user identifier, so that the virtual IP addresses corresponding to different user identifiers are not duplicated. Therefore, a unique user identifier can be located based on a single virtual IP address, thereby improving traceability accuracy and facilitating auditing.
[0178] Considering remote access scenarios, terminals in different locations may access intranet servers through different network environments. For example, terminal A at home accesses web application A provided by the intranet server through a home router, terminal B in a public WLAN network such as a cafe or campus accesses web application A provided by the intranet server through the public WLAN network, and terminal C accesses web application A provided by the intranet server through a mobile data network. This results in a large number of real IP addresses for all terminals accessing intranet web applications. If the source IP address in the message sent by the security protection system to the intranet server is still the real IP address of the terminal, the source IP address in the message transmitted within the intranet will contain IP addresses from various networks. In the scenario where terminals and intranet servers access each other, in order to meet the demand of the intranet server to return messages to the terminals, a large number of return routes need to be configured on the intranet server for the real IP addresses of a large number of terminals. The destination IP address in each return route is the real IP address of the corresponding terminal, and the intranet server also needs to publish a large number of return routes in the intranet so that each hop node in the forwarding path between the security protection system and the intranet server can obtain the return route, so that the messages returned by the server to each terminal can be forwarded to the corresponding terminal based on the return route. Even for terminals that access temporarily, it is necessary to configure and publish return routes, which leads to high complexity of network configuration and huge network overhead caused by publishing return routes.
[0179] Based on this, in some embodiments of the present application, since the virtual IP addresses assigned by the security protection system to each user are all intranet IP addresses (private IP addresses), for example, a corresponding virtual IP address is assigned to each user of the network application to be accessed from an intranet IP address segment, the security protection system replaces the source IP addresses of the messages initiated by each terminal with the virtual IP addresses of the corresponding users, so that the source IP addresses of the messages from each terminal sent to the intranet server all belong to the intranet IP addresses. Therefore, when it is necessary to forward the return message from the server, only one return route needs to be configured for the virtual IP address of each user. For example, the destination IP address of the return route is the intranet IP address segment including the virtual IP address, and the next hop of the return route is the IP address of the security protection system. There is no need to configure the return route for the real IP address of each terminal, thereby reducing the complexity of configuring the return route and reducing the network overhead of publishing the return route.
[0180] The types of virtual IP addresses include various situations. In some embodiments, the virtual IP address assigned by the security protection system to the user is an Internet Protocol version 4 (IPv4) address, thereby supporting access to network applications using an IPv4 address as the source IP address, and is applicable to scenarios where network applications support communication based on the IPv4 protocol. In other embodiments, the virtual IP address assigned by the security protection system to the user is an IPv6 address, thereby supporting access to network applications using an IPv6 address as the source IP address based on the IPv6 protocol, and is applicable to scenarios where network applications support communication based on the IPv6 protocol. In still other embodiments, in scenarios where network applications support both communication based on the IPv4 protocol and the IPv6 protocol, the virtual IP address assigned by the security protection system to the user is a dual-stack IP address, and the virtual IP address includes an IPv4 address and an IPv6 address, thereby supporting access to network applications using an IPv4 address as the source IP address, and supporting access to network applications using an IPv6 address as the source IP address, and is applicable to scenarios where network applications support communication based on the IPv4 protocol and the IPv6 protocol.
[0181] For example, the correspondence between user identifiers and virtual IP addresses is shown in Table 3 below.
[0182] Table 3 Correspondence between user ID and virtual IP address
[0183] In conjunction with Table 3, in a specific example, in a scenario where an intranet server provides IPv4 services, the correspondence between user identifiers and virtual IP addresses indicates that user identifier User 1 corresponds to the virtual IP address 192.168.20.11 in the form of an IPv4 address. Subsequently, when User 1 initiates access, the security protection system uses the virtual IP address 192.168.20.11 as the source IP address to access the intranet server at IP address 192.168.10.100. Furthermore, when the audit and traceability system obtains a message sent by the security protection system to the intranet server, based on the virtual IP address 192.168.20.11 carried in the source IP address of the message and the correspondence between the virtual IP address 192.168.20.11 and user identifier User 1, the audit and traceability system can locate user identifier User 1, thereby determining that the user who triggered the access to the intranet server at IP address 192.168.10.100 was User 1, thereby tracing the source to the specific user.
[0184] Combined with Table 3, in a specific example, in a scenario where the intranet server provides IPv6 services, the user identifier User 2 corresponds to the virtual IP address 540b:843c:1:a::100 in the form of an IPv6 address. Subsequently, when User 2 initiates an access, the security protection system uses the virtual IP address 540b:843c:1:a::100 in the form of an IPv6 address as the source IP address to access the intranet server with the destination IP address 440b:843c:1:a::100. Moreover, when the audit tracing system obtains the message sent by the security protection system to the intranet server, the audit tracing system can locate the user identifier User 2 based on the virtual IP address 540b:843c:1:a::100 carried by the source IP address in the message and the correspondence between the virtual IP address 540b:843c:1:a::100 and the user identifier User 2, thereby knowing that the user who triggered the access to the intranet server with IP address 440b:843c:1:a::100 is User 2, thereby tracing the source to the specific user.
[0185] Combined with Table 3, in a specific example, in a scenario where the intranet server provides IPv4 and IPv6 services, the correspondence between user identifiers and virtual IP addresses shows that user identifier User 3 corresponds to the virtual IP address 192.168.5.101 in the form of an IPv4 address and the IPv6 address 540b:843c:1:a::101. Subsequently, when User 3 initiates an access, the security protection system can use the virtual IP address 192.168.5.101 in the form of an IPv4 address as the source IP address to access the intranet server with a destination IP address of 192.168.1.101, and can also use the virtual IP address 540b:843c:1:a::101 in the form of an IPv6 address as the source IP address to access the intranet server with a destination IP address of 440b:843c:1:a::101. Moreover, when the audit tracing system obtains the message sent by the security protection system to the intranet server, the audit tracing system can locate the user identifier User 3 based on the virtual IP address 540b:843c:1:a::101 carried by the source IP address in the message and the correspondence between the virtual IP address 540b:843c:1:a::101 and the user identifier User 3, thereby knowing that the user who triggered the access to the intranet server with IP address 440b:843c:1:a::101 is User 3, thereby tracing the source to the specific user. Based on the virtual IP address 192.168.5.101 carried in the source IP address of the message and the correspondence between the virtual IP address 192.168.5.101 and the user ID User 3, the audit tracing system can locate the user ID User 3, thereby knowing that the user who triggered the access to the intranet server with the IP address 192.168.1.101 is User 3, thereby tracing the source to the specific user.
[0186] In some embodiments, the virtual IP address corresponding to the user identifier belongs to the same network (such as a local area network) as the IP address of the server cluster where the network application that the security protection system authorizes the user identifier to access is located. In some embodiments, the virtual IP address corresponding to a user identifier belongs to the network where the IP address of the server cluster where the network application that the user identifier has permission to access is located. In some embodiments, the type of the virtual IP address corresponding to a user identifier is determined based on the type of the IP address of the server where the network application that the user identifier has permission to access is located. In some embodiments, the security protection system assigns a virtual IP address of the same type to each user identifier in the list of user identifiers registered for the network application that have permission to access the network application based on the type of IP address registered for the network application. Since the security protection system uniformly assigns virtual IP addresses to each user from the intranet IP address segment to which the IP address of the network application belongs, on the one hand, it facilitates network planning and reduces the complexity of network configuration. In addition, because the security protection system performs virtual IP address allocation without the need for terminals to perform virtual IP address allocation, the risk of leaking internal network addresses is reduced, and the risk of attackers sniffing the virtual network card through the physical network card to steal data and deduce the network architecture or new vulnerabilities in the network card program are reduced, thereby reducing the risk of being attacked and affecting the security of the entire organization.
[0187] As an example, during the application registration phase, a network administrator registers with the security system the IP address of the server hosting network application A as IPv4 address 192.168.0.0 and a list of user IDs with access rights to network application A, including User 1, User 2, and User 3. The security system then selects three idle IP addresses from the IPv4 address segment 192.168.0.0 / 24 as virtual IP addresses to be assigned to User 1, User 2, and User 3, respectively. For another example, during the application registration phase, a network administrator registers with the security system the IP address of the server hosting network application B as IPv6 address 2001:db8::1 / 128 and a list of user IDs with access rights to network application B, including User 1, User 2, and User 3. The security system then selects three idle IPv6 addresses from the IPv6 address segment 2001:db8:: / 32 as virtual IP addresses to be assigned to User 1, User 2, and User 3, respectively.
[0188] In some embodiments, the correspondence between user identifiers and virtual IP addresses is one, corresponding to one user identifier. In other words, the correspondence between user identifiers and virtual IP addresses is a one-to-one relationship. Alternatively, the correspondence between user identifiers and virtual IP addresses is multiple, corresponding to one user identifier. For example, in a network application supporting dual-stack services, one user identifier corresponds to two virtual IP addresses. One virtual IP address corresponding to the user identifier is in the form of an IPv4 address, and the security protection system can access the network application via an IPv4 link using the IPv4 address as the source IP address. The other virtual IP address corresponding to the user identifier is in the form of an IPv6 address, and the security protection system can access the network application via an IPv6 link using the IPv6 address as the source IP address. For another example, in a case where a user identifier has permission to access a first network application and a second network application, and the first network application is provided by a server in a first local area network and the second network application is provided by a server in a second local area network, the user identifier corresponds to a virtual IP address in the first local area network and a virtual IP address in the second local area network.
[0189] In some embodiments, the security protection system performs IP address translation between two networks, thereby hiding the intranet IP address and reducing the risk of IP attacks.
[0190] In one example, the terminal as the access initiator is located in the first network, and the server as the access destination is located in the second network. The source IP address carried in the IP basic header of the data packet received by the security protection system from the terminal is the IP address in the first network. The security protection system replaces the source IP address carried in the IP basic header of the data packet with a virtual IP address in the second network, so that during the transmission of the data packet in the first network, the source IP address of the IP basic header does not need to carry the IP address in the second network, so that the device in the first network cannot perceive the IP address in the second network based only on the source IP address carried in the IP basic header, which is equivalent to hiding the digital assets (IP address) of the second network, thereby reducing the security risks caused by IP attacks.
[0191] In another example, the source IP address carried in the IP basic header of the data message received by the security protection system from the terminal is an IP address in the first network, and the destination IP address carried in the IP basic header is also an IP address in the first network (such as the virtual IP address of the security protection system). The security protection system not only replaces the source IP address carried in the IP basic header of the data message with the virtual IP address in the second network, but also replaces the destination IP address carried in the IP basic header of the data message with the IP address of the server in the second network. Since both the source IP address and the destination IP address are replaced, during the transmission of the data message in the first network, the source IP address and the destination IP address of the IP basic header do not need to carry the IP address in the second network, so that the devices in the first network cannot perceive the IP address in the second network based only on the source IP address and the destination IP address carried in the IP basic header, thereby more effectively hiding the digital assets (IP addresses) of the second network and further reducing the security risks caused by IP attacks.
[0192] In some embodiments, after a terminal (such as an SDP client) passes identity authentication, the security protection system sends a virtual IP address corresponding to the user identifier to the terminal during the authorization process. Since the virtual IP address is issued to the terminal based on the result of identity authentication, the terminal's passing of identity authentication is used as a prerequisite for issuing the virtual IP address. For example, the security protection system will issue the virtual IP address corresponding to the user identifier to the terminal only if the terminal passes identity authentication. If the terminal fails identity authentication, the security protection system will not issue the virtual IP address corresponding to the user identifier to the terminal. Compared with address allocation technologies that do not provide authentication functions, such as the Dynamic Host Configuration Protocol (DHCP), this improves the credibility of the IP address to a certain extent, making it impossible for terminals that have not passed identity authentication to access network applications using the virtual IP address, reducing the risk of attacks initiated by forged source IP addresses, and improving the security of intranet applications.
[0193] In some implementations, after a terminal passes SPA authentication and / or SDP authentication, the security protection system sends a virtual IP address corresponding to the user identifier to the terminal during the authorization process. By combining the results of SPA authentication and / or SDP authentication, which are unique to SDP zero-trust scenarios, to issue the virtual IP address, this improves the security of the virtual IP address while also being more suitable for SDP zero-trust scenarios, reducing the complexity of implementing traceability using this solution in SDP zero-trust scenarios.
[0194] In some embodiments, the security protection system sends the virtual IP address corresponding to the user identifier to the terminal during the authorization process if the terminal passes both SPA authentication and SDP authentication. If the terminal fails either SPA authentication or SDP authentication, the security protection system refuses to send the virtual IP address corresponding to the user identifier to the terminal. Since the security protection system does not issue the virtual IP address if either SPA or SDP authentication fails, the security protection system further improves the security of the virtual IP address and reduces the security risk to the intranet posed by the virtual IP address being stolen by an attacker.
[0195] In some implementations, the security protection system first performs SPA authentication on the terminal. If the SPA authentication passes, the security protection system further performs SDP authentication on the terminal. If the SDP authentication passes, the security protection system issues a virtual IP address to the terminal.
[0196] In some embodiments, in the first login scenario, the security protection system first performs SPA authentication on the terminal. If the terminal passes SPA authentication, the security protection system further performs SDP authentication on the terminal. If SDP authentication passes, the security protection system issues a virtual IP address to the terminal. In non-first login scenarios, the security protection system does not need to perform SPA authentication. If the terminal passes SDP authentication, the security protection system issues a virtual IP address to the terminal.
[0197] In some embodiments, when the terminal initiates an access, the terminal encapsulates the virtual IP address of the terminal into the XFF field in the application layer message header in the message. Considering that there are multiple hop intermediate nodes between the client and the server, the XFF field may carry the IP address of the previous hop node, so tracing the source based on the content of the XFF field depends on the authenticity of the IP address of the previous hop node. If there is NAT in the network, the IP address carried in the XFF field is the IP address after NAT, which makes it impossible to determine the IP address of the terminal based on the content of the XFF field. Based on this, in some embodiments of the present application, the XFF field is used to carry the virtual IP address of the terminal, for example, the XFF field is used to carry the virtual IP address of the SDP client, so that the role of the XFF field matches the definition of the XFF field in the standard, and any one-hop network device between the client and the server (such as an SDP gateway) can know that the content of the XFF field includes the IP address of the client based on the field name of the XFF field, so that the solution can reuse the message format of the HTTP header provided in the existing standard, which is more compatible with the standard and reduces the implementation complexity.
[0198] Referring to Figure 1, Figure 1 shows a schematic diagram of the architecture of a network system 10 provided in an embodiment of the present application. The network system 10 shown in Figure 1 includes a terminal 110, a security protection system 130, and a server 120. The terminal 110 is located in a first network. The server 120 is located in a second network. The security protection system 130 is deployed between the terminal 110 and the server 120. In some embodiments, client software is installed and running on the terminal 110. The client software is used to access network applications deployed in the second network. The client software is, for example, virtual private network (VPN) software. For example, in an SDP zero trust scenario, the client software is an SDP client. The client software is, for example, browser software, or an application client corresponding to a network application. The server 120 acts as an access object. The server 120 is used to provide network applications. In some embodiments, the security protection system 130 includes a network device 131 and a controller 132. The network device 131 is located between the first network and the second network. For example, the network device 131 is connected to the first network and the second network respectively.
[0199] Referring to Figure 2, Figure 2 shows a flow chart of a method for accessing a network application provided by an embodiment of the present application. In some embodiments, the method shown in Figure 2 is applied to the network system 10 shown in Figure 1, and the method shown in Figure 2 is interactively executed by the terminal 110, the security protection system 130, and the server 120 in the network system 10 shown in Figure 1. Optionally, when the network device 131 and the controller 132 are implemented in a separate manner, the message forwarding process performed by the security protection system in the method shown in Figure 2 is specifically executed by the network device 131. For example, the network device 131 supports and enables the access proxy mode. In the access proxy mode, the network device 131 executes S220, S222, S224, S228, S230, S232, and S234 in the method shown in Figure 2. The identity authentication and authorization process performed by the security protection system in the method shown in Figure 2 is executed by the controller 132. For example, the controller 132 executes S206, S208, S210, and S212 in the method shown in Figure 2.
[0200] S202: The terminal generates an authentication request.
[0201] The authentication request is used to instruct the terminal to authenticate its identity. For example, in the SDP zero-trust scenario, the authentication request includes at least one of an SPA authentication request and / or an SDP authentication request. For example, the authentication request is a synchronization (SYN) message in the Transmission Control Protocol (TCP) or an HTTP request message. For another example, in the SSL VPN scenario, the authentication request is a RADIUS authentication message. For another example, the authentication request is an LDAP authentication message. For another example, the authentication request is an authentication message in the 802.1X protocol. For another example, the authentication request is an Internet Key Exchange (IKE) negotiation message. In some embodiments, the terminal generates an authentication request in response to a user's login operation.
[0202] The authentication request includes a user identifier. Some embodiments of this application involve the user identifier carried in the authentication request initiated by the terminal and the user identifier pre-saved by the security protection system before the terminal initiates authentication. To distinguish the description, the user identifier carried in the authentication request is described below as "first user identifier." The first user identifier is the identifier of the user logged in on the terminal.
[0203] How the terminal obtains the first user identifier includes multiple implementations. In some implementations of the terminal obtaining the first user identifier, the terminal displays an authentication interface. The user enters the first user identifier on the authentication interface. The terminal receives the first user identifier entered on the authentication interface. For example, in an SDP zero-trust scenario, the terminal displays the authentication interface through the SDP client, and the terminal receives the first user identifier entered on the authentication interface through the SDP client. In other implementations of the terminal obtaining the first user identifier, the first user identifier includes a certificate pre-saved on the terminal, for example, the first user identifier includes a certificate configured to the SDP client when the SDP client is installed, and the terminal reads the first user identifier from the local storage space of the terminal. In still other implementations of the terminal obtaining the first user identifier, the first user identifier includes the device identifier of the terminal, and the terminal reads the device identifier configured or burned on the hardware of the terminal.
[0204] In some embodiments, the terminal encapsulates the terminal's first device identification into an authentication request and sends the request to the security protection system. The security protection system obtains the terminal's first device identification carried in the authentication request and authenticates the terminal based on the terminal's first device identification and the terminal's second device identification pre-stored on the security protection system.
[0205] S204: The terminal sends an authentication request to the security protection system.
[0206] The destination of the authentication request can be in various situations. In some implementations, the security protection system includes a controller, and the terminal sends the authentication request to the controller. For example, in an SDP zero-trust scenario, the terminal includes an SDP client, and the security protection system includes an SDP controller. The terminal sends the authentication request to the SDP controller via the SDP client. In another example, in an SSL VPN scenario, the terminal sends the authentication request to the SSL VPN server via a web browser.
[0207] For more details on how the terminal generates and sends an authentication request, please refer to the previous description of SPA authentication and SDP authentication.
[0208] S206: The security protection system receives an authentication request from the terminal.
[0209] S208: The security protection system authenticates the terminal based on the authentication request.
[0210] In some implementations, the security protection system authenticates the terminal by at least one of SPA authentication and SDP authentication.
[0211] In some embodiments, the security protection system obtains a first user identifier carried in the authentication request. The security protection system performs a consistency check based on the first user identifier and a second user identifier pre-stored by the security protection system. If the first user identifier passes the consistency check, the security protection system determines that the terminal has passed authentication. If the first user identifier fails the consistency check, the security protection system determines that the terminal has failed authentication.
[0212] In this embodiment, after the terminal initiates authentication, the security protection system will issue a virtual IP address corresponding to the user identifier to the terminal only if the terminal authentication is successful, thereby improving the security of the intranet IP address.
[0213] S210 , in response to the terminal passing the authentication, the security protection system obtains a first virtual IP address based on the user identifier.
[0214] Since the message interaction process in some implementations of the present application involves virtual IP addresses of different entities, in order to distinguish the description, the "first virtual IP address" is used to specifically refer to the virtual IP address corresponding to the user identifier and located in the network where the server is located.
[0215] In some implementations of obtaining the first virtual IP address, the security protection system searches for a target correspondence based on the user identifier to obtain the first virtual IP address.
[0216] The target correspondence is, for example, the correspondence between the user identifier and the virtual IP address described above. The target correspondence includes the user identifier and the first virtual IP address. Optionally, the target correspondence adopts a key-value format, the user identifier is the key of the target correspondence, and the first virtual IP address is the value corresponding to the key in the target correspondence. In some embodiments, the number of user identifiers corresponding to a virtual IP address in the target correspondence is one, so the virtual IP addresses found by the security protection system based on different user identifiers are not repeated, so that the audit and tracing system can locate a unique user identifier based on a virtual IP address, thereby improving the traceability accuracy and facilitating auditing. In some embodiments, the number of virtual IP addresses corresponding to a user identifier in the target correspondence is one or more, thereby meeting the user's need to access dual-stack services or access multiple network applications in multiple intranets.
[0217] Regarding the method by which the security protection system obtains the target correspondence, the security protection system may optionally pre-save the target correspondence before the terminal initiates authentication. For example, an administrator may configure the target correspondence for the security protection system. For example, in an SDP zero-trust scenario, the security protection system includes an SDP controller, and during the SDP registration process (initial permission configuration), the administrator configures the target correspondence for the SDP controller.
[0218] For more technical details on the target correspondence, please refer to the description of the correspondence between the user identifier and the virtual IP address in the previous text.
[0219] As an example of obtaining the first virtual IP address, the user identifier carried in the authentication request is User 1. The security protection system searches for the target correspondence shown in Table 3 based on User 1 to obtain the virtual IP address corresponding to User 1 as 192.168.20.11. 192.168.20.11 is a specific example of the first virtual IP address. As another example of obtaining the first virtual IP address, the user identifier carried in the authentication request is User 2. The security protection system searches for the target correspondence shown in Table 3 based on User 2 to obtain the virtual IP address corresponding to User 2 as 1540b:843c:1:a::100. 540b:843c:1:a::100 is a specific example of the first virtual IP address.
[0220] In some other embodiments of obtaining the first virtual IP address, the security protection system obtains the first virtual IP address by interacting with a third-party authentication system. For example, the security protection system sends a user identifier to the third-party authentication system. The third-party authentication system searches for the target correspondence based on the user identifier to obtain the first virtual IP address. The third-party authentication system sends the first virtual IP address to the security protection system. The security protection system receives the first virtual IP address from the third-party authentication system. In one implementation method in which the security protection system interacts with the third-party authentication system, the security protection system sends a query request to the third-party authentication system, the query request including a user identifier and an operator, and the operator indicates the virtual IP address corresponding to the query user identifier. The third-party authentication system parses the query request to obtain the user identifier and the operator. The third-party authentication system performs the query operation indicated by the operator based on the user identifier, thereby obtaining the virtual IP address corresponding to the user identifier.
[0221] S212: During the authorization process of the terminal, the security protection system sends a first virtual IP address to the terminal.
[0222] In some embodiments, the security protection system generates an authentication response based on the first virtual IP address. The security protection system sends the authentication response to the terminal. The authentication response is a response message corresponding to the authentication request. The authentication response includes the first virtual IP address. Because the authentication response carries the first virtual IP address, the security protection system simultaneously sends the virtual IP address to the terminal while feeding back the identity authentication result. In some embodiments, the authentication response also includes a string indicating that the terminal has passed identity authentication.
[0223] In some embodiments in which the security protection system issues the first virtual IP address, when the identity authentication method adopted by the security protection system for the terminal includes SDP authentication, the authentication response carrying the first virtual IP address includes a response message in the SDP authentication interaction process. For example, the authentication request initiated by the terminal includes an SDP authentication request, and the security protection system generates an SDP authentication response corresponding to the SDP authentication request. The security protection system sends the SDP authentication response corresponding to the SDP authentication request to the terminal, and the SDP authentication response includes the first virtual IP address.
[0224] In some embodiments in which the security protection system issues the first virtual IP address, the authentication request sent by the terminal includes an HTTP request message, the security protection system generates an HTTP response message corresponding to the HTTP request message, and the security protection system sends an HTTP response message corresponding to the HTTP request message to the terminal. The response body in the HTTP response message carries the first virtual IP address. Optionally, the HTTP response message also includes a string indicating that the terminal has passed identity authentication. The message format of the response body is, for example, extensible markup language (XML), JavaScript object notation (JSON), or protocol buffers (protobuf).
[0225] As an example, the security protection system uses SDP authentication to authenticate the terminal. The authentication request initiated by the terminal includes an SDP authentication request, which includes an HTTP request message. The security protection system sends an SDP authentication response corresponding to the SDP authentication request to the terminal. The SDP authentication response is the HTTP response message. The response body in the SDP authentication response carries the first virtual IP address.
[0226] As a specific example of the security protection system issuing the first virtual IP address, the security protection system sends an HTTP response message to the terminal. The content of the HTTP response message is as follows.
[0227] HTTP / 1.1 200OK indicates that the security protection system as the server has successfully processed the terminal's authentication request and returned an authentication response. Content-Type:application / json indicates that the data type of the authentication response message body is in JSON format. "status code":"0000" indicates a custom status code, indicating that the terminal has successfully passed SDP authentication. "message":"success" indicates that the security protection system has successfully found the virtual IP address corresponding to the user identifier. token is a token generated by the security protection system and is used for subsequent identity authentication and session management. "vIP":"vIP":"192.168.20.11" indicates that the first virtual IP address is 192.168.20.11.
[0228] In some embodiments in which the security protection system issues the first virtual IP address, the authentication request sent by the terminal includes an HTTPS request message, the security protection system generates an HTTPS response message corresponding to the HTTPS request message, and the security protection system sends an HTTPS response message corresponding to the HTTPS request message to the terminal. The response body in the HTTPS response message carries the first virtual IP address. Optionally, the HTTPS response message also includes a character string indicating that the terminal has passed identity authentication.
[0229] In some embodiments where the security protection system issues the first virtual IP address, the authentication request sent by the terminal includes a TCP-SYN message, and the security protection system generates a synchronize-acknowledgement (SYN-ACK) message corresponding to the TCP-SYN message, where the SYN-ACK message includes the first virtual IP address. For example, the first virtual IP address is carried in a TCP option of the SYN-ACK message. The security protection system sends a SYN-ACK message including the first virtual IP address to the terminal.
[0230] In some other embodiments of the security protection system issuing the first virtual IP address, when the identity authentication method used by the security protection system for the terminal includes SPA authentication, the authentication response carrying the first virtual IP address includes a response message in the SPA authentication interaction process. For example, the authentication request initiated by the terminal includes an SPA authentication request, the security protection system generates an SPA authentication response message corresponding to the SPA authentication request, and the security protection system sends the SPA authentication response message corresponding to the SPA authentication request to the terminal, where the SPA authentication response message includes the first virtual IP address.
[0231] In some further implementations of the security protection system issuing the first virtual IP address, the authentication request sent by the terminal includes a RADIUS authentication message, and the security protection system sends a RADIUS response message corresponding to the RADIUS authentication message to the terminal, where the RADIUS response message carries the first virtual IP address.
[0232] In some further implementations of the security protection system issuing the first virtual IP address, the authentication request sent by the terminal includes an LDAP authentication request message, and the authentication response sent by the security protection system to the terminal includes an LDAP authentication response message, which carries the first virtual IP address.
[0233] In some further implementations of the security protection system issuing the first virtual IP address, the authentication request sent by the terminal includes an IKE negotiation message, and the authentication response sent by the security protection system to the terminal includes an IKE negotiation response message, which carries the first virtual IP address.
[0234] The protocol types of the messages used by the security protection system to send the first virtual IP address listed above are only exemplary. The protocol type of the message used to send the first virtual IP address is, for example, any protocol type that matches the protocol type of the authentication request initiated by the terminal.
[0235] In some embodiments, during the terminal authorization process, the security protection system sends the terminal a first virtual IP address and a list of resources that the security protection system authorizes the user to access. For the definition and explanation of the resource list, please refer to the description of the resource list in the SDP authorization process above. Since the first virtual IP address and the resource list are sent to the terminal together, this is equivalent to sending two types of resources to the terminal simultaneously through a single authorization process: one type of resource is the virtual IP address of the access subject (terminal), and the other type of resource is the identifier of the access object (network application and SDP gateway).
[0236] In some embodiments where the first virtual IP address and the resource list are sent together to the terminal, the security protection system encapsulates the first virtual IP address and the resource list into the same message, thereby obtaining a message including the first virtual IP address and the resource list. The security protection system sends the message including the first virtual IP address and the resource list to the terminal, so that the terminal can obtain both the first virtual IP address and the resource list from the received message.
[0237] In some embodiments where the first virtual IP address and the resource list are sent to the terminal together, the security protection system encapsulates the first virtual IP address, the identifier of the network application that the security protection system authorizes the user to access, and the identifier of the server providing the network application into the same message, thereby obtaining a message including the first virtual IP address, the identifier of the network application, and the identifier of the server providing the network application. The security protection system sends the message including the first virtual IP address, the identifier of the network application, and the identifier of the server to the terminal.
[0238] In some embodiments of sending the first virtual IP address and the resource list together to the terminal, the security protection system encapsulates the first virtual IP address, the identifier of the network application that the security protection system authorizes the user to access, the identifier of the server that provides the network application, the IP address of the network device that can access the network application (such as the SDP gateway), and the port number of the network device that can access the network application (such as the SDP gateway) into the same message, thereby obtaining a message including the first virtual IP address, the identifier of the network application, the identifier of the server, the IP address of the network device, and the port number of the network device. The security protection system sends a message including the first virtual IP address, the identifier of the network application, the identifier of the server, the IP address of the network device, and the port number of the network device to the terminal.
[0239] For the message type including the first virtual IP address, the identifier of the network application, the identifier of the server, the IP address of the network device, and the port number of the network device, please refer to the examples of various types of messages carrying the first virtual IP address above. For example, the message including the first virtual IP address, the identifier of the network application, the identifier of the server, the IP address of the network device, and the port number of the network device is an SDP authentication response message or an SPA authentication response message, such as an HTTP response message, an HTTPS response message, a SYN-ACK message, or a RADIUS response message.
[0240] As a specific example of the message content sent by a security protection system to a terminal during the authorization process, the security protection system sends an HTTP response message to the terminal. The HTTP response message includes a first virtual IP address and a resource list. The content of the HTTP response message is shown below.
[0241] By parsing the content of the above HTTP response message, the terminal can determine that when it needs to access the network application named patent management system, the terminal must encapsulate the virtual IP address 192.168.20.1 into the access request and send the access request including the virtual IP address 192.168.20.11 to the port number 8443 of the SDP gateway with IP address 10.19.10.100, so as to access the patent management system with the domain name www.mypatent.com through the SDP gateway with IP address 10.19.10.100. When accessing a network application named online game is required, the terminal will encapsulate the virtual IP address 192.168.20.1 into the access request, and send the access request including the virtual IP address 192.168.20.11 to the port 5060 of the SDP gateway with IP address 10.19.20.200, so as to access the online game with IP address 192.168.0.1 through the SDP gateway with IP address 10.19.20.200.
[0242] S214, during the authorization process of the terminal, the terminal receives a first virtual IP address from the security protection system.
[0243] In some embodiments, the terminal receives an authentication response (such as an SDP authentication response or an SPA authentication response message) from the security protection system. The terminal parses the authentication response and obtains the first virtual IP address carried in the authentication response. For example, the terminal receives an HTTP response message. The terminal parses the response body in the HTTP response message and obtains the first virtual IP address carried in the response body. For example, the terminal receives an HTTPS response message. The terminal parses the response body in the HTTPS response message and obtains the first virtual IP address carried in the response body.
[0244] S216: The terminal generates a first message based on the first virtual IP address.
[0245] The first message includes the first virtual IP address. For example, the terminal encapsulates the first virtual IP address into the first message, so that the security protection system can obtain the first virtual IP address from the first message, and then encapsulates the first virtual IP address into the source IP address field and sends it to the server.
[0246] The protocol type of the first message includes multiple cases. In some embodiments, the first message is an HTTP message. For example, the first message is an HTTP connect request message. In other embodiments, the first message is an HTTP get message, an HTTP post message, or an HTTP put message. In other embodiments, the first message is an HTTPS message. In other embodiments, the first message is a TCP-SYN message. In still other embodiments, the first message is a secure shell (SSH) message, a TELNET message, or a file transfer protocol (FTP) message.
[0247] The carrying location of the first virtual IP address in the first message includes multiple implementations. In some embodiments, the first message includes an application layer message header, and the application layer message header in the first message carries the first virtual IP address. For example, the first message includes an HTTP header. The HTTP header includes the first virtual address. For example, the HTTP header includes an X-Forwarded-For field, and the first virtual IP address is carried in the X-Forwarded-For field in the HTTP header. For another example, the first message includes an HTTPS header, and the HTTPS header includes the first virtual address. For example, the HTTPS header includes an X-Forwarded-For field. The first virtual IP address is carried in the X-Forwarded-For field in the HTTPS header.
[0248] In some embodiments, an encrypted tunnel is established between the terminal and the security protection system, and the first message also includes a tunnel header for establishing the encrypted tunnel. For example, the tunnel header includes an HTTPS header. For example, the tunnel header includes an SSL / TLS tunnel header. Optionally, the first virtual IP address is carried in the message in the inner layer of the tunnel header in the first message. For example, the first message includes an IP basic header encapsulated in the inner layer of the tunnel header, and the first virtual IP address is carried in the source IP address field in the IP basic header in the inner layer of the tunnel header. For another example, the first message includes a TCP header encapsulated in the inner layer of the tunnel header, and the first virtual IP address is carried in the TCP options in the TCP header in the inner layer of the tunnel header. In other embodiments, the first virtual IP address is carried in the tunnel header. For example, the first virtual IP address is carried in the HTTP header included in the tunnel header. For another example, the first virtual IP address is carried in the TCP options in the TCP header included in the tunnel header.
[0249] In some embodiments, the first message is a data message (also called a service message). For example, the first message includes not only the first virtual IP address but also first service data. The first service data is service data to be transmitted by the terminal to the network application. Because the first message includes the first virtual IP address and the first service data, the security protection system is triggered to forward the first service data to the network application using the first virtual IP address as the source IP address.
[0250] When the first message is a data message, the first virtual IP address is, for example, encapsulated in an outer layer of the first service data. For example, the first message includes a payload field, and the payload field in the first message is used to carry the first service data. The payload field in the first message is, for example, encapsulated in an inner layer of an application layer message header or an IP basic header that carries the first virtual IP address.
[0251] In some embodiments, the first message is a control message (also called control signaling). For example, the first message includes not only the first virtual IP address, but also the first instruction. The first instruction is used to instruct the security protection system to establish a connection with the server that provides the network application. For example, the first instruction includes the string connect. Since the first message includes the first virtual IP address and the first instruction, the security protection system is triggered by the first instruction to establish a connection with the network application with the first virtual IP address as the source IP address, so that the business data from the terminal can be subsequently forwarded to the network application through the connection. For another example, the first message includes not only the first virtual IP address, but also the second instruction. The second instruction is used to instruct the security protection system to establish an encrypted tunnel with the terminal. Since the first message includes the first virtual IP address and the second instruction, the first virtual IP address can be passed to the security protection system during the process of establishing an encrypted tunnel between the security protection system and the terminal.
[0252] In some embodiments, the first message also includes an identifier of a server providing the network application to be accessed. For example, the first message also includes the IP address of the server providing the network application. In another example, the first message also includes the domain name of the server providing the network application. In another example, the first message also includes the URL of the server providing the network application. Optionally, the server identifier (e.g., the server's IP address) is carried in an application layer header of the first message. For example, the server identifier is carried in an HTTP header, HTTP request line, or HTTPS header of the first message. For example, the server identifier (e.g., the server's IP address) and the first virtual IP address are carried in the same application layer header of the first message. Optionally, the server's IP address is carried in the destination address field of the IP base header within the tunnel header of the first message. Alternatively, the server's IP address is carried in an HTTP header included in the tunnel header of the first message. Alternatively, the server's IP address is carried in an HTTP request line included in the tunnel header of the first message. The server identifier (e.g., the server's IP address) is optionally received by the terminal from the security protection system during the authorization process. The terminal encapsulates the server identifier and the first virtual IP address into the first message, so that the first message includes the server identifier and the first virtual IP address. Because the first message includes the server IP address and the first virtual IP address, the security protection system can forward the message from the terminal to the server using the first virtual IP address as the source IP address and the server IP address as the destination IP address.
[0253] In some embodiments, the first message also includes an identifier of a network device (such as an SDP gateway) that can access the network application. For example, the first message also includes the IP address of the network device (such as the SDP gateway) that can access the network application and the port number of the network device (such as the SDP gateway) that can access the network application. Optionally, the identifier of the network device is carried in the application layer message header of the first message. For example, the identifier of the network device is carried in the host field in the HTTP header of the first message. For another example, the IP address of the network device is carried in the destination IP address field of the IP basic header of the first message, and the port number of the network device is carried in the destination port number field in the transport layer protocol header of the first message. The IP address and port number of the network device that can access the network application are optionally received by the terminal from the security protection system during the authorization process. The terminal encapsulates the IP address of the network device that can access the network application, the port number of the network device that can access the network application, and the first virtual IP address into the first message, so that the first message includes the IP address of the network device that can access the network application, the port number of the network device that can access the network application, and the first virtual IP address. Therefore, the first message can be forwarded to the network device that can access the network application based on the IP address of the network device and the port number of the network device.
[0254] In an exemplary application scenario for generating a first message, the terminal displays the icon of a network application. The user triggers a click operation on the icon of the network application. In response to the click operation on the icon of the network application, the terminal searches the resource list for the IP address of the server corresponding to the network application, the IP address of the network device that can access the network application, and the port number of the network device that can access the network application based on the icon of the network application. The terminal encapsulates the first virtual IP address, the IP address of the server, the IP address of the network device, and the port number of the network device into the first message, thereby obtaining the first message. As a specific example, in response to the click operation on the icon of an online game, the terminal searches the resource list for the IP address of the server corresponding to the online game, which is 192.168.0.1, the IP address of the network device that can access the network application is 10.19.20.200, and the port number of the network device that can access the network application is 5060 based on the icon of the online game. The terminal encapsulates the first virtual IP address 192.168.20.11, the IP address 192.168.0.1 of the server, the IP address 10.19.20.200 of the network device, and the port number 5060 of the network device into the first message, thereby obtaining the first message.
[0255] S218: The terminal sends a first message to the security protection system.
[0256] For example, the terminal carries the first virtual IP address in the XFF field in the HTTP header of the first message. In the case where the first message carries the first virtual IP address through another field other than the XFF field in the HTTP header or another message header, the terminal may carry the first virtual IP address in another field other than the XFF field in the HTTP header or another message header.
[0257] S220: The security protection system receives a first message from the terminal.
[0258] In some embodiments, the security protection system includes a network device (such as an SDP gateway). After the security protection system determines that the terminal has passed authentication, the security protection system opens a port on the network device that the terminal has permission to access (such as the port number of the network device that can access the network application in the resource list), and the network device receives the first message through the port.
[0259] S222: The security protection system obtains a second message based on the first message.
[0260] The second message refers to the message sent by the security protection system to the server when interacting with the server under the triggering of the first message. The source IP address of the second message includes the first virtual IP address. For example, the second message includes an IP basic header. The source IP address field in the IP basic header in the second message carries the first virtual IP address. Since the source address of the second message carries the first virtual IP address, it is possible to determine the user accessing the server based on the first virtual IP address, thereby achieving traceability. In some embodiments, the first virtual IP address carried in the source IP address field in the second message is obtained by the security protection system parsing the content of a specific field of the first message. For example, the security protection system parses the application layer message header in the first message to obtain the first virtual IP address carried in the application layer message header in the first message.
[0261] In other embodiments, the second message is a control message. For example, the second message includes a third instruction, and the third instruction is used to instruct the server to establish a connection with the security protection system. For example, the second message is a TCP-SYN message.
[0262] There are multiple implementations for how the security protection system processes and obtains the second message. The following describes how to obtain the second message with examples combining several implementations.
[0263] Implementation method for obtaining the second message: 1. The security protection system uses the first virtual IP address to replace the source IP address originally carried in the first message.
[0264] In some embodiments, the first message itself includes an IP basic header, and the security protection system uses the first virtual IP address to replace the contents of the source IP address field in the IP basic header of the first message to obtain the second message. For example, the source IP address field in the IP basic header of the first message received by the security protection system carries the real IP address of the terminal. The security protection system uses the first virtual IP address to replace the real IP address of the terminal in the source IP address field in the IP basic header of the first message, so that the contents of the source IP address field in the IP basic header of the first message are updated from the real IP address of the terminal to the first virtual IP address. Therefore, when the first message is forwarded through the security protection system, the source IP address of the first message can be transformed from the IP address of the first network to the IP address of the second network.
[0265] In some embodiments, the security protection system further replaces the contents of the destination IP address field in the IP basic header of the first message with the IP address of the server providing the network application to obtain the second message. For example, the destination IP address field in the IP basic header of the first message received by the security protection system carries the IP address of the security protection system. The security protection system replaces the IP address of the security protection system carried in the destination IP address field with the IP address of the server, thereby updating the contents of the destination IP address field in the IP basic header of the first message from the IP address of the security protection system to the IP address of the server. Therefore, when the first message is forwarded through the security protection system, the destination IP address of the first message can also be changed from the IP address of the first network to the IP address of the second network.
[0266] This embodiment does not limit the order in which the security protection system replaces the source IP address and the destination IP address when forwarding the first message. For example, the security protection system first uses the first virtual IP address to replace the source IP address in the first message, and then uses the server's IP address to replace the destination IP address in the first message; or, the security protection system first uses the server's IP address to replace the destination IP address in the first message, and then uses the first virtual IP address to replace the source IP address in the first message.
[0267] In some embodiments, the second message is a data message. The second message includes first service data to be transmitted by the terminal to the network application. The first service data carried in the second message, for example, comes from the payload field of the first message. For example, when the first message is a data message, the security protection system does not need to change or parse the contents of the payload field in the first message during the process of forwarding the first message. Instead, it replaces the source IP address and destination IP address in the outer layer of the payload field, so that the obtained second message also includes the first service data.
[0268] In some embodiments, the first message also includes a tunnel header for establishing an encrypted tunnel between the terminal and the security protection system. The security protection system decapsulates the tunnel header carried by the first message and replaces the source IP address of the IP basic header encapsulated in the inner layer of the tunnel header with the first virtual IP address to obtain the second message. Alternatively, the security protection system decapsulates the portion of the tunnel header of the first message excluding the IP basic header and replaces the source IP address of the IP basic header contained in the tunnel header with the first virtual IP address to obtain the second message.
[0269] Implementation method 2 for obtaining the second message: the security protection system decapsulates the IP basic header in the first message, and recapsulates the IP basic header whose source IP address is the first virtual IP address.
[0270] In some embodiments, the first message itself includes a first basic IP header. The security protection system decapsulates the first basic IP header in the first message and generates a second basic IP header based on the first virtual IP address. The source IP address field in the second basic IP header includes the first virtual IP address. The security protection system encapsulates the newly generated second basic IP header into the first message, thereby obtaining a second message.
[0271] Implementation method three for obtaining the second message: the security protection system saves the first virtual IP address, and when subsequently receiving a message from the terminal, the security protection system uses the saved first virtual IP address to replace the source IP address in the subsequently received message.
[0272] For example, the security protection system saves the first virtual IP address and the parameters of the first session to a session relationship. The session relationship includes a correspondence between the first virtual IP address and the parameters of the first session. The session relationship may be, for example, an entry or a combination of multiple entries in a session table stored by the security protection system.
[0273] The first session is a session established between the terminal and the security protection system. The first message belongs to the first session. For example, the first message is the first message in the first session.
[0274] The parameters of the first session are used to identify the first session. The parameters of the first session are, for example, obtained by the security protection system from the first message. In some embodiments, the parameters of the first session include the IP address of the terminal and the IP address of the security protection system (the IP address of the network device that can access the network application). In some embodiments, the parameters of the first session include a quintuple of the first session. The quintuple of the first session includes the IP address of the terminal, the IP address of the network device that can access the network application, the port number of the terminal, the port number of the network device that can access the network application, and a first protocol identifier, which identifies the transport layer protocol used for communication between the terminal and the network device. In still other embodiments, the parameters of the first session include information carried in the application layer message of the first message. For example, the parameters of the first session include the session ID of the first session. Because the parameters of the first session are stored in the session relationship, the security protection system can determine whether a subsequently received message is a subsequent message in the first session based on a match between the subsequently received message and the parameters of the first session.
[0275] In some embodiments, the security system also saves parameters for the second session to the session relationship. The second session is a session established between a network device capable of accessing a network application and a server. In some embodiments, the parameters for the second session include a first virtual IP address and the IP address of the server providing the network application. In some embodiments, the parameters for the second session include a quintuple for the second session. The quintuple for the second session includes the first virtual IP address, the IP address of the server providing the network application, the IP address of the network device capable of accessing the network application, the port number of the network device capable of accessing the network application, the port number of the network device capable of accessing the network application, and a second protocol identifier, which identifies the transport layer protocol used for communication between the network device capable of accessing the network application and the server. In still other embodiments, the parameters for the second session include information carried in the application layer message of the first message. For example, the parameters for the second session include the session ID of the second session. Because the parameters for the second session are saved in the session relationship, the security system can determine whether a subsequently received message is a subsequent message in the second session based on a match between the subsequently received message and the parameters of the second session.
[0276] Optionally, the session relationship adopts a key-value pair format. When forwarding subsequent outbound messages from the terminal, the parameters of the first session are the key in the session relationship, and the parameters of the second session are the value corresponding to the key in the session relationship. When forwarding subsequent return messages from the server, the parameters of the second session are the key in the session relationship, and the parameters of the first session are the value corresponding to the key in the session relationship.
[0277] In one example of obtaining a second message, after the security protection system saves the first virtual IP address and parameters of the first session to the session relationship based on the first message, the security protection system subsequently receives a first data message. In response to determining that the parameters of the first session are present in the subsequently received first data message, the security protection system determines that the first data message is a message in the first session, and then the security protection system replaces the source IP address in the first data message with the first virtual IP address to obtain the second message. For example, the security protection system matches the source IP address of the first data message with the IP address of the endpoint of the first session in the session relationship, and matches the destination IP address of the first data message with the IP address of the security protection system in the first session in the session relationship. In response to the source IP address of the first data message matching the IP address of the endpoint of the first session in the session relationship and the destination IP address of the first data message matching the IP address of the security protection system in the first session in the session relationship, the security protection system obtains the first virtual IP address from the session relationship and replaces the source IP address in the first data message with the first virtual IP address to obtain the second message.
[0278] Implementation method 4 for obtaining the second message: The security protection system obtains the IP address of the server providing the network application from the first message. The security protection system generates a second message using the first virtual IP address as the source IP address and the server's IP address as the destination IP address. The second message is a TCP-SYN message, which is used to request the server to establish a TCP connection between the server and the security protection system.
[0279] S224: The security protection system sends a second message to the server.
[0280] Since the source IP address field in the IP basic header in the second message carries the first virtual IP address, the first virtual IP address is the IP address (intranet IP address or trusted IP address) in the network (second network) where the server is located. Therefore, when the second message is transmitted between the security protection system and the server, when the intermediate node between the security protection system and the server forwards the second message, the intermediate node can determine that the second message comes from a trusted device, thereby improving the success rate of forwarding the second message between the security protection system and the server.
[0281] S226: The server generates a third message based on the second message.
[0282] The third message is a return message corresponding to the second message. In some embodiments, when the second message is a data message, the server parses the payload field of the second message to obtain the first service data carried by the payload field. The server executes the service corresponding to the network application based on the first service data to obtain the second service data. The server generates a third message based on the first virtual IP address and the second service data. The third message includes the second service data. The destination IP address of the third message includes the first virtual IP address.
[0283] For example, the third message includes an IP basic header, an application layer message header, and a payload field. The source IP address field in the IP basic header of the third message carries the IP address of the server (the IP address in the second network). The destination IP address field in the IP basic header of the third message carries the first virtual IP address. The payload field in the third message includes the second service data. The payload field is encapsulated within the inner layer of the IP basic header and the application layer message header.
[0284] As a specific example of the message encapsulation format in the message interaction process between a terminal, a security protection system and a server, the first message sent by the terminal includes an IP basic header whose source IP address is the real IP address of the terminal, an HTTPS header containing a first virtual IP address, and an HTTP request message encapsulated in the inner layer of the HTTPS header. The second message sent by the security protection system includes an IP basic header whose source IP address is the first virtual IP address and an HTTP request message encapsulated in the inner layer of the IP basic header. The third message sent by the server includes an IP basic header whose destination IP address is the first virtual IP address and an HTTP response message encapsulated in the inner layer of the IP basic header. The HTTP response message includes an HTTP header and a payload field, and the payload field includes the second business data. The payload field is encapsulated in the inner layer of the IP basic header and the HTTP header.
[0285] In some embodiments, when the second message is a control message, the server performs a corresponding operation based on the instruction carried in the control message. For example, the second message is a TCP-SYN message, and the server establishes a TCP connection with the security protection system based on the TCP-SYN message.
[0286] S228, the server sends a third message to the security protection system.
[0287] S230: The security protection system receives a third message from the server.
[0288] S232: The security protection system obtains a fourth message based on the IP address of the terminal and the third message.
[0289] The fourth message refers to the message sent by the security protection system to the terminal when interacting with the terminal under the trigger of the third message. The source IP address of the fourth message includes the IP address of the security protection system, and the destination IP address of the fourth message includes the IP address of the terminal. The fourth message includes the second business data. For example, the fourth message includes an IP basic header and a payload field, and the destination IP address field in the IP basic header of the fourth message carries the IP address of the terminal. The source IP address field in the IP basic header of the fourth message carries the IP address of the security protection system (the IP address of the network device that can access the network application). The payload field in the fourth message includes the second business data.
[0290] There are multiple implementations for how the security protection system processes and obtains the fourth message. The following describes the method of obtaining the fourth message with examples in combination with several implementations.
[0291] Implementation method for obtaining the fourth message: 1. The security protection system replaces the destination IP address originally carried in the third message with the IP address of the terminal.
[0292] In some embodiments, the third message itself includes an IP basic header, and the security protection system replaces the contents of the destination IP address field in the IP basic header in the third message with the IP address of the terminal to obtain a fourth message. For example, the destination IP address field in the IP basic header in the third message received by the security protection system carries a first virtual IP address, and the security protection system replaces the first virtual IP address with the IP address of the terminal so that the contents of the destination IP address field in the IP basic header in the third message are updated from the first virtual IP address to the IP address of the terminal. Considering that the first virtual IP address may not be directly applicable to the forwarding of the return message (the third message), the security protection system replaces the destination IP address from the first virtual IP address to the IP address of the terminal so that the message can be routed and forwarded to the terminal based on the IP address of the terminal.
[0293] In some embodiments, the security protection system also uses the IP address of the security protection system to replace the content of the source IP address field in the IP basic header of the third message to obtain a fourth message. For example, the source IP address field in the IP basic header of the third message received by the security protection system carries the IP address of the server providing the network application. The security protection system uses the IP address of the security protection system to replace the IP address of the server providing the network application carried in the source IP address field, so that the content of the source IP address field in the IP basic header of the third message is updated from the IP address of the server to the IP address of the security protection system. Since the security protection system performs the action of replacing the source IP address when forwarding the third message, the source IP address of the third message can be changed from the IP address of the second network to the IP address of the first network after passing through the security protection system. Therefore, when the message is subsequently forwarded in the first network, the IP address of the second network (intranet IP) is hidden.
[0294] This embodiment does not limit the order in which the security protection system replaces the destination IP address when forwarding the third message and the time sequence of replacing the destination IP address. For example, the security protection system first uses the IP address of the terminal to replace the destination IP address in the third message, and then uses the IP address of the security protection system to replace the source IP address in the third message; or, the security protection system first uses the IP address of the security protection system to replace the source IP address in the third message, and then uses the IP address of the terminal to replace the destination IP address in the third message.
[0295] In some embodiments, the fourth message is a data message. The fourth message includes first service data to be transmitted by the terminal to the network application. The first service data carried in the fourth message, for example, comes from the payload field of the third message. For example, when the third message is a data message, the security protection system does not need to change or parse the contents of the payload field in the third message during the process of forwarding the third message. Instead, it replaces the destination IP address and the destination IP address in the outer layer of the payload field. As a result, the obtained fourth message also includes the first service data.
[0296] In some embodiments, the fourth message also includes a tunnel header for establishing an encrypted tunnel between the terminal and the security protection system. For example, the security protection system encapsulates the tunnel header into the third message to obtain the fourth message. Optionally, the security protection system first replaces the source and destination IP addresses of the third message, and then encapsulates the tunnel header into the third message with both the updated source and destination IP addresses.
[0297] Regarding the way in which the security protection system obtains the terminal IP address when replacing the destination IP address in the third message, in some embodiments, the security protection system parses the destination IP address field in the IP basic header in the third message to obtain the first virtual IP address carried in the destination IP address field. The security protection system searches for the session relationship based on the first virtual IP address to obtain the IP address of the terminal corresponding to the first virtual IP address. In some embodiments, the security protection system uses the source IP address of the third message and the destination IP address of the third message to match the parameters of the second session in the session relationship. In response to the source IP address of the third message matching the destination IP address of the second session in the session relationship (the IP address of the server) and the destination IP address of the third message matching the source IP address of the second session in the session relationship (the first virtual IP address), the security protection system determines that the third message belongs to the return message of the second session, and therefore the security protection system obtains the IP address of the terminal corresponding to the first virtual IP address in the session relationship, so as to replace the destination IP address of the third message based on the IP address of the terminal.
[0298] Implementation method 2 for obtaining the fourth message: the security protection system decapsulates the IP basic header in the third message, and recapsulates the IP basic header whose destination IP address is the IP address of the terminal.
[0299] In some embodiments, the security protection system decapsulates the IP basic header originally included in the third message. The security protection system generates an IP basic header based on the IP address of the terminal. The source IP address field of the IP basic header is the IP address of the security protection system, and the destination IP address field of the IP basic header is the IP address of the terminal. The security protection system encapsulates the newly generated IP basic header into the third message from which the original IP basic header has been removed, thereby obtaining a fourth message.
[0300] S234: The security protection system sends a fourth message to the terminal.
[0301] The method provided in this embodiment associates a user identifier with a virtual IP address. When a terminal accesses a network application through a security protection system, the source IP address in the message sent by the security protection system to the server providing the network application is the virtual IP address corresponding to the user identifier. This ensures that the source IP address sent to the server is strongly bound to the user, thereby reducing the difficulty of tracing the user who initiated the access based on the source IP address of the message. In addition, because the virtual IP address corresponding to the user identifier is the IP address in the network where the server is located (such as an intranet IP), there is no need to configure a corresponding return route on the server for the real IP address of each terminal on the Internet, thereby reducing the complexity of configuring the return route.
[0302] S240, the audit and tracing system determines the user identifier based on the first virtual IP address and performs tracing.
[0303] The audit and tracing system searches for the correspondence between the user identifier and the virtual IP address based on the first virtual IP address, obtains the user identifier corresponding to the first virtual IP address, and then locates the specific user based on the user identifier. It is therefore possible to determine which user initiated access to the network application, thereby achieving auditing and tracing.
[0304] In one example of traceability, the audit traceability system searches Table 3 based on the virtual IP address 192.168.20.11 to obtain the user ID User 1, thereby determining that User 1 initiated access to the network application. In another example, the audit traceability system searches Table 3 based on the virtual IP address 540b:843c:1:a::101 to obtain the user ID User 3, thereby determining that User 3 initiated access to the network application.
[0305] Optionally, the audit and tracing system adopts multiple replaceable implementation methods to obtain the first virtual IP address to achieve tracing. For example, in some embodiments, the security protection system sends part of the messages passing through the security protection system to the audit and tracing system according to a predetermined sampling rate or configured forwarding conditions. For example, the security protection system communicates with the audit and tracing system through an out-of-band management interface, and the security protection system sends part of the messages passing through the security protection system to the audit and tracing system through the out-of-band management interface. For example, the security protection system copies part of the messages passing through the security protection system to obtain a mirror message, and the security protection system sends the mirror message to the audit and tracing system so that the audit and tracing system obtains the first virtual IP address carried in the source IP address field in the mirror message and thus performs tracing based on the first virtual IP address. In other embodiments, the audit and tracing system is deployed in the second network, and the audit and tracing system captures business messages, obtains the first virtual IP address from the source IP address field in the captured business messages, and thus performs tracing based on the first virtual IP address.
[0306] In some further embodiments, a probe (also called a traffic collection device) generates a log based on a business message or a mirror message of a business message, and the probe sends the log to an audit and tracing system. The log includes a five-tuple of the business message transmitted in the second network (for example, the second message in the embodiment of Figure 2). The five-tuple includes the source IP address, source port number, destination IP address, destination port number and transport layer protocol number. The source IP address is the first virtual IP address. The audit and tracing system obtains the first virtual IP address from the log, thereby tracing the source based on the first virtual IP address.
[0307] Regarding the deployment location of the probe, in some embodiments, the probe is deployed inside the second network. For example, the probe is connected to the inlet switch in the second network shown in Figure 1, or the probe is hung next to the switch. In the process of forwarding business messages to the server 120 at the back end of the switch, the switch copies part or all of the business messages passing through the switch to obtain mirror messages, and the switch sends the mirror messages to the probe. In other embodiments, the probe is integrated inside the inlet switch in the second network shown in Figure 1. In other embodiments, the probe is connected to the network device 131 in the security protection system shown in Figure 1, or the probe is integrated inside the network device 131 in the security protection system.
[0308] In other embodiments, the network device 131 in the security protection system is, for example, an IPS device. The network device 131 in the security protection system generates an alarm during message forwarding and sends the alarm to the audit and tracing system. The alarm includes a quintuple of the service message transmitted in the second network (for example, the second message in the embodiment of FIG. 2 ) and alarm information, and the source IP address in the quintuple is the first virtual IP address. The audit and tracing system obtains the first virtual IP address from the alarm, and thus performs tracing based on the first virtual IP address.
[0309] Referring to Figure 3, Figure 3 shows a schematic diagram of accessing a network application in an SDP zero-trust scenario provided by an embodiment of the present application. The security protection system 130 shown in Figure 1 includes the SDP gateway and SDP controller shown in Figure 3. The terminal 110 shown in Figure 1 includes the SDP client shown in Figure 3. The server 120 shown in Figure 1 is used to provide the B / S application 1, C / S application 1 or C / S application 2 in Figure 3. Figure 3 is a specific example of applying the method shown in Figure 2 to the SDP zero-trust scenario.
[0310] In some embodiments, the SDP gateway and the SDP controller are implemented in a separate manner. The SDP gateway and the SDP controller are different physical devices that communicate with each other. For example, the SDP gateway is located in a general network device such as a router, switch or firewall, or a dedicated network device, and the SDP controller is located in a server that communicates with the network device, and the server implements the function of the SDP controller by running software that supports the SDP control and management plane functions. In other embodiments, the SDP gateway and the SDP controller are implemented in a combined manner, and the SDP gateway and the SDP controller are integrated into the same physical device. The following embodiment of Figure 5 describes the process using the case where the SDP gateway and the SDP controller are separately provided as an example. When the SDP gateway and the SDP controller are implemented in a combined manner, the following steps performed by the SDP gateway and the steps performed by the SDP controller are all performed by the device integrated with the SDP gateway and the SDP controller. For example, when the SDP controller is integrated on the SDP gateway, the following steps performed by the SDP controller are actually performed by the SDP gateway.
[0311] Referring to Figure 4, a schematic diagram of the structure of an SDP gateway is shown. Optionally, the network device 131 in Figure 1 has the structure shown in Figure 4. Optionally, the SDP gateway in Figure 3 has the structure shown in Figure 4.
[0312] The SDP gateway includes an external network interface, an HTTPS tunnel header decapsulation module, a source IP replacement module A, a destination IP replacement module A, an intranet sending module, an intranet reply module, a destination IP replacement module B, a source IP replacement module B, an HTTPS tunnel header encapsulation module, and an intranet interface. The external network interface is connected to a first network. The external network interface is used to communicate with a terminal. The intranet interface is connected to a second network. The intranet interface is used to communicate with a server.
[0313] The HTTPS tunnel header decapsulation module, source IP replacement module A, destination IP replacement module A and intranet sending module are all located on the forwarding path of the outbound message. The HTTPS tunnel header decapsulation module, source IP replacement module A, destination IP replacement module A and intranet sending module are used to forward the message from the SDP client to the server. When the external network interface receives the message from the SDP client, the HTTPS tunnel header decapsulation module decapsulates the HTTPS tunnel header in the data message. The message in the inner layer of the HTTPS tunnel header is sent to the source IP replacement module A. The source IP replacement module A replaces the source IP address of the data message with the first virtual IP address. The destination IP replacement module A replaces the destination IP address in the data message with the IP address of the server. The intranet sending module sends the message with the source IP replaced and the destination IP replaced to the server through the intranet interface.
[0314] The HTTPS tunnel header encapsulation module, destination IP replacement module B, source IP replacement module B, and intranet packet return module are all located on the forwarding path of the return message. The HTTPS tunnel header encapsulation module, destination IP replacement module B, source IP replacement module B, and intranet packet return module are used to forward the message from the server to the SDP client. When the intranet interface receives a message from the server, the intranet packet return module sends the received message to the destination IP replacement module B. The destination IP replacement module B replaces the destination IP address in the data message with the IP address of the SDP client. The source IP replacement module B replaces the source IP address in the data message with the IP address of the SDP gateway. The HTTPS tunnel header encapsulation module encapsulates the HTTPS tunnel header into the message after the source IP and destination IP are replaced. The external network interface sends the encapsulated message to the server.
[0315] Referring to Figure 5 , Figure 5 further illustrates the method for accessing intranet applications in the scenario illustrated in Figure 3 using a sequential interaction diagram. The process illustrated in Figure 5 is a specific embodiment of the method illustrated in Figure 2 in the SDP Zero Trust scenario. In the embodiment illustrated in Figure 5 , User 1, User 2, and User 3 are all specific examples of user identifiers, 192.168.20.11 is a specific example of the virtual IP address assigned to User 1, and the correspondence between user identifiers and virtual IP addresses is a specific example of a target correspondence.
[0316] Step S510: The SDP controller receives the correspondence between the user identifier and the virtual IP address configured by the network administrator.
[0317] Since the correspondence between the user identifier and the virtual IP address is configured, it is convenient to trace the source based on the virtual IP address carried in the message and the correspondence between the user identifier and the virtual IP address during the subsequent message forwarding process.
[0318] In some implementations, the SDP controller performs step S510 during the SDP registration process. For example, the SDP controller receives the identifier of at least one user with access rights to the network application input by the network administrator during the process of receiving the user identifier list configured by the network administrator.
[0319] Step S520: The third-party authentication system saves the correspondence between the user identifier and the virtual IP address.
[0320] Since the correspondence between the user identifier and the virtual IP address is stored through a dedicated authentication system, the SDP controller does not need to store the correspondence between the user identifier and the virtual IP address, thereby saving storage resources occupied by the correspondence between the user identifier and the virtual IP address on the SDP controller.
[0321] Step S520 is an optional step and is not shown in Figure 5. In other implementations, step S520 is omitted, and the SDP controller saves the correspondence between the user identifier and the virtual IP address.
[0322] Step S530: The SDP client generates a SPA authentication request.
[0323] Step S532: The SDP client sends an SPA authentication request to the SDP controller.
[0324] Step S534: The SDP controller receives the SPA authentication request.
[0325] Step S536: The SDP controller authenticates the SDP client based on the SPA authentication request.
[0326] Step S540 : In response to the SDP client passing the SPA authentication, the SDP controller sends an authentication interface to the SDP client.
[0327] The authentication interface is used for SDP authentication. For example, the SDP controller sends a JavaScript file or HTML file to the SDP client. The SDP client parses the JavaScript file or HTML file through the browser to obtain the login page code. The SDP client then renders the authentication interface in the browser based on the login page code, thereby displaying the authentication interface.
[0328] Step S541: The SDP client receives the authentication interface and displays the authentication interface.
[0329] Step S542: The SDP client receives the first user identifier input on the authentication interface.
[0330] Step S543: The SDP client generates an SDP authentication request based on the first user identifier, where the SDP authentication request includes the first user identifier.
[0331] Step S544: Send an SDP authentication request to the SDP controller.
[0332] Step S545: The SDP controller receives the SDP authentication request.
[0333] Step S546: The SDP controller performs SDP authentication on the SDP client based on the SDP authentication request.
[0334] For example, the SDP controller obtains the first user identifier carried in the SDP authentication request, and performs a consistency check based on the first user identifier and a second user identifier pre-stored by the SDP controller. If the consistency check passes, the SDP controller determines that the SDP client has passed the SDP authentication.
[0335] Step S550 : In response to the SDP client passing the authentication, the SDP controller obtains a first virtual IP address based on the user identifier during the authorization process of the SDP client.
[0336] Regarding the manner in which the SDP controller obtains the user identifier, in some implementations, the SDP controller parses the authentication request message, thereby obtaining the user identifier carried in the authentication request message.
[0337] The following describes two ways in which the SDP controller obtains the first virtual IP address.
[0338] Method 1 for the SDP controller to obtain the first virtual IP address: When step S510 is used, the SDP controller searches for the correspondence between the user identifier and the virtual IP address based on the user identifier to obtain the first virtual IP address. For example, if the user identifier carried in the authentication request message is User 1, the SDP controller searches for the correspondence between the user identifier and the virtual IP address shown in Table 3 based on User 1 to obtain the virtual IP address 192.168.20.11. For another example, if the user identifier carried in the authentication request message is User 3, the SDP controller searches for the correspondence between the user identifier and the virtual IP address shown in Table 3 based on User 3 to obtain the virtual IP addresses 192.168.5.101 and 540b:843c:1:a::101.
[0339] The second way for the SDP controller to obtain the first virtual IP address is that when step S520 is adopted, the SDP controller obtains the virtual IP address by communicating with a third-party authentication system. In some embodiments, the SDP controller receives the correspondence between the user identifier and the virtual IP address sent by the third-party authentication system. In other embodiments, the SDP controller sends a query request carrying the user identifier to the third-party authentication system. In response to the query request, the third-party authentication system queries the correspondence between the user identifier and the virtual IP address based on the user identifier, obtains the first virtual IP address corresponding to the user identifier, and the third-party authentication system sends the first virtual IP address to the SDP controller. The SDP controller receives the first virtual IP address from the third-party authentication system, thereby obtaining the first virtual IP address. For example, the user identifier carried in the authentication request message is User 1, and the SDP controller sends a query request carrying User 1 to the third-party authentication system. In response to the query request, the third-party authentication system queries the correspondence between the user identifier and the virtual IP address based on User 1, and obtains the first virtual IP address corresponding to User 1 as 192.168.20.11. The third-party authentication system sends the first virtual IP address 192.168.20.11 to the SDP controller.
[0340] Step S552: The SDP controller sends an SDP authentication response to the SDP client, where the SDP authentication response includes the first virtual IP address.
[0341] For example, the SDP controller allocates the first virtual IP address as a resource to the SDP client, and the resource is used for the SDP client to access the intranet application. In another example, the SDP controller allocates the first virtual IP address as a token or part of a token to the SDP client, so as to use the first virtual IP address to perform security verification on the user.
[0342] For example, in the process of the SDP controller authorizing the SDP client logged in with the account User 1, the SDP authentication response sent by the SDP controller to the SDP client includes the first virtual IP address 192.168.20.11.
[0343] For example, the SDP authentication request is an HTTP request message, and the SDP controller sends an HTTP response message corresponding to the HTTP request message to the SDP client. The response body in the HTTP response message carries the first virtual IP address.
[0344] Since the SDP controller obtains and sends the first virtual IP address to the SDP client based on the results of SPA authentication and SDP authentication, it is equivalent to combining the three functions of SPA authentication, SDP authentication, and IP address allocation. This allows clients that have passed SPA authentication and SDP authentication to obtain virtual IP addresses, reducing the security risks posed by devices that have not been SPA-authenticated and SDP-authenticated to network applications based on virtual IP addresses, thereby increasing network security. In addition, since the virtual IP address is sent to the SDP client identified by the logged-in user, the SDP client using the virtual IP address is associated with the user identity, making it easier to trace the source. In addition, the SDP controller centrally controls and manages the virtual IP addresses used to access the intranet server, thereby improving scalability. It can be seen that the address allocation process executed by the SDP controller helps to replace DHCP and become the next generation of address allocation technology.
[0345] In some implementations, the SDP controller simultaneously sends the first virtual IP address and the resource list to the SDP client. Since the SDP controller also sends the first virtual IP address in addition to sending the resource list during the authorization process, this is equivalent to authorizing both the source IP address (the first virtual IP address) and the destination IP address (the server's IP address) relied upon by the accessed network application to the SDP client, further improving the SDP authorization process.
[0346] In some embodiments, the SDP authentication response includes the first virtual IP address and the resource list. The SDP controller sends the SDP authentication response carrying the first virtual IP address and the resource list to the SDP client. Because the first virtual IP address and the resource list are transmitted in a single message, transmission overhead is reduced compared to a method in which the first virtual IP address and the resource list are sent to the SDP client in separate messages.
[0347] In some embodiments, if the SDP controller determines that the SDP client fails SPA authentication or SDP authentication, the SDP controller denies the SDP client access to the SDP gateway, and the SDP controller does not need to execute the steps of obtaining a first virtual IP address based on the user identifier and issuing the first virtual IP address to the SDP client. Since the SDP controller only issues the virtual IP address to the SDP client when both SPA authentication and SDP authentication are passed, the SDP controller will not issue the virtual IP address to the SDP client when either SPA authentication or SDP authentication fails, thereby further improving the security of the virtual IP address and reducing the security risk to the intranet caused by the virtual IP address being stolen by an attacker.
[0348] Step S554: The SDP client receives an SDP authentication response from the SDP controller, where the SDP authentication response includes the first virtual IP address.
[0349] The SDP client parses the SDP authentication response and obtains the first virtual IP address carried in the SDP authentication response.
[0350] Step S560: During the process of establishing an encrypted tunnel between the SDP client and the SDP gateway, the SDP client generates an HTTP connect message based on the virtual IP address issued by the SDP controller during the authorization process.
[0351] The HTTP connect message includes an IP basic header, a TCP header, a request line, and an HTTP header. The IP basic header includes a source IP address field and a destination IP address field. The source IP address field includes the IP address of the SDP client. The destination IP address field includes the IP address of the SDP gateway. For example, when the SDP client and the SDP gateway communicate based on the IPv4 protocol, the IP basic header in the HTTP connect message is an IPv4 basic header, the source IP address field in the IPv4 basic header includes the IPv4 address of the SDP client, and the destination IP address field in the IPv4 basic header includes the IPv4 address of the SDP gateway. For another example, when the SDP client and the SDP gateway communicate based on the IPv6 protocol, the IP basic header in the HTTP connect message is an IPv6 basic header, the source IP address field in the IPv6 basic header includes the IPv6 address of the SDP client, and the destination IP address field in the IPv6 basic header includes the IPv6 address of the SDP gateway.
[0352] The TCP header is encapsulated within the IP header. The TCP header includes source and destination port fields. The source port field in the TCP header includes the port number of a first port, which is the port used by the SDP client to communicate with the SDP gateway. The destination port field includes the port number of a second port, which is the port used by the SDP gateway to communicate with the SDP client.
[0353] The HTTP header is encapsulated within the TCP header. The HTTP header includes an XFF field. The XFF field contains the virtual IP address assigned to the user. Because the XFF field carries the virtual IP address assigned to the user, the SDP gateway can obtain the virtual IP address from the XFF field and access intranet applications based on this virtual IP address. For example, the SDP gateway can use this virtual IP address to replace the source IP address in a message and send the message with the replaced source IP address to the server providing the intranet application.
[0354] The HTTP request line is encapsulated within the HTTP header. It includes a request method field and a server identifier field. The request method field includes the string "connect." The server identifier field in the HTTP request line carries the identifier of the server to be accessed by the SDP client.
[0355] For example, in a scenario where the SDP client accesses an intranet application based on an IP address, the HTTP request line is used to carry the IP address of the server that provides the intranet application. The SDP gateway can obtain the IP address of the server based on the HTTP request line field, so the SDP gateway can determine which specific server in the intranet to forward the message from the SDP client to based on the server's IP address, and replace the destination IP address in the message from the SDP client with the IP address of the server. Optionally, the HTTP request line also carries the port number of a third port. The third port is the port in the server used to communicate with the SDP gateway. Based on the port number of the third port, the SDP gateway can determine which port in the server in the intranet to forward the message from the SDP client to, and which port number to use to replace the destination port number in the message from the SDP client.
[0356] For example, when an SDP client accesses an intranet application based on a domain name, the HTTP request line carries the domain name of the server providing the intranet application, such as the server URL. The SDP gateway obtains the server domain name based on the HTTP request line fields. The SDP gateway then obtains the server IP address based on the server domain name through DNS resolution. The SDP gateway then accesses the server using the server IP address obtained through DNS.
[0357] For example, please refer to Figure 3. In the scenario shown in Figure 3, the IP address of the SDP client is 10.19.30.123, the port number of the port in the SDP client used to communicate with the SDP gateway is 4567, the IP address of the SDP gateway is 10.19.10.100, the port number of the port in the SDP gateway used to communicate with the SDP client is 8443, the IP address of the server providing intranet applications in the intranet is 192.168.10.100, and the port number of the port in the server used to communicate with the SDP gateway is 80.
[0358] The HTTP connect message contains the following content.
[0359] CONNECT tcp: / / 192.168.10.100:80HTTP / 1.1
[0360] Host:10.19.10.100:8443
[0361] Cookies:
[0362] SDP SESSIONID=9d952a05dd3a4d66bcd6929f452dc496;
[0363] app_id=163025c0264e472e97b4fddc09339a48
[0364] X-Forwarder-For:192.168.20.11
[0365] Regarding the meaning of the HTTP connect message above, the HTTP request line includes CONNECT tcp: / / 192.168.10.100:80HTTP / 1.1. CONNECT defines the request method, requesting a tunnel connection between the SDP gateway and the server providing the network application. 192.168.10.100:80 indicates that the IP address of the server to which the SDP gateway is connecting is 192.168.10.100, and the port number of the server to which the SDP gateway is connecting is 80. HTTP / 1.1 indicates that the HTTP protocol version used is HTTP / 1.1. Because the HTTP request line field carries CONNECT tcp: / / 192.168.10.100:80HTTP / 1.1, the SDP gateway can determine that it needs to use the HTTP / 1.1 protocol to establish a connection with port 80 of the server with IP address 192.168.10.100:80. In this way, it can subsequently forward the message from the SDP client to port 80 of the server with IP address 192.168.10.100:80, replace the destination IP address in the message from the SDP client with 192.168.10.100, and replace the destination port number in the message from the SDP client with 80.
[0366] The Host field is used to indicate the host to which the access subject is to connect and the port of the host to which the access subject is to connect. For example, the Host field is used to carry the address of the host to be connected and the port number of the port of the host to be connected. In the above example, the SDP client is the access subject, and the host to which the SDP client is to connect is the SDP gateway. Therefore, the SDP client writes the IP address of the SDP gateway (10.19.10.100) and the port number of the SDP gateway (8443) in the Host field, so that the content of the Host field includes 10.19.10.100:8443.
[0367] The Cookie field is used to convey session status. SDP Zero Trust scenarios involve sessions established between the SDP client and the SDP gateway, as well as sessions established between the SDP gateway and the server. To distinguish these two sessions, the following uses "first session" to describe the session between the SDP client and the SDP gateway, and "second session" to describe the session between the SDP gateway and the server.
[0368] The SDP SESSIONID field is used to carry the identifier of the first session. In the above example, the identifier of the first session is the string 9d952a05dd3a4d66bcd6929f452dc4. Because the SDP SESSIONID field carries the identifier of the first session, the SDP gateway can obtain the identifier of the first session based on the SDP SESSIONID field, establish the first session based on the identifier of the first session, and maintain the status of the first session based on the identifier of the first session.
[0369] The app_id field is used to carry the identifier of the second session. In the above example, the identifier of the second session is 163025c0264e472e97b4fddc09339a48. Since the app_id field carries the identifier of the second session, the SDP gateway can establish the second session based on the identifier of the second session and maintain the state of the second session based on the identifier of the second session. In some embodiments, the SDP gateway saves the correspondence between the identifier of the first session and the identifier of the second session in the session table, thereby associating the two sessions. Therefore, based on the association between the two sessions, the return message from the server can be forwarded to the SDP client, and the destination IP address in the return message can be restored from the virtual IP address to the real IP address of the SDP client.
[0370] The X-Forwarder-For field carries the virtual IP address 192.168.20.11. The SDP gateway can determine to use the virtual IP address 192.168.20.11 to replace the source IP address in the message from the SDP client.
[0371] In Figure 3, the string 10.19.30.123:4567->10.19.10.100:8443 means that the source IP address field in the IP basic header includes the SDP client's IP address 10.19.30.123, and the destination address field in the IP basic header includes the SDP gateway's IP address 10.19.10.100. The TCP header includes source and destination port numbers. The source port number field includes the SDP client's port number 4567, and the destination port number field includes the SDP gateway's port number 8443.
[0372] Step S562: The SDP client sends an HTTP connect message including the first virtual IP address to the SDP gateway.
[0373] The SDP client sends an HTTP connect message containing the first virtual IP address to the SDP gateway, thereby triggering the SDP gateway to establish a tunnel between the SDP client and the SDP gateway, and allowing the SDP gateway to obtain the first virtual IP address.
[0374] In step S564, the SDP gateway receives the HTTP connect message from the SDP client and obtains the virtual IP address carried in the HTTP connect message.
[0375] For example, the SDP gateway parses the XFF field in the HTTP connect message to obtain the virtual IP address carried in the XFF field. The SDP gateway extracts the virtual IP address from the HTTP connect message so that it can subsequently access the server in the intranet using the virtual IP address as the source IP address.
[0376] In some embodiments, after the SDP gateway receives the HTTP connect message, the SDP gateway also establishes an HTTS tunnel between the SDP gateway and the SDP client based on the IP address of the SDP client, the IP address of the SDP gateway, the port number of the SDP client, and the port number of the SDP gateway. The HTTS tunnel is used to encrypt and transmit data between the SDP client and the SDP gateway. The endpoints of the HTTS tunnel include the SDP gateway and the SDP client.
[0377] In step S565, the SDP gateway saves the virtual IP address to the session relationship.
[0378] The session relationship includes the correspondence between the virtual IP address and the IP address of the SDP client. For example, the session relationship is an entry or a combination of multiple entries in the session table stored by the SDP gateway. The IP address of the SDP client in the session relationship is the real IP address of the terminal running the SDP client. For example, the SDP client IP address is obtained by the SDP gateway from the source IP address field in the IP basic header of the HTTP connect message. The virtual IP address is obtained by the SDP gateway from the XFF field in the HTTP connect message.
[0379] The purpose of the session relationship includes forwarding the return message from the server to the SDP client and forwarding the subsequent message of the HTTP connect message from the SDP client to the server. Specifically, since the SDP gateway saves the correspondence between the virtual IP address and the IP address of the SDP client, when the SDP gateway receives the return message from the server, the SDP gateway searches for the correspondence between the virtual IP address and the IP address of the SDP client based on the virtual IP address carried in the return message, and can obtain the IP address of the SDP client, thereby forwarding the return message to the terminal based on the IP address of the SDP client. When the SDP gateway receives the subsequent message of the HTTP connect message from the SDP client, the SDP gateway searches for the correspondence between the IP addresses of the SDP client based on the IP address of the SDP client carried in the subsequent message, and can obtain the virtual IP address, thereby replacing the source IP address in the subsequent message based on the virtual IP address, and forwarding the subsequent message with the source IP address replaced with the virtual IP address to the server.
[0380] In some embodiments, the session relationship also includes the IP address of the server. The IP address of the server is obtained by the SDP gateway from the HTTP request line in the HTTP connect message, for example. Since the SDP gateway saves the correspondence between the virtual IP address, the IP address of the server, and the IP address of the SDP client, when the SDP gateway receives a return message from the server, the SDP gateway searches for the virtual IP address, the IP address of the server, and the IP address of the SDP client based on the virtual IP address carried in the return message and the IP address of the server, and can obtain the IP address of the SDP client, thereby forwarding the return message to the terminal based on the IP address of the SDP client. When the SDP gateway receives a subsequent message of the HTTP connect message from the SDP client, the SDP gateway searches for the virtual IP address, the IP address of the server, and the IP address of the SDP client based on the IP address of the SDP client and the IP address of the server carried in the subsequent message, and can obtain the virtual IP address, thereby replacing the source IP address in the subsequent message based on the virtual IP address, and forwarding the subsequent message with the source IP address replaced with the virtual IP address to the server. In addition, in the scenario where multiple servers are deployed in the intranet, the SDP gateway also uses the server's IP address when looking up session relationships, so it can distinguish sessions corresponding to different servers. Therefore, it can more flexibly and accurately process return messages from multiple servers and outbound messages sent to different servers.
[0381] In some implementations, the session relationship stored by the SDP gateway further includes the IP address of the SDP gateway. The IP address of the SDP gateway is, for example, obtained by the SDP gateway from the Host field in the HTTP connect message.
[0382] In some embodiments, the session relationship stored by the SDP gateway includes parameters of the first session and parameters of the second session. The parameters of the first session include the IP address of the SDP client and the IP address of the SDP gateway. The parameters of the second session include the virtual IP address and the IP address of the server.
[0383] As a specific example, in the scenario shown in FIG. 3 , the session relationship is shown in Table 4 below.
[0384] Table 4 Session relations
[0385] In other embodiments, the parameters of the first session in the session relationship saved by the SDP gateway include the quintuple of the first session. The parameters of the second session include the quintuple of the second session. The quintuple of the first session includes the IP address of the SDP client, the IP address of the SDP gateway, the port number of the SDP client, the port number of the SDP gateway, and a first protocol identifier, where the first protocol identifier is used to identify the transport layer protocol based on which the communication between the SDP client and the SDP gateway is based. The quintuple of the second session includes the first virtual IP address, the IP address of the server, the port number of the server, the port number of the SDP gateway, and a second protocol identifier, where the second protocol identifier is used to identify the transport layer protocol based on which the communication between the SDP gateway and the server is based. The port number of the SDP client is optionally carried by the source port number field in the TCP header of the HTTP connect message. The port number of the SDP gateway is optionally carried by the destination port number field in the TCP header of the HTTP connect message. As a specific example, in the scenario shown in Figure 3, the session relationship is shown in Table 5 below.
[0386] Table 5 Session relations
[0387] Optionally, the session relationship stored by the SDP gateway further includes an identifier of the first session. The identifier of the first session is, for example, obtained by the SDP gateway from an SDP SESSIONID field in an HTTP header in an HTTP connect message.
[0388] Optionally, the session relationship stored by the SDP gateway further includes an identifier of the second session. The identifier of the second session is, for example, obtained by the SDP gateway from an app_id field in an HTTP header in an HTTP connect message.
[0389] In step S570, the SDP client generates a first data message and sends the first data message to the SDP gateway through the HTTPS tunnel.
[0390] The first data message is equivalent to a subsequent message of the HTTP connect message. The first data message is a message in the first session established based on the HTTP connect message. The source IP address of the first data message includes the real IP address of the SDP client (such as an IP address on the Internet or an IP address provided by a public WLAN network accessed by the SDP client). The destination IP address of the first data message includes the IP address of the SDP gateway. For example, the source IP address of the first data message includes the IP address 10.19.30.123. The destination IP address of the first data message includes 10.19.10.100.
[0391] In some embodiments, the first data packet includes an IP header, a TCP header, an HTTPS header, an application layer header, and a payload field. The HTTPS header carries parameters for establishing an HTTPS tunnel between the SDP client and the SDP gateway. The source address field in the IP header includes the real IP address of the SDP client. The destination address field in the IP header includes the IP address of the network device. The TCP header is encapsulated within the IP header. The source port number field in the TCP header includes the port number of the SDP client. The destination port number field in the TCP header includes the port number of the SDP gateway. The HTTPS header includes an HTTP header and a TLS / SSL header. The TLS / SSL header is encapsulated within the TCP header. The TLS / SSL header carries an identifier of the encryption algorithm, a certificate, and an identifier of the message integrity check algorithm. The HTTP header is encapsulated within the TLS / SSL header. The application layer header is, for example, an HTTPS header or an HTTP header. The application layer header includes the IP address of the intranet server. In some embodiments, the application layer header includes the virtual IP address of the SDP client. For example, the application layer header includes an HTTP header, and the XFF header in the HTTP header includes the virtual IP address of the SDP client. The payload field is encapsulated in the inner layer of the application layer header and is used to carry the first service data to be transmitted from the SDP client to the network application.
[0392] In step S572, the SDP gateway receives a first data packet from the SDP client and replaces the source IP address of the first data packet based on the first virtual IP address, thereby obtaining a second data packet.
[0393] Step S574: The SDP gateway sends a second data message to the server.
[0394] In some embodiments, the SDP gateway replaces the source IP address in the IP header of the received first data packet with the first virtual IP address from the real IP address of the SDP client, so that the source IP address in the IP header of the second data packet sent by the SDP gateway to the intranet server is the first virtual IP address. For example, the SDP gateway replaces the content of the source IP address field in the IP header of the first data packet from the IP address 10.19.30.123 of the SDP client to the first virtual IP address 192.168.20.11, and the content of the source IP address field in the IP header of the second data packet sent by the SDP client to the server is the first virtual IP address 192.168.20.11.
[0395] In some embodiments, the SDP gateway replaces the destination IP address in the IP basic header of the first data packet received from the SDP gateway with the IP address of the intranet server, so that the destination IP address in the IP basic header of the second data packet sent by the SDP gateway to the intranet server is the IP address of the intranet server. For example, the SDP gateway replaces the content of the destination IP address field in the IP basic header of the first data packet received in the future from the SDP gateway's IP address 10.19.10.100 with the server's IP address 192.168.10.100, and the content of the destination IP address field in the IP basic header of the second data packet sent by the SDP client to the server is the server's IP address 192.168.10.100.
[0396] In some embodiments, when the first data packet includes an HTTPS header encapsulated in an outer layer of an application layer header, the SDP gateway further decapsulates the outer HTTPS header in the first data packet. Decapsulating the outer HTTPS header is equivalent to terminating the HTTPS tunnel between the SDP client and the SDP gateway, allowing the SDP gateway to obtain the application layer header and payload field encapsulated in the inner layer of the HTTPS header, so as to forward the second data packet including the application layer header and payload field to the server.
[0397] How the SDP gateway obtains the first virtual IP address when forwarding a data message includes the following implementation method 1 and implementation method 2.
[0398] In the first implementation method in which the SDP gateway obtains the first virtual IP address, when the application layer header of the first data packet carries the first virtual IP address, the SDP gateway parses the application layer header of the first data packet, thereby obtaining the first virtual IP address carried by the application layer header, so as to send the second data packet to the intranet server with the first virtual IP address as the destination IP address.
[0399] In the second implementation method in which the SDP gateway obtains the first virtual IP address, when the application layer header of the first data packet carries the first virtual IP address, the SDP gateway obtains the parameters of the first session carried by the first data packet, and the SDP gateway searches for the session relationship based on the parameters of the first session to obtain the first virtual IP address corresponding to the parameters of the first session.
[0400] Taking the example of searching for a session relationship based on the source IP address and the destination IP address of the first session, and in conjunction with the specific example provided in Table 4, the SDP gateway matches the source IP address carried in the IP basic header of the first data packet with the IP address 10.19.30.123 of the SDP client in the session relationship, and the SDP gateway matches the destination IP address carried in the IP basic header of the first data packet with the IP address 10.19.10.100 of the SDP gateway in the session relationship. In response to the source IP address carried in the IP basic header of the first data packet and the IP address 10.19.30.123 of the SDP client in the session relationship meeting the matching condition, and the destination IP address carried in the IP basic header of the first data packet and the IP address 10.19.10.100 of the SDP gateway in the session relationship meeting the matching condition, the SDP gateway obtains the first virtual IP address 192.168.20.11 from the session relationship.
[0401] Taking the five-tuple search for the session relationship based on the first session as an example, combined with the specific example provided in Table 5, the SDP gateway matches the source IP address carried in the IP basic header of the first data packet with the IP address 10.19.30.123 of the SDP client in the session relationship, the SDP gateway matches the destination IP address carried in the IP basic header of the first data packet with the IP address 10.19.10.100 of the SDP gateway in the session relationship, the SDP gateway matches the source port number carried in the TCP header of the first data packet with the port number 4567 of the SDP client in the session relationship, and the SDP gateway matches the destination port number carried in the TCP header of the first data packet with the port number 8443 of the SDP gateway in the session relationship. The SDP gateway matches the transport layer protocol identifier carried in the first data packet with the first protocol identifier TCP in the session relationship. In response to the fact that the source IP address carried by the IP basic header of the first data packet meets the matching condition with the IP address 10.19.30.123 of the SDP client in the session relationship, and the destination IP address carried by the IP basic header of the first data packet meets the matching condition with the IP address 10.19.10.100 of the SDP gateway in the session relationship, and the source port number carried by the TCP header of the first data packet meets the matching condition with the port number 4567 of the SDP client in the session relationship, and the destination port number carried by the TCP header of the first data packet meets the matching condition with the port number 8443 of the SDP gateway in the session relationship, and the transport layer protocol identifier carried by the first data packet meets the matching condition with the first protocol identifier TCP in the session relationship, the SDP gateway obtains the first virtual IP address 192.168.20.11 from the session relationship.
[0402] How the SDP gateway obtains the IP address of the intranet server when forwarding data packets includes the following implementation methods: 1 and 2.
[0403] In the first implementation method in which the SDP gateway obtains the IP address of the intranet server, when the application layer header of the first data packet carries the IP address of the intranet server, the SDP gateway parses the application layer header of the first data packet, thereby obtaining the IP address of the intranet server carried in the application layer header, so as to send the second data packet to the intranet server with the IP address of the intranet server as the destination IP address.
[0404] In the second implementation method in which the SDP gateway obtains the IP address of the intranet server, when the application layer message header of the first data message carries the IP address of the intranet server, the SDP gateway obtains the parameters of the first session carried by the first data message, and the SDP gateway searches for the session relationship based on the parameters of the first session to obtain the IP address of the intranet server corresponding to the parameters of the first session.
[0405] Taking the example of searching for a session relationship based on the source IP address and the destination IP address of the first session, combined with the specific example provided in Table 4, the SDP gateway matches the source IP address carried in the IP basic header of the first data packet with the IP address 10.19.30.123 of the SDP client in the session relationship, and the SDP gateway matches the destination IP address carried in the IP basic header of the first data packet with the IP address 10.19.10.100 of the SDP gateway in the session relationship. In response to the source IP address carried in the IP basic header of the first data packet and the IP address 10.19.30.123 of the SDP client in the session relationship meeting the matching condition, and the destination IP address carried in the IP basic header of the first data packet and the IP address 10.19.10.100 of the SDP gateway in the session relationship meeting the matching condition, the SDP gateway obtains the IP address 192.168.10.100 of the intranet server from the session relationship.
[0406] Taking the five-tuple search for the session relationship based on the first session as an example, combined with the specific example provided in Table 5, the SDP gateway matches the source IP address carried in the IP basic header of the first data packet with the IP address 10.19.30.123 of the SDP client in the session relationship, the SDP gateway matches the destination IP address carried in the IP basic header of the first data packet with the IP address 10.19.10.100 of the SDP gateway in the session relationship, the SDP gateway matches the source port number carried in the TCP header of the first data packet with the port number 4567 of the SDP client in the session relationship, and the SDP gateway matches the destination port number carried in the TCP header of the first data packet with the port number 8443 of the SDP gateway in the session relationship. The SDP gateway matches the transport layer protocol identifier carried in the first data packet with the first protocol identifier TCP in the session relationship. In response to the fact that the source IP address carried by the IP basic header of the first data packet meets the matching condition with the IP address 10.19.30.123 of the SDP client in the session relationship, and the destination IP address carried by the IP basic header of the first data packet meets the matching condition with the IP address 10.19.10.100 of the SDP gateway in the session relationship, and the source port number carried by the TCP header of the first data packet meets the matching condition with the port number 4567 of the SDP client in the session relationship, and the destination port number carried by the TCP header of the first data packet meets the matching condition with the port number 8443 of the SDP gateway in the session relationship, and the transport layer protocol identifier carried by the first data packet meets the matching condition with the first protocol identifier TCP in the session relationship, the SDP gateway obtains the IP address 192.168.10.100 of the intranet server from the session relationship.
[0407] Step S575: The server receives the second data packet from the SDP gateway.
[0408] The above description focuses on the SDP gateway's forwarding process for outbound messages. Because the SDP gateway replaces the source IP address of the data message carrying the first service data with a virtual IP address on the intranet, it can pass the first service data from the SDP client to the server. From the server's perspective, the server treats the first service data as coming from the virtual IP address on the intranet, eliminating the need to perceive the data message's actual origin from the external IP address, thereby simplifying return routing. The following example illustrates the forwarding process for the return message.
[0409] Step S576: The server obtains a third data packet based on the second data packet.
[0410] Step S577: The server sends a third data message to the SDP gateway.
[0411] The third data packet includes second service data to be transmitted by the server to the SDP client. The source IP address of the third data packet includes the IP address of the server. The destination IP address of the third data packet includes the first virtual IP address. In an exemplary scenario, after the server obtains the first service data from the SDP client based on the second data packet, the server transmits the third data packet to feed the second service data back to the SDP client, thereby meeting the requirements of an interactive service scenario. For example, the network application is a database application, and the first service data includes a query statement for target data in the database application. The server executes the query statement, searches the database for the target data, and carries the obtained target data in the third data packet to send to the SDP client.
[0412] Regarding the message encapsulation format of the third data message, the third data message illustratively includes an IP basic header, a transport layer protocol header, and a payload field. The source IP address field in the IP basic header includes the IP address of the server. The destination IP address field in the IP basic header includes the first virtual IP address. The source port number field in the transport layer protocol header includes the port number of the server. The destination port number field in the transport layer protocol header includes the port number of the SDP gateway. The payload field includes the second service data.
[0413] In some embodiments, the server parses the payload field in the second data packet to obtain the first service data from the SDP client. The server processes the first service data to obtain the second service data. The server parses the IP basic header in the second data packet to obtain the first virtual IP address. The server generates a third data packet based on the second service data and the first virtual IP address.
[0414] Step S579: The SDP gateway receives the third data message from the server and replaces the destination IP address of the third data message with the IP address of the SDP client to obtain a fourth data message.
[0415] The source IP address of the fourth data message includes the IP address of the SDP gateway. The destination IP address of the fourth data message includes the IP address (real IP address) of the SDP client. The fourth data message includes the second service data.
[0416] Since the source IP address of the uplink data message is replaced by the SDP gateway from the real IP address of the SDP client to the first virtual IP address, the server will return the return message with the first virtual IP address as the destination IP address. The SDP gateway replaces the destination IP address in the return message from the first virtual IP address to the IP address (real IP address) of the SDP client so as to transmit the second service data to the SDP client based on the IP address of the SDP client, thereby reducing the risk of interruption of the second service data transmission due to the unreachable routing of the first virtual IP address in the Internet.
[0417] In some implementations, the SDP gateway further replaces the source IP address carried in the third data packet with the IP address of the SDP gateway to obtain the fourth data packet.
[0418] In some implementations, the SDP gateway further replaces the source port number carried in the third data packet with the port number of the SDP gateway to obtain the fourth data packet.
[0419] In some implementations, the SDP gateway further replaces the destination port number carried in the third data packet with the port number of the SDP client to obtain a fourth data packet.
[0420] In some implementations, the SDP gateway further encapsulates an HTTPS header into the third data packet to obtain a fourth data packet.
[0421] Regarding the message encapsulation format of the fourth data message, illustratively, the fourth data message includes an IP basic header, a transport layer protocol header, an HTTPS header, and a payload field. The source IP address field in the IP basic header of the fourth data message includes the IP address of the SDP gateway. The destination IP address field in the IP basic header of the fourth data message includes the IP address of the SDP client. The source port number field in the transport layer protocol header includes the port number of the SDP gateway. The destination port number field in the transport layer protocol header includes the port number of the SDP client. The payload field includes the second service data.
[0422] This embodiment does not limit the order in which the SDP gateway replaces the source IP address and the destination IP address when forwarding the downlink data message. For example, the SDP gateway first replaces the source IP address in the downlink data message and then replaces the destination IP address in the downlink data message; or, the SDP gateway first replaces the destination IP address in the downlink data message and then replaces the source IP address in the downlink data message.
[0423] Regarding the manner in which the SDP gateway obtains the IP address of the SDP client while forwarding the downlink data packet, in some embodiments, the SDP gateway obtains the parameters of the second session carried in the third data packet. Based on the parameters of the second session, the SDP gateway searches the session relationship stored by the SDP gateway to obtain the parameters of the first session corresponding to the parameters of the second session, where the parameters of the first session include the IP address of the SDP client.
[0424] Taking the example of searching for a session relationship based on the source IP address and the destination IP address, for example, the session relationship includes the source IP address of the second session (the first virtual IP address), the destination IP address of the second session (the IP address of the server), and the source IP address of the first session (the IP address of the SDP client). The SDP gateway searches for the session relationship based on the source IP address (the IP address of the server) carried by the third data packet and the destination IP address (the first virtual IP address) carried by the third data packet, and obtains the source IP address of the first session corresponding to the source IP address (the IP address of the server) carried by the third data packet and the destination IP address (the first virtual IP address) carried by the third data packet, thereby obtaining the IP address of the SDP client.
[0425] In combination with the specific example provided in Table 4, for example, the IP basic header of the third data packet carries the source IP address 192.168.10.100, and the IP basic header of the third data packet carries the destination IP address 192.168.20.11. The SDP gateway uses the source IP address 192.168.10.100 of the third data packet to match the destination IP address (server IP address) 192.168.10.100 of the second session in the session relationship, and the SDP gateway uses the destination IP address 192.168.20.11 of the third data packet to match the source IP address (first virtual IP address) 192.168.20.11 of the second session in the session relationship. In response to the source IP address 192.168.10.100 of the third datagram matching the destination IP address 192.168.10.100 of the second session in the session relationship (the server's IP address), and the destination IP address 192.168.20.11 of the third datagram matching the source IP address 192.168.20.11 of the second session in the session relationship (the first virtual IP address), the SDP gateway obtains the source IP address 10.19.30.123 of the first session (the IP address of the SDP client) corresponding to the second session and the destination IP address 10.19.10.100 of the first session (the IP address of the SDP gateway). The SDP gateway replaces the destination IP address 192.168.20.11 carried in the third datagram with the source IP address 10.19.30.123 of the first session (the IP address of the SDP client). The SDP gateway replaces the source IP address 192.168.10.100 carried in the third data packet with the destination IP address 10.19.10.100 of the first session (the IP address of the SDP gateway), thereby obtaining a fourth data packet. The IP basic header of the fourth data packet carries the source IP address 10.19.10.100, and the IP basic header of the third data packet carries the destination IP address 10.19.30.123.
[0426] Taking the five-tuple-based search for session relations as an example, combined with the session relations provided in Table 5, for example, the session relations include the source IP address of the second session (the first virtual IP address), the destination IP address of the second session (the IP address of the server), the source port number of the second session (the port number of the SDP gateway), the destination port number of the second session (the port number of the server), the protocol identifier of the second session (the second protocol identifier), the source IP address of the first session (the IP address of the SDP client), the destination IP address of the first session (the IP address of the SDP gateway), the source port number of the first session (the port number of the SDP client), the destination port number of the first session (the port number of the SDP gateway), the protocol identifier of the first session (the first protocol identifier), and the SDP gateway Based on the source IP address (server's IP address) carried by the third data packet, the destination IP address (first virtual IP address) carried by the third data packet, the source port number (server's port number) carried by the third data packet, and the destination port number (SDP gateway's port number) carried by the third data packet, the session relationship is searched, thereby obtaining the source IP address of the first session corresponding to the source IP address (server's IP address) carried by the third data packet, the destination IP address (first virtual IP address) carried by the third data packet, the source port number (server's port number) carried by the third data packet, and the destination port number (SDP gateway's port number) carried by the third data packet, thereby obtaining the IP address of the SDP client.
[0427] Step S580: The SDP gateway sends a fourth data packet to the SDP client.
[0428] Step S581: The SDP client receives a fourth data packet from the SDP gateway and obtains the second service data carried in the fourth data packet.
[0429] In step S590, the audit and tracing system performs tracing based on the virtual IP address carried in the source IP address field of the message to be traced.
[0430] The method provided in this embodiment replaces the source IP address in the message from the SDP client with the virtual IP address of the user identifier by the SDP gateway in the SDP zero-trust scenario. The IP address sent by the SDP gateway to the intranet server corresponds to the user identifier, thereby realizing accurate traceability in remote or local network access scenarios.
[0431] Referring to Figure 6, Figure 6 shows a schematic structural diagram of a security protection system 600 provided in an embodiment of the present application. The security protection system 600 shown in Figure 6 is, for example, arranged between the terminal 110 and the server 120 shown in Figure 1. The security protection system 600 shown in Figure 6 is, for example, the security protection system 130 shown in Figure 1. The security protection system 600 shown in Figure 6 includes, for example, the controller 132 and the network device 131 in Figure 1. The security protection system 600 includes a receiving unit 610, a processing unit 620, and a sending unit 630.
[0432] In some embodiments, the security protection system 600 shown in Figure 6 is used to execute the steps performed by the security protection system in the method shown in Figure 2. The receiving unit 610 is used to execute S220; the processing unit 620 is used to execute S222; and the sending unit 630 is used to execute S224.
[0433] In some embodiments, the receiving unit 610 is further configured to execute the receiving steps in S206, S230, S510, S534, S545, S554, S564, and S572, and the receiving step in S579; the processing unit 620 is further configured to execute the message generation steps in S208, S210, S232, S536, S546, S550, S560, and S572, and the address replacement step in S579; the sending unit 630 is further configured to execute S234, S540, S212, S544, S552, S574, and S580. In some embodiments, the security protection system 600 further includes a storage unit configured to execute S565. In some embodiments, the security protection system 600 includes the SDP controller and SDP gateway shown in FIG. 3. In some embodiments, the security protection system 600 includes the SDP gateway shown in FIG. 4.
[0434] The device embodiment described in FIG6 is merely illustrative. For example, the division of the above units is merely a logical functional division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. The functional units in the various embodiments of the present application can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into a single unit.
[0435] Each unit in the security protection system 600 is implemented in whole or in part by software, hardware, firmware or any combination thereof.
[0436] The following describes some possible implementation methods of using hardware or software to implement each functional unit in the security protection system 600 in conjunction with the security protection system 800 described later.
[0437] In the case of software implementation, for example, the processing unit 620 is implemented by a software functional unit generated by at least one processor 801 in FIG. 8 reading a program code stored in the memory 802 .
[0438] In the case of hardware implementation, each unit in FIG6 is implemented by different hardware in security protection system 800. For example, processing unit 620 is implemented by a portion of the processing resources of at least one processor 801 in FIG8 (e.g., one or two cores in a multi-core processor), while processing unit 620 is implemented by the remaining processing resources of at least one processor 801 in FIG8 (e.g., other cores in a multi-core processor), or by a programmable device such as a field-programmable gate array (FPGA) or a coprocessor. Receiving unit 610 and sending unit 630 are implemented by network interface 803 in FIG8.
[0439] Referring to Figure 7, Figure 7 shows a schematic structural diagram of a terminal 700 provided in an embodiment of the present application. The terminal 700 shown in Figure 7 is, for example, provided in the system shown in Figure 1, and the terminal 700 shown in Figure 7 is, for example, the terminal 110 shown in Figure 1. The terminal 700 includes a sending unit 710, a receiving unit 720, and a processing unit 730. The sending unit 710 is used to execute S204, S218, S532, S544, and S562; the receiving unit 720 is used to execute S214, S534, S542, S554, and S581; the processing unit 730 is used to execute S202, S216, S530, S541, S543, S560, and S570; the sending unit 710 is also used to send a first message to the security protection system. In some embodiments, the terminal 700 includes the SDP client shown in Figure 3. In some embodiments, the terminal 700 also includes a display unit, and the display unit is used to execute S541.
[0440] The device embodiment described in FIG7 is merely illustrative. For example, the division of the above units is merely a logical functional division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. The functional units in the various embodiments of the present application can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into a single unit.
[0441] Each unit in the terminal 700 is implemented entirely or partially by software, hardware, firmware, or any combination thereof.
[0442] In conjunction with the terminal 900 described below, some possible implementations of the various functional units in the terminal 700 using hardware or software are described below.
[0443] In the case of software implementation, for example, the processing unit 730 is implemented by a software functional unit generated by at least one processor 901 in FIG. 9 reading a program code stored in the memory 902 .
[0444] In the case of hardware implementation, for example, the above-mentioned units in FIG7 are respectively implemented by different hardware in terminal 900. For example, processing unit 730 is implemented by a portion of the processing resources of at least one processor 901 in FIG9 (e.g., one or two cores in a multi-core processor), while processing unit 730 is implemented by the remaining processing resources of at least one processor 901 in FIG9 (e.g., other cores in a multi-core processor), or by a programmable device such as a field-programmable gate array (FPGA) or a coprocessor. Receiving unit 720 and sending unit 710 are implemented by network interface 903 in FIG9.
[0445] FIG8 is a schematic structural diagram of a safety protection system 800 provided in an embodiment of the present application.
[0446] The security protection system 800 shown in Figure 8 is, for example, arranged between the terminal 110 and the server 120 shown in Figure 1. The security protection system 800 shown in Figure 8 is, for example, the security protection system 130 shown in Figure 1. The security protection system 800 shown in Figure 8 includes, for example, the controller 132 and the network device 131 in Figure 1. The security protection system 800 includes at least one processor 801, a memory 802, and at least one network interface 803. In some embodiments, the security protection system 800 shown in Figure 8 is used to execute the steps performed by the security protection system in the method shown in Figure 2. The network interface 803 is used to execute S220; the processor 801 is used to execute S222; and the network interface 803 is used to execute S224.
[0447] In some embodiments, the network interface 803 is further configured to execute the receiving steps in S206, S230, S510, S534, S545, S554, S564, and S572, and the receiving step in S579; the processor 801 is further configured to execute the message generation steps in S208, S210, S232, S536, S546, S550, S560, and S572, and the address replacement step in S579; the network interface 803 is further configured to execute S234, S540, S212, S544, S552, S574, and S580. In some embodiments, the security protection system 800 further includes a storage unit configured to execute S565. In some embodiments, the security protection system 800 includes the SDP controller and SDP gateway shown in FIG3. In some embodiments, the security protection system 800 includes the SDP gateway shown in FIG4.
[0448] The processor 801 is, for example, a general-purpose central processing unit (CPU), a network processor (NP), a graphics processing unit (GPU), a neural-network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solution of the present application. For example, the processor 801 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0449] The memory 802 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. Optionally, the memory 802 exists independently and is connected to the processor 801 via an internal connection 804. Alternatively, the memory 802 and the processor 801 are optionally integrated together.
[0450] The network interface 803 uses any transceiver-like device for communicating with other devices or communication networks. For example, the network interface 803 includes at least one of a wired network interface and a wireless network interface. For example, the wired network interface is an Ethernet interface. For example, the Ethernet interface is an optical interface, an electrical interface, or a combination thereof. For example, the wireless network interface is a wireless local area network (WLAN) interface, a cellular network interface, or a combination thereof.
[0451] In some embodiments, the processor 801 includes one or more CPUs, such as CPU0 and CPU1 shown in FIG. 8 .
[0452] In some embodiments, security system 800 may optionally include multiple processors, such as processor 801 and processor 805 shown in FIG8 . Each of these processors may be, for example, a single-CPU or a multi-CPU. A processor herein may optionally refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0453] In some embodiments, security system 800 further includes internal connections 804. Processor 801, memory 802, and at least one network interface 803 are connected via internal connections 804. Internal connections 804 include pathways for transmitting information between these components. Optionally, internal connections 804 are boards or buses. Optionally, internal connections 804 are divided into address buses, data buses, control buses, and the like.
[0454] Optionally, the processor 801 implements the method in the above embodiment by reading the program code stored in the memory 802, or the processor 801 implements the method in the above embodiment by using the program code stored internally. In the case where the processor 801 implements the method in the above embodiment by reading the program code stored in the memory 802, the memory 802 stores the program code 810 that implements the method provided in the embodiment of the present application.
[0455] For more details on how the processor 801 implements the above functions, please refer to the descriptions in the previous method embodiments, which will not be repeated here.
[0456] FIG9 is a schematic structural diagram of a terminal 900 provided in an embodiment of the present application.
[0457] The terminal 900 shown in FIG. 9 is, for example, provided in the system shown in FIG. 1 . The terminal 900 shown in FIG. 9 is, for example, the terminal 110 shown in FIG. 1 .
[0458] Terminal 900 includes at least one processor 901, a memory 902, and at least one network interface 903. Network interface 903 is configured to execute S204, S218, S532, S544, S562, S214, S534, S542, S554, and S581; processor 901 is configured to execute S202, S216, S530, S541, S543, S560, and S570. In some embodiments, terminal 900 includes the SDP client shown in FIG. 3 .
[0459] The processor 901 is, for example, a general-purpose central processing unit (CPU), a network processor (NP), a graphics processing unit (GPU), a neural-network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solution of the present application. For example, the processor 901 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0460] The memory 902 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. Optionally, the memory 902 exists independently and is connected to the processor 901 via an internal connection 904. Alternatively, the memory 902 and the processor 901 are optionally integrated together.
[0461] The network interface 903 uses any transceiver-like device for communicating with other devices or communication networks. For example, the network interface 903 includes at least one of a wired network interface and a wireless network interface. For example, the wired network interface is an Ethernet interface. For example, the Ethernet interface is an optical interface, an electrical interface, or a combination thereof. For example, the wireless network interface is a wireless local area network (WLAN) interface, a cellular network interface, or a combination thereof.
[0462] In some embodiments, the processor 901 includes one or more CPUs, such as CPU0 and CPU1 shown in FIG. 9 .
[0463] In some embodiments, terminal 900 optionally includes multiple processors, such as processor 901 and processor 905 shown in FIG9 . Each of these processors is, for example, a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein optionally refers to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0464] In some embodiments, terminal 900 further includes internal connections 904. Processor 901, memory 902, and at least one network interface 903 are connected via internal connections 904. Internal connections 904 include pathways for transmitting information between the aforementioned components. Optionally, internal connections 904 are single boards or buses. Optionally, internal connections 904 are divided into address buses, data buses, control buses, and the like.
[0465] In some embodiments, the terminal 900 further includes an input / output interface 906 . The input / output interface 906 is connected to the internal connection 904 .
[0466] In some embodiments, the input / output interface 906 is configured to connect to an input device 907. The input / output interface 906 receives commands or data related to the embodiment of FIG. 2 or FIG. 5 , such as a first user identifier (e.g., a user name and / or password, biometrics, etc.), inputted by a user through the input device 907. Input devices include, but are not limited to, a keyboard, a touch screen, a microphone, a mouse, or a sensor device.
[0467] In some embodiments, the input / output interface 906 is further configured to connect to a display 908. The display 908 is configured to display an authentication interface.
[0468] Optionally, the processor 901 implements the method in the above embodiment by reading the program code stored in the memory 902, or the processor 901 implements the method in the above embodiment by internally stored program code. In the case where the processor 901 implements the method in the above embodiment by reading the program code stored in the memory 902, the memory 902 stores program code 910 that implements the method provided in the embodiment of the present application.
[0469] For more details on how the processor 901 implements the above functions, please refer to the descriptions in the previous method embodiments, which will not be repeated here.
[0470] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments.
[0471] A refers to B, which means that A is the same as B or A is a simple variant of B.
[0472] The terms "first" and "second" in the description and claims of the embodiments of this application are used to distinguish different objects, not to describe a specific order of objects, and should not be understood to indicate or imply relative importance. For example, the terms "first message" and "second message" are used to distinguish different messages, not to describe a specific order of messages, and should not be understood to mean that the first message is more important than the second message.
[0473] In the embodiments of the present application, unless otherwise specified, "at least one" means one or more, and "a plurality" means two or more. For example, a plurality of messages means two or more messages.
[0474] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in accordance with the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).
[0475] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for accessing a network application, characterized in that: Applied to a network system, the network system includes a terminal, a security protection system, and a server providing a network application, the terminal is deployed in a first network, the server is deployed in a second network, the security protection system is used to protect the security of the server, and the method includes: The security protection system receives a first message from the terminal, the first message includes an application layer message header, the application layer message header in the first message carries a first virtual IP address corresponding to a user identifier, the user identifier is an identifier of a user logged in on the terminal, and the first virtual IP address is an IP address in the second network; The security protection system obtains a second message based on the first message, the second message includes an IP basic header, and a source IP address field in the IP basic header in the second message carries the first virtual IP address; The security protection system sends the second message to the server.
2. The method according to claim 1, characterized in that The first message also includes an IP basic header encapsulated in the outer layer of the application layer message header, and the security protection system obtains a second message based on the first message, including: the security protection system uses the first virtual IP address to replace the content of the source IP address field in the IP basic header in the first message to obtain the second message; or The first message belongs to a first session, and the first session is a session established between the terminal and the security protection system. The security protection system obtains a second message based on the first message, including: the security protection system uses the first virtual IP address to replace the content of the source IP address field in the IP basic header in the subsequent message of the first message in the first session to obtain the second message.
3. The method according to claim 1, characterized in that Before the security protection system receives the first message from the terminal, the method further includes: The security protection system receives an authentication request message from the terminal, wherein the authentication request message includes the user identifier; The security protection system authenticates the terminal based on the authentication request message; In response to the terminal passing the authentication, the security protection system obtains the first virtual IP address based on the user identifier; During the authorization process of the terminal, the security protection system sends the first virtual IP address to the terminal.
4. The method according to claim 3, characterized in that The security protection system obtains the first virtual IP address based on the user identifier, including: The security protection system searches for a target correspondence based on the user identifier to obtain the first virtual IP address, where the target correspondence includes the user identifier and the first virtual IP address.
5. The method according to claim 3, characterized in that: The security protection system obtains the first virtual IP address based on the user identifier, including: The security protection system sends the user identification to a third-party authentication system; The security protection system receives the first virtual IP address from a third-party authentication system.
6. The method according to claim 3, characterized in that The security protection system sends the first virtual IP address to the terminal, including: The security protection system sends the first virtual IP address and the list of resources authorized by the security protection system for the user to access to the terminal, wherein the resource list includes the identifier of the network application, the identifier of the server corresponding to the identifier of the network application, the IP address of the SDP gateway, and the port number of the SDP gateway. The terminal can access the network application based on the IP address of the SDP gateway and the port number of the SDP gateway.
7. The method according to claim 6, characterized in that The authentication request message includes an HTTP request message, and the security protection system sends the first virtual IP address and a list of resources that the security protection system authorizes the user to access to the terminal, including: The security protection system sends an HTTP response message corresponding to the HTTP request message to the terminal, and a response body in the HTTP response message carries the first virtual IP address and the resource list.
8. The method according to any one of claims 1 to 7, characterized in that The first message is an HTTP connect message, the application layer message header is an HTTP header, the HTTP header includes an X-Forwarded-For field, and the first virtual IP address is carried in the X-Forwarded-For field.
9. The method according to claim 1, characterized in that: The first message also includes an IP basic header encapsulated in the outer layer of the application layer message header, and the source IP address field in the IP basic header in the first message carries the IP address of the terminal. After the security protection system receives the first message from the terminal, the method further includes: The security protection system saves a session relationship, and the session relationship includes the IP address of the terminal and the first virtual IP address.
10. The method according to claim 9, characterized in that After the security protection system sends the second message to the server, the method further includes: The security protection system receives a third message from the server, the third message includes an IP basic header, and the destination IP address field in the IP basic header in the third message carries the first virtual IP address; The security protection system searches for the session relationship based on the first virtual IP address to obtain the IP address of the terminal; The security protection system obtains a fourth message based on the IP address of the terminal and the third message, wherein the fourth message includes an IP basic header, and a destination IP address field in the IP basic header in the fourth message carries the IP address of the terminal; The security protection system sends the fourth message to the terminal.
11. The method according to claim 1, characterized in that: The terminal includes an SDP client, and the security protection system includes an SDP controller and an SDP gateway running based on an access proxy mode.
12. The method according to claim 1, characterized in that The network system further includes an audit tracing system. After the security protection system sends the second message to the server, the method further includes: The audit tracing system determines the user identifier based on the first virtual IP address.
13. A method for accessing a network application, characterized in that: Applied to a network system, the network system includes a terminal, a security protection system, and a server providing a network application, the terminal is deployed in a first network, the server is deployed in a second network, the security protection system is used to protect the security of the server, and the method includes: The terminal sends an authentication request message to the security protection system, wherein the authentication request message includes a user identifier, and the user identifier is an identifier of a user who logs in on the terminal; During the authorization process of the terminal, the terminal receives a first virtual IP address corresponding to the user identifier from the security protection system, where the first virtual IP address is an IP address in the second network; The terminal generates a first message based on the first virtual IP address, the first message includes an application layer message header, and the application layer message header in the first message carries the first virtual IP address; The terminal sends the first message to the security protection system.
14. The method according to claim 13, characterized in that The first message is an HTTP connect message, the application layer message header is an HTTP header, the HTTP header includes an X-Forwarded-For field, and the first virtual IP address is carried in the X-Forwarded-For field.
15. The method according to claim 13, characterized in that The security protection system includes an SDP gateway running in access proxy mode, and the terminal receives a first virtual IP address from the security protection system, including: The terminal receives a first virtual IP address from the security protection system and a list of resources authorized by the security protection system for the user to access, wherein the list of resources includes an identifier of the network application, an identifier of the server corresponding to the identifier of the network application, an IP address of an SDP gateway, and a port number of the SDP gateway, and the terminal can access the network application based on the IP address of the SDP gateway and the port number of the SDP gateway; Accordingly, the terminal generates a first message based on the first virtual IP address, including: The terminal generates a first message based on the first virtual IP address, the proxy gateway list and the resource list, the first message also including an IP basic header and a transport layer protocol header, the destination address field of the IP basic header in the first message includes the IP address of the SDP gateway, the destination port number field of the transport layer protocol header in the first message includes the port number of the SDP gateway, the application layer message header in the first message also carries the identifier of the network application and the identifier of the server, the IP basic header is encapsulated in the outer layer of the transport layer protocol header and the application layer message header, and the transport layer protocol header is encapsulated in the outer layer of the application layer message header; The terminal sending the first message to the security protection system includes: The terminal sends the first message to the SDP gateway.
16. The method according to claim 15, characterized in that The authentication request message includes an HTTP request message, and the terminal receives the first virtual IP address from the security protection system, the resource list authorized by the security protection system for the user to access, and the proxy gateway list authorized by the security protection system for the user to access, including: The terminal receives an HTTP response message corresponding to the HTTP request message from the security protection system, and a response body in the HTTP response message carries the first virtual IP address, the resource list, and the proxy gateway list.
17. A safety protection system, characterized in that: Provided in a network system, the network system includes a terminal, the security protection system and a server providing network applications, the terminal is deployed in a first network, the server is deployed in a second network, the security protection system is used to protect the security of the server, and the security protection system includes: a receiving unit, configured to receive a first message from the terminal, the first message comprising an application layer message header, the application layer message header in the first message carrying a first virtual IP address corresponding to a user identifier, the user identifier being an identifier of a user logging in on the terminal, and the first virtual IP address being an IP address in the second network; A processing unit, configured to obtain a second message based on the first message, wherein the second message includes an IP basic header, and a source IP address field in the IP basic header in the second message carries the first virtual IP address; A sending unit, configured to send the second message to the server.
18. The safety protection system according to claim 17, characterized in that: The receiving unit is further configured to receive an authentication request message from the terminal, wherein the authentication request message includes the user identifier; The processing unit is further configured to authenticate the terminal based on the authentication request message; The processing unit is further configured to obtain the first virtual IP address based on the user identifier in response to the terminal passing the authentication; The sending unit is further configured to send the first virtual IP address to the terminal during the authorization process of the terminal.
19. The safety protection system according to claim 17, characterized in that: The sending unit is used to send the first virtual IP address and the list of resources authorized by the security protection system for the user to access to the terminal, the resource list including the identifier of the network application, the identifier of the server corresponding to the identifier of the network application, the IP address of the SDP gateway and the port number of the SDP gateway, and the terminal can access the network application based on the IP address of the SDP gateway and the port number of the SDP gateway.
20. A terminal, characterized in that: Provided in a network system, the network system includes the terminal, the security protection system and a server providing network applications, the terminal is deployed in a first network, the server is deployed in a second network, the security protection system is used to protect the security of the server, and the terminal includes: A sending unit, configured to send an authentication request message to the security protection system, wherein the authentication request message includes a user identifier, and the user identifier is an identifier of a user who logs in on the terminal; A receiving unit, configured to receive a first virtual IP address corresponding to the user identifier from the security protection system during the authorization process of the terminal, wherein the first virtual IP address is an IP address in the second network; A processing unit, configured to generate a first message based on the first virtual IP address, wherein the first message includes an application layer message header, and the application layer message header in the first message carries the first virtual IP address; The sending unit is further used to send the first message to the security protection system.
21. The terminal according to claim 20, characterized in that: The security protection system includes an SDP gateway running based on an access proxy mode, and the receiving unit is used to receive a first virtual IP address from the security protection system and a resource list authorized by the security protection system for the user to access, wherein the resource list includes an identifier of the network application, an identifier of the server corresponding to the identifier of the network application, an IP address of the SDP gateway, and a port number of the SDP gateway, and the terminal can access the network application based on the IP address of the SDP gateway and the port number of the SDP gateway; Correspondingly, the processing unit is used to generate a first message based on the first virtual IP address, the proxy gateway list and the resource list, the first message also includes an IP basic header and a transport layer protocol header, the destination address field of the IP basic header in the first message includes the IP address of the SDP gateway, the destination port number field of the transport layer protocol header in the first message includes the port number of the SDP gateway, the application layer message header in the first message also carries the identifier of the network application and the identifier of the server, the IP basic header is encapsulated in the outer layer of the transport layer protocol header and the application layer message header, and the transport layer protocol header is encapsulated in the outer layer of the application layer message header; The sending unit is used to send the first message to the SDP gateway.
22. A safety protection system, characterized in that: The security protection system comprises: a processor, the processor is coupled to a memory, the memory stores at least one computer program instruction, and the at least one computer program instruction is loaded and executed by the processor so that the security protection system implements the method described in any one of claims 1-12.
23. A terminal, characterized in that: The terminal includes: a processor, the processor is coupled to a memory, the memory stores at least one computer program instruction, and the at least one computer program instruction is loaded and executed by the processor so that the terminal implements the method according to any one of claims 13 to 16.
24. A network system, characterized in that: The network system includes the security protection system as claimed in claim 22 and the terminal as claimed in claim 23.
25. A computer-readable storage medium, characterized in that: The storage medium stores at least one instruction, and when the instruction is executed on a computer, the computer executes the method according to any one of claims 1 to 16.
26. A computer program product, characterized in that The computer program product comprises one or more computer program instructions, and when the computer program instructions are loaded and executed by a computer, the computer is caused to execute the method according to any one of claims 1 to 16.
Citation Information
Patent Citations
Network application access method and related equipment
CN119921964A
Communication security processing method, apparatus and system
CN103718527A
Network isolation method and device, equipment and storage medium
CN114157632A
Secure authentication of remote equipment
US20160261414A1
Safety defense method and apparatus for DNS server, and communication device and storage medium
WO2020083288A1
Cited By
Resource file acquisition method and device, equipment, storage medium and program product
CN121334145A