Front-end security control method and system

By introducing a security policy module on the front end, and using asynchronous listening communication and synchronous communication to obtain security policy entries from the back end, the problem of insufficient flexibility in front-end security adaptation in the existing technology is solved, and flexible configuration and effective security management of front-end security policies are realized.

WO2025092037A1PCT designated stage expired Publication Date: 2025-05-08ZTE CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/106510
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-01
Filing Date
2024-07-19
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

In the prior art, security governance methods lack flexibility in front-end security adaptation, resulting in the need to develop multiple versions when dealing with different security standards, frequent upgrades, and strong invasiveness to software business modules, and high R&D costs.

Method used

By introducing a security policy module on the front end, the security policy entries are obtained from the back end using asynchronous listening communication and synchronous communication, and stored them in the front end storage, completing the configuration of the front end security policy.

Benefits of technology

It realizes flexible configuration of front-end security policies, reduces the workload and complexity of system security governance, reduces the intrusion of software, and can effectively meet the security needs of front-end in different scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024106510_08052025_PF_FP_ABST
    Figure CN2024106510_08052025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a front-end security control method and system. The method comprises: setting at least one security policy entry in a back-end security policy module by means of a network management software interface, wherein the security policy entry is a combination of front-end security rules; and when a trigger condition for front-end policy updating is satisfied, a front-end security policy module obtains a security policy entry from the back-end security policy module, so as to perform security control on a front end on the basis of the security policy entry, wherein asynchronous monitoring communication and synchronous communication are supported between the front-end security policy module and the back-end security policy module.
Need to check novelty before this filing date? Find Prior Art

Description

Front-end security control method and system

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This disclosure is based on Chinese patent application CN202311447179.0, filed on November 1, 2023, entitled “A Front-End Security Control Method and System”, and claims the priority of the patent application, and all the contents disclosed therein are incorporated into this disclosure by reference. Technical Field

[0003] The present disclosure relates to the field of network security, and in particular to a front-end security control method and system. Background Art

[0004] With the continuous development of 5G technology, the application of 5G's advanced wireless technology in the industrial sector is becoming the next hot application in the B2B scenario. Due to its cross-industry nature and different networking methods, B2B network security faces multiple standards and scenarios. Customers in different industries have introduced different scanning software, but the scanning standards are not exactly the same. In particular, regarding web security parameters (security-related parameters in the Hypertext Transfer Protocol), different security scanning software has different standard definitions due to historical reasons. For example, some standards define different scopes of Hypertext Transfer Protocol (HTTP) security methods. Some scanning software can pass the PUT (modify) / DELETE (delete) method, while others cannot.

[0005] Related technologies employ code modifications for security governance, but this approach lacks the flexibility to adapt to front-end security, requiring the development of multiple versions and frequent upgrades to meet varying security standards. Furthermore, this approach is highly invasive to software business modules and requires upgrading all business modules, resulting in high R&D costs. Another approach employed in related technologies is to set back-end security policies. While this approach can meet back-end security regulations, it lacks flexible customization for front-end security.

[0006] In summary, there is no good solution to the above technical problems.

[0007] Summary of the Invention

[0008] The embodiments of the present disclosure provide a front-end security control method and system to at least solve the problem that the security management methods in related technologies lack flexibility in front-end security adaptation.

[0009] According to one embodiment of the present disclosure, a front-end security control method is provided, which includes: the front-end security policy module obtains security policy entries from the back-end security policy module, wherein asynchronous monitoring communication and synchronous communication are supported between the front-end security policy module and the back-end security policy module; the front-end security policy module stores the security policy entries in the front-end storage to complete the configuration of the front-end security policy.

[0010] According to another embodiment of the present disclosure, a front-end security control system is provided, which includes: a back-end security policy module for managing security policy entries; a front-end security policy module for obtaining security policy entries from the back-end security policy module and storing the security policy entries in the front-end storage to complete the configuration of the front-end security policy, wherein asynchronous listening communication and synchronous communication are supported between the front-end security policy module and the back-end security policy module.

[0011] According to another embodiment of the present disclosure, a computer-readable storage medium is provided, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above method embodiments are executed.

[0012] According to another embodiment of the present disclosure, an electronic device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] FIG1 is a hardware structure block diagram of a front-end security control method according to an embodiment of the present disclosure;

[0014] FIG2 is a flow chart of a front-end security control method according to an embodiment of the present disclosure;

[0015] FIG3 is a block diagram of a front-end security control system according to an embodiment of the present disclosure;

[0016] FIG4 is a schematic diagram of a processing flow of a front-end security control system according to an embodiment of the present disclosure;

[0017] FIG5 is a schematic diagram of a process for timely effectiveness of a security policy according to an embodiment of the present disclosure;

[0018] 6 is a flow chart showing timely effectiveness of security policies of a front-end security policy module according to an embodiment of the present disclosure;

[0019] 7 is a schematic diagram of a security policy query validation process according to an embodiment of the present disclosure;

[0020] 8 is a flowchart of a security policy query of a front-end security policy module according to an embodiment of the present disclosure;

[0021] FIG9 is a schematic diagram of a monitoring duration in an asynchronous monitoring mechanism according to an embodiment of the present disclosure;

[0022] FIG10 is a flowchart of a business processing flow of a front-end security policy module according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0023] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the accompanying drawings and in conjunction with embodiments.

[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0025] The embodiments of the present disclosure provide a front-end security control method and system to at least solve the problem that the security management methods in related technologies lack flexibility in front-end security adaptation. ToB network managers have different requirements for front-end security scanning when dealing with customers in different industries. The embodiments of the present disclosure have made improvements in system security management, flexible configuration and policy execution to achieve flexible adaptation to front-end security policies and reduce the workload and complexity of system security management.

[0026] In the embodiments of the present disclosure, the front end refers to the user-visible interface, such as the visual interface of a website or application, which is responsible for user interface presentation and user business logic processing. The back end runs in the background or server side of the website or application and controls the content of the front end, interacts with the front end, and processes the corresponding business logic. The front end can be implemented using Hypertext Markup Language (HTML) and JavaScript, and the back end can be implemented using server-side programming languages ​​(such as Java, Python, PHP, etc.) and databases (such as MySQL, Oracle, etc.), and this disclosure does not impose any restrictions on this.

[0027] In the disclosed embodiments, users can access the front-end using a mobile terminal or computer terminal, through a website or application, and send service requests. The disclosed embodiments set up a front-end security policy module dedicated to front-end security processing on the front-end, which can centrally process service requests securely, avoid intrusion into the software, and provide greater versatility.

[0028] The method embodiments provided in the embodiments of the present disclosure can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, FIG1 is a hardware structure block diagram of the front-end security control method of the embodiment of the present disclosure. As shown in FIG1 , the hardware board may include one or more (only one is shown in FIG1 ) processors 12 (the processor 12 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device) and a memory 14 for storing data, wherein the above-mentioned mobile terminal may also include a transmission device 16 and an input and output device 18 for communication functions. It can be understood by those skilled in the art that the structure shown in FIG1 is only for illustration, and it does not limit the structure of the above-mentioned mobile terminal. For example, the mobile terminal may also include more or fewer components than those shown in FIG1 , or have a configuration different from that shown in FIG1 .

[0029] The memory 14 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the front-end security control method in the embodiment of the present disclosure. The processor 12 executes various functional applications and the front-end security control method by running the computer program stored in the memory 14, that is, implements the above-mentioned method. The memory 14 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 14 may further include a memory remotely located relative to the processor 12, and these remote memories can be connected to the mobile terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0030] The transmission device 16 is used to receive or send data via a network. Specific examples of the aforementioned network may include a wireless network provided by a communications provider. In one embodiment, the transmission device 16 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, the transmission device 16 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0031] In one embodiment of the present disclosure, a front-end security control method is provided. FIG2 is a flow chart of the front-end security control method according to the embodiment of the present disclosure. As shown in FIG2 , the flow chart includes the following steps:

[0032] Step S201, setting at least one security policy entry in the back-end security policy module through the network management software interface, wherein the security policy entry is a combination of front-end security rules;

[0033] Step S202: When the triggering conditions for the front-end policy update are met, the front-end security policy module obtains the security policy entry from the back-end security policy module so as to perform security control on the front-end based on the security policy entry, wherein asynchronous monitoring communication and synchronous communication are supported between the front-end security policy module and the back-end security policy module.

[0034] In this embodiment, the front-end security policy module and the back-end security policy module support asynchronous monitoring communication and synchronous communication. For example, the front-end and the back-end can establish communication based on Hypertext Transfer Protocol (HTTP), which is not limited in this disclosure.

[0035] In the embodiment of the present disclosure, through the above-mentioned steps S201 and S202, flexible configuration of the front-end security policy can be achieved through communication between the front-end security policy module and the back-end security policy module, thereby solving the problem that the security governance method in related technologies lacks flexibility in adapting to front-end security. While reducing the intrusiveness to the software, it can effectively meet the security needs of the front-end in different scenarios, and also reduce the workload of security governance research and development.

[0036] In some embodiments, the triggering conditions for the front-end policy update in step S202 may include: A, the front-end security policy module receives an indication of active front-end policy update generated based on human-computer interaction operations; and / or, B, the front-end security policy module monitors the policy update message actively pushed by the back-end security policy module.

[0037] In some embodiments, before the front-end security policy module obtains the security policy entry from the back-end security policy module in step S202, the method further includes:

[0038] Step S202A: upon receiving an indication of active front-end policy update based on human-computer interaction, the front-end security policy module sends a security policy synchronization request for querying the security policy entry to the back-end security policy module, wherein the security policy synchronization request is a synchronization message.

[0039] In some embodiments, step S202, in which the front-end security policy module obtains the security policy entry from the back-end security policy module, may include the following steps:

[0040] Step S2022: After receiving the security policy synchronization request, the backend security policy module returns a security policy synchronization response to the frontend security policy module, wherein the security policy synchronization response carries the security policy entry;

[0041] Step S2024: The front-end security policy module receives the security policy synchronization response and obtains the security policy entry from the security policy synchronization response.

[0042] In some embodiments, after step S202, the method further includes:

[0043] In step S203, the front-end security policy module verifies the security policy entry. If the verification fails, the front-end security policy module continues to send the security policy synchronization request to the back-end security policy module until the security policy entry verification succeeds.

[0044] In an exemplary embodiment, the front-end security policy module can verify the format of the security policy entry, the integrity of the content, or whether the processing rules of the security policy conflict, etc. The present disclosure does not limit the verification method of the security policy entry.

[0045] In some embodiments, if the verification in step S203 succeeds, the security policy can be solidified through storage. If the verification fails, the above steps S202A, S2022, S2024, and S203 are repeated until the verification in step S203 succeeds. In the embodiments of the present disclosure, by verifying the security policy entries, it is possible to prevent the security policy entries from being incomplete or tampered with due to network anomalies and network security anomalies.

[0046] In some embodiments, before the front-end security policy module obtains the security policy entry from the back-end security policy module in step S202, the method further includes:

[0047] Step S202B: the front-end security policy module asynchronously monitors the push message of the back-end security policy module.

[0048] In some embodiments, after step S201, the method further includes: the back-end security policy module pushes a policy update message to at least one of the front-end security policy modules within a preset security policy issuance time period, wherein the policy update message is an asynchronous message and carries the security policy entry.

[0049] In an exemplary embodiment, the backend security policy module can push policy update messages to multiple frontend security policy modules in a broadcast manner, or push policy update messages to each online frontend security policy module in a point-to-point manner. This disclosure does not impose any restrictions on this.

[0050] In some embodiments, step S202, in which the front-end security policy module obtains the security policy entry from the back-end security policy module, includes:

[0051] Step S2026: When the front-end security policy module monitors the policy update message actively pushed by the back-end security policy module, the front-end security policy module obtains the security policy entry from the policy update message.

[0052] In some embodiments, step S202B includes: starting a monitoring period of a preset second time at every preset first time interval, wherein the difference between the preset first time and the preset second time is greater than a preset threshold; during the monitoring period, the front-end security policy module asynchronously monitors the push messages of the back-end security policy module.

[0053] In this embodiment, the preset first time is much longer than the preset second time. By setting a shorter monitoring duration and a longer monitoring interruption period, resource waste caused by long-term monitoring can be avoided.

[0054] In some embodiments, the asynchronous monitoring of the push message from the backend security policy module by the frontend security policy module in step S202B may include the following steps:

[0055] Step S202B-1: When the monitoring duration begins, the front-end security policy module opens an event message monitoring channel for the back-end security policy module;

[0056] Step S202B-2: During the monitoring period, the front-end security policy module asynchronously monitors the push messages of the back-end security policy module through the event message monitoring channel;

[0057] Step S202B-3: When the monitoring duration ends, the front-end security policy module closes the event message monitoring channel.

[0058] In some embodiments, the security administrator user can set security policy entries or a security policy entry list (including multiple security policy entries) in the ToB network management (NM) software, and trigger subsequent security policy effectiveness mechanisms (including synchronous mechanisms and asynchronous mechanisms).

[0059] In some embodiments, each of the security policy entries includes at least one of the following: an identifier, a name, a content description, a processing type, a policy effective location, and a processing rule.

[0060] In an exemplary embodiment, the processing type may include but is not limited to setting, replacing, encoding (transcoding), etc. For example, setting may be setting a specific parameter in the service request, and replacing may be replacing the HTTP request method, such as replacing the DELETE method with the POST method.

[0061] In this embodiment, the policy effective location can be set according to the message format of the business request. For example, when the business request is an HTTP request, according to the message format of the HTTP request, the policy effective location can include the request line, request header and request body, which correspond to the three components of the HTTP request respectively, so as to facilitate separate processing.

[0062] In some embodiments, after step S202, the method further includes: step S204, the front-end security policy module stores the security policy entry in the front-end storage to complete the configuration of the front-end security policy.

[0063] In some embodiments, after the front-end security policy module stores the security policy entry in the front-end storage to complete the configuration of the front-end security policy in step S204, the method further includes the following steps:

[0064] Step S206, when the front-end business module sends a business request to the back-end, the front-end security policy module reads the front-end security policy from the front-end storage;

[0065] Step S207: the front-end security policy module processes the service request according to the front-end security policy;

[0066] Step S208: Send the processed service request to the backend service module via the backend security policy module.

[0067] In this embodiment, the front-end business module and the back-end business module are used to process business requests according to the business logic. The business module can be the original business logic processing module of the application, website or server. The security policy module is separated from the business module, and the security policy configuration of the front-end can be implemented without invading the original business logic.

[0068] In some embodiments, step S208 sends the processed service request to the backend service module via the backend security policy module, including the following steps:

[0069] Step S2082: the front-end security policy module sends the processed service request to the back-end security policy module;

[0070] Step S2084: the backend security policy module performs a security policy check on the processed service request according to the security policy entry;

[0071] Step S2086: If the security policy verification is successful, the back-end security policy module sends the processed business request to the back-end business module.

[0072] In this embodiment, the purpose of performing security policy verification on the service request is to verify whether the security policy executed by the front-end is consistent with the security policy stored on the back-end. For example, verification can be performed by determining whether the processed service request satisfies the security policy stored on the back-end. Alternatively, the processed service request can directly include the identifier of the executed security policy item and verify whether the identifiers are consistent.

[0073] In some embodiments, the method further comprises the steps of:

[0074] Step S2087: If the security policy verification fails, the backend security policy module returns a policy exception message to the frontend security policy module;

[0075] Step S2088: After receiving the policy exception message, the front-end security policy module sends a security policy synchronization request for querying the security policy entry to the back-end security policy module, wherein the security policy synchronization request is a synchronization message.

[0076] In this embodiment, the purpose of performing security policy verification on the service request is to verify whether the security policy executed by the front-end is consistent with the security policy stored in the back-end. If the security policy verification fails, it means that the security policy executed by the front-end is not the latest security policy and a synchronization request is required to update the security policy of the front-end.

[0077] In the disclosed embodiment, independent security policy modules are set at the front-end and back-end. The front-end obtains security policies from the back-end through asynchronous monitoring communication and synchronous communication, which can realize flexible configuration of the front-end security policies, thereby solving the problem that the security governance methods in related technologies lack flexibility in adapting to front-end security. While reducing the intrusion into the software, it can effectively meet the security needs of the front-end in different scenarios, and also reduce the workload of security governance research and development.

[0078] FIG3 is a block diagram of a front-end security control system according to an embodiment of the present disclosure. As shown in FIG3 , the system includes the following structures:

[0079] A back-end security policy module 32 is configured to manage at least one security policy entry under the settings of the network management software interface, wherein the security policy entry is a combination of front-end security rules;

[0080] The front-end security policy module 34 is used to obtain the security policy entry from the back-end security policy module when the triggering condition of the front-end policy update is met, wherein the front-end security policy module and the back-end security policy module support asynchronous monitoring communication and synchronous communication.

[0081] In some embodiments, the backend security policy module may execute the steps of any of the above method embodiments in the background of application software, website, or server.

[0082] In some embodiments, the front-end security policy module may execute the steps in any of the above method embodiments at the front end of a mobile terminal or a computer terminal.

[0083] In some embodiments, the triggering conditions for the front-end policy update may include: A, the front-end security policy module receives an indication of active front-end policy update generated based on human-computer interaction operations; and / or, B, the front-end security policy module monitors the policy update message actively pushed by the back-end security policy module.

[0084] In some embodiments, one back-end security policy module may correspond to multiple front-end security policy modules, and the front-end security policies of multiple terminal devices may be centrally managed through the back-end security policy modules.

[0085] In some embodiments, the system further includes a network management software interface. A security administrator user can use the front-end network management software interface to set security policy entries in the back-end security policy module, which then distributes the security policy entries to each operation and maintenance personnel's terminal device (specifically, the front-end security policy module).

[0086] The disclosed embodiments are primarily divided into two parts: the front-end and the back-end. The front-end is responsible for user interface presentation and user-visible business logic processing. The front-end can include all front-end systems capable of establishing asynchronous listening and synchronous communication with the back-end. The back-end can include all back-end systems capable of establishing asynchronous listening and synchronous communication with the front-end. For example, communication between the front-end and back-end can be asynchronous listening and synchronous communication based on the HTTP protocol.

[0087] In an exemplary embodiment, the front end may include a front-end security policy module and a front-end service module. The front end may also include a network management software interface, and the front-end service module may be a service module of a ToB network management. The back end may include a back-end security policy module and a back-end service module.

[0088] In some embodiments, the front-end security policy module is further used to send a security policy synchronization request for querying the security policy entry to the back-end security policy module upon receiving an indication of active update of the front-end policy generated based on human-computer interaction operations, wherein the security policy synchronization request is a synchronization message.

[0089] In some embodiments, the back-end security policy module is further used to return a security policy synchronization response to the front-end security policy module after receiving the security policy synchronization request, wherein the security policy synchronization response carries the security policy entry; the front-end security policy module is further used to receive the security policy synchronization response and obtain the security policy entry from the security policy synchronization response.

[0090] In some embodiments, the front-end security policy module is also used to verify the security policy entry before the front-end security policy module stores the security policy entry in the front-end storage. If the verification fails, continue to send the security policy synchronization request to the back-end security policy module until the security policy entry is successfully verified.

[0091] In some embodiments, the front-end security policy module is further configured to asynchronously monitor push messages from the back-end security policy module.

[0092] In some embodiments, the network management software interface is configured to configure security policy entries based on user operations and send the configured security policy entries to the back-end security policy module. The back-end security policy module is further configured to push a policy update message to at least one of the front-end security policy modules within a preset security policy issuance time period after receiving the security policy entry. The policy update message is an asynchronous message and carries the security policy entry.

[0093] In some embodiments, the front-end security policy module is further configured to obtain the security policy entry from the policy update message when the front-end security policy module monitors the policy update message actively pushed by the back-end security policy module.

[0094] In some embodiments, the front-end security policy module is also used to start a monitoring period of a preset second time at intervals of a preset first time, wherein the difference between the preset first time and the preset second time is greater than a preset threshold; during the monitoring period, the push messages of the back-end security policy module are asynchronously monitored.

[0095] In some embodiments, the front-end security policy module is also used to open an event message monitoring channel for the back-end security policy module at the beginning of the monitoring duration; asynchronously monitor the push messages of the back-end security policy module through the event message monitoring channel during the monitoring duration; and close the event message monitoring channel at the end of the monitoring duration.

[0096] In some embodiments, the front-end security policy module is further configured to store the security policy entries in the front-end storage to complete the configuration of the front-end security policy.

[0097] In some embodiments, the front-end security policy module is also used to read the front-end security policy from the front-end storage when the front-end business module sends a business request to the back-end; process the business request according to the front-end security policy; and send the processed business request to the back-end business module via the back-end security policy module.

[0098] In some embodiments, the front-end security policy module is also used to send the processed business request to the back-end security policy module; the back-end security policy module is also used to perform security policy verification on the processed business request according to the security policy entry; if the security policy verification is successful, the processed business request is sent to the back-end business module.

[0099] In some embodiments, the back-end security policy module is also used to return a policy exception message to the front-end security policy module when the security policy verification fails; the front-end security policy module is also used to send a security policy synchronization request for querying the security policy entry to the back-end security policy module after receiving the policy exception message, wherein the security policy synchronization request is a synchronization message.

[0100] The embodiment of the present disclosure introduces a security policy module at the front end and the back end, and uses the security policy module to handle the management, issuance and effectiveness of security policies, thereby avoiding intrusion into the business module and reducing the possibility of upgrading the business module for security governance.

[0101] FIG4 is a schematic diagram of a processing flow of a front-end security control system according to an embodiment of the present disclosure. As shown in FIG4 , the front-end security control system mainly includes the following processing flows:

[0102] Security policy setting; security policy issuance; security policy inquiry; business request processing.

[0103] In this embodiment, security management personnel can set security policies through the front-end network management software interface. The security policy can be composed of a set of security policy items, which are a combination of front-end security processing rules. Each security policy item includes information such as name, description, type, and specific processing rules.

[0104] In this embodiment, the set security policy can be stored in the backend. Exemplarily, it can be stored in a storage module or database of the backend to solidify the backend security policy.

[0105] In this embodiment, the backend security policy module is responsible for managing security policy entries and can support adding, modifying, deleting, and querying security policy entries. The backend security policy module is responsible for pushing security policies to the frontend and responding to security policy inquiries from the frontend.

[0106] In this embodiment, the front-end security policy module is responsible for enforcing security policies on the front-end. Specifically, this may include setting, assembling, replacing, and encoding relevant front-end security parameters in service requests to ensure that the front-end security parameters meet the security requirements of the current scenario. It is also responsible for sending processed service requests to the back-end system.

[0107] In an exemplary embodiment, after the security policy entries are set, the back-end security policy module will proactively push the current security policy entries to the front-end to enable the security policy to take effect in a timely manner.

[0108] In another exemplary embodiment, the front-end security policy module can also proactively initiate a security policy query to the back-end security policy module. For example, during the initial startup of a front-end application, initial user login, or website page refresh, the front-end security policy module can obtain the current security policy entries through a security policy query.

[0109] In this embodiment, security policy issuance is implemented through an asynchronous monitoring mechanism, and security policy query is implemented through a synchronous mechanism. Exemplarily, asynchronous monitoring and synchronous query can be implemented based on the HTTP protocol.

[0110] In this embodiment, both the front end and the back end have business modules responsible for responding to and processing specific business requests.

[0111] In the disclosed embodiments, security policy modules are integrated into both the front-end and back-end to centrally handle the configuration, query, issuance, consolidation, and implementation of security policies, without intruding on the network management service module. The service processing logic of the service module and the security control logic of the security policy module are independent of each other, enabling flexible configuration of front-end security policies without intruding on the service logic, reducing the likelihood of modifying service procedures and alleviating the workload of R&D personnel.

[0112] In this embodiment, there are two mechanisms for front-end security policy validation: one is that after the front-end starts monitoring back-end events, the back-end pushes the security policy to the online front-end, immediately initiating the relevant security policy to take effect on the front-end; the other is that after a newly started front-end logs into the network management system, the front-end will proactively query the back-end for the latest security policy. For example, after setting a security policy, the security administrator can use the first method to distribute the policy to the currently online terminal. If a new terminal comes online later, the currently executed policy can be obtained through the second method.

[0113] FIG5 is a schematic diagram of a process for timely effectiveness of a security policy according to an embodiment of the present disclosure. As shown in FIG5 , the process for timely effectiveness of a security policy may include the following steps:

[0114] Step S502: The security administrator user sets security policies in the network management software interface;

[0115] Step S504: The backend security policy module pushes the security policy to all online monitoring frontend security policy modules via messages, thereby implementing the distribution of the frontend security policy.

[0116] Step S506: After the front-end security policy module receives the security policy update message pushed by the back-end, the message takes effect immediately and solidifies the security policy in the front-end storage.

[0117] In this embodiment, there can be multiple front-end security policy modules, each located on a different terminal. The security administrator configures security policies through the network management interface on the management terminal. Operations and maintenance personnel can monitor back-end events on multiple terminals to obtain security policies that take effect immediately.

[0118] In this embodiment, asynchronous monitoring communication is adopted between the front-end and the back-end. The front-end monitors the back-end events, and the back-end sends policy update messages through asynchronous messages (such as HTTP broadcast messages). For example, asynchronous monitoring can be achieved through websocket (network socket) or server event (service event).

[0119] In an exemplary embodiment, the front end can set a shorter monitoring duration, perform asynchronous monitoring during the monitoring duration, and set a longer time interval between the two monitoring durations, thereby saving the connection resources paid by the back end for the front-end security policy to take effect. Under the condition of a certain bandwidth, the network management business runs more smoothly.

[0120] In an exemplary embodiment, the security policy setting process may also include processes such as front-end and back-end communication and back-end storage solidification. The front-end network management (or front-end security policy module) sends the set security policy items (list) to the back-end (back-end program or server) based on user operations. The back-end security policy module may solidify the security policy items into the back-end storage.

[0121] In the disclosed embodiments, the timely implementation mechanism for security policies enables the timely delivery of the latest security policies to all online operation and maintenance terminals, improving the flexibility and timeliness of security policy adjustments in different scenarios. The disclosed embodiments enable the instant delivery of security policies to all online operation and maintenance terminals via asynchronous push messages, avoiding message congestion. The disclosed embodiments also enable the provision of shorter monitoring durations, ensuring that security policies take effect promptly, while avoiding the waste of significant connection resources caused by prolonged monitoring.

[0122] FIG6 is a flow chart of the timely effectiveness of the security policy of the front-end security policy module according to an embodiment of the present disclosure. As shown in FIG6 , the flow includes the following steps:

[0123] Step S602: monitoring the backend push message;

[0124] Step S604, determining whether it is a policy update message;

[0125] Step S606: If it is a policy update message, update the front-end security policy.

[0126] In this embodiment, in step S602, the front-end security policy module triggers the process to start when the front-end monitors the back-end push message. If step S604 determines that the push message is not a policy update message, the process ends directly.

[0127] In one exemplary embodiment, updating the front-end security policy may include updating the internal cache of the front-end security policy module. In another exemplary embodiment, the front-end security policy module may solidify the received security policy into a storage module outside the front-end security policy module, such as a browser cache, which is not limited in this disclosure. In scenarios where the frequency of front-end security policy updates is low, solidifying the storage allows the terminal to directly obtain the available front-end security policy upon the next startup.

[0128] FIG7 is a schematic diagram of a security policy query validation process according to an embodiment of the present disclosure. As shown in FIG7 , the security policy query process may include the following steps:

[0129] Step S702: The front-end security policy module sends a security policy synchronization request to the back-end security policy module to inquire about the security policy;

[0130] Step S704: The backend security policy module sends the security policy to the frontend security policy module via a security policy synchronization response.

[0131] Step S706: The front-end security policy module parses and verifies the security policy synchronization response and solidifies the security policy.

[0132] In this embodiment, the security policy synchronization request may be an HTTP request (Request), and the security policy synchronization response may be an HTTP response (Response).

[0133] In one exemplary embodiment, step S706 may verify the security policy, such as policy integrity, policy format, and whether there are conflicts among the rules contained in the policy. This disclosure does not impose any restrictions on this. If the policy verification succeeds, the policy takes effect and is stored in the front-end storage. If the policy verification fails, a security policy synchronization request must be resent to the back-end for policy query.

[0134] In an exemplary embodiment, the security policy inquiry process can also be initiated during the business request processing process. For example, the front-end security policy module processes the business request according to the front-end policy, and sends the processed business request to the back-end business module through the back-end security policy module. At this time, the back-end security policy module will also verify the security policy of the processed business request to verify whether the security policy executed by the front-end is the same as the security policy stored in the back-end. If the two policies are inconsistent, the back-end will notify the front-end, and then the front-end will initiate the security policy inquiry process through an HTTP request.

[0135] This embodiment allows the front-end to proactively retrieve policies from the back-end during terminal device initial startup, login, page refresh, or security policy exceptions. The policy synchronization query mechanism fills the gaps in the application scenarios of the asynchronous monitoring mechanism, ensuring that the front-end security policy can be effective across a variety of application scenarios.

[0136] FIG8 is a flow chart of a security policy query of a front-end security policy module according to an embodiment of the present disclosure. As shown in FIG8 , the flow may include the following steps:

[0137] Step S802: The business person starts the front end and logs into the system or refreshes the page if already logged in.

[0138] Step S804: The front-end sends a security policy synchronization request (HTTP Request) to the back-end to inquire about the security policy;

[0139] Step S806: Determine whether the security policy is obtained and verified successfully. If the security policy is obtained and verified successfully, proceed to the next step; otherwise, repeat step S804.

[0140] Step S808: The front-end updates the security policy and saves it to the front-end storage.

[0141] Through the disclosed embodiments, the front-end can proactively retrieve policies from the back-end during scenarios such as initial device startup, login, page refresh, or security policy anomalies. The policy synchronization query mechanism addresses the application scenarios lacking in the asynchronous monitoring mechanism, building a complete security policy setting and validation mechanism. This helps on-site operations teams customize security policies and implement unified validation operations, making security policy settings more flexible and meeting the differentiated security requirements of different industries.

[0142] FIG9 is a schematic diagram of the monitoring duration in the asynchronous monitoring mechanism according to an embodiment of the present disclosure. As shown in FIG9 , the front end establishes an event message channel with the back end during the monitoring duration to monitor the back end push messages.

[0143] In this embodiment, the front-end can proactively open a listening channel at a preset time. If the back-end has a security policy update, it will push a policy update message within the preset security policy delivery period. During the time period that overlaps with the front-end's listening duration, the front-end can obtain the security policy via push messages from the back-end. Regardless of whether the front-end receives the push message, it will proactively close the listening channel at the end of the duration.

[0144] In this embodiment, the duration of the monitoring period is less than the time interval between the two periods. For example, the duration can be set to 5 minutes and the time interval can be set to 1 hour. The front end will restart the monitoring period after every preset time interval. The present disclosure does not limit the duration and interval of the period, and the time can also be set in seconds or millimeter units.

[0145] In some embodiments, the security policy delivery time period may be greater than the duration of the monitoring duration period.

[0146] In the disclosed embodiment, the immediate effect mechanism uses short-duration time slices for communication, which can reduce the time that system resources are occupied, avoid long-term and unlimited occupation of conventional service channels, and save communication resources.

[0147] FIG10 is a flowchart of a service processing flow of a front-end security policy module according to an embodiment of the present disclosure. As shown in FIG10 , the flow may include the following steps:

[0148] Step S1000: The front-end triggers the security policy execution process by sending a service request to the back-end;

[0149] Step S1002: The front end reads the security policy from the storage;

[0150] Step S1004: The front end parses and executes the security policy to send a service request;

[0151] Step S1006: If an exception occurs, a security policy synchronization request is sent to the backend to query the policy;

[0152] Step S1008: The front-end updates the security policy and saves it to the front-end storage, and then re-enters step S1002.

[0153] In this embodiment, after the security policy takes effect, during normal business operation, the front-end security policy module executes the security policy to process the business request before sending it to the back-end.

[0154] In this embodiment, a service request is initiated by operations personnel through the front-end service module. The front-end security policy module performs security processing on the service request according to the front-end security policy and sends the processed service request to the back-end service module via the back-end security policy module. The back-end security policy module verifies the processed service request, primarily to verify that the security policies implemented by the front-end and back-end are consistent. This determination can be made based on the identifier, processing type, or specific processing rules in the executed security policy entry.

[0155] In an exemplary embodiment, the processing rule of the security policy is to replace the DELETE method with the POST method. If the back-end security policy module detects that the processed business request is the DELETE method, it means that the front-end and back-end security policies are inconsistent. The back-end returns a policy exception message to the front-end. After receiving the message, the front-end re-initiates the policy query.

[0156] In some embodiments, the security administrator user sets security policy entries in the ToB network management (NM) software, and can complete the security policy setting in the ToB NM software based on a certain security policy entry or a list of security policy entries, thereby triggering a subsequent effectiveness mechanism.

[0157] In some embodiments, as shown in Table 1, the security policy entry includes but is not limited to one or more of the following combinations: the security policy entry's identifier, name, content description, processing type, effective location, and specific processing rules.

[0158] Table 1:

[0159] In an exemplary embodiment, the processing types of security policy entries include setting, replacing, encoding, etc. The effective locations of security policy entries include request line, request header and request body, which correspond to the three components of HTTP request respectively, so as to facilitate separate processing.

[0160] In an exemplary embodiment, as shown in Table 2, the security policy entry list may include multiple security policy entries.

[0161] Table 2:

[0162] The disclosed embodiments can address the diverse requirements of front-end security scanning for clients across different industries, enabling flexible adaptation of security policies to front-end security parameters and providing more personalized security management. This eliminates the need to modify front-end and back-end code to meet industry security specifications, reducing the workload and complexity of system security management.

[0163] An embodiment of the present disclosure further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above method embodiments are executed.

[0164] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disk.

[0165] An embodiment of the present disclosure further provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0166] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.

[0167] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail here.

[0168] Obviously, those skilled in the art should understand that the modules or steps of the present disclosure described above can be implemented using a general-purpose computing device, they can be concentrated on a single computing device, or distributed across a network composed of multiple computing devices, they can be implemented using program code executable by the computing device, and thus, they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be performed in a different order than herein, or they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module for implementation. Thus, the present disclosure is not limited to any particular combination of hardware and software.

[0169] The foregoing is merely an exemplary embodiment of the present disclosure and is not intended to limit the present disclosure. Those skilled in the art will readily appreciate that the present disclosure is susceptible to various modifications and variations. Any modifications, equivalent substitutions, improvements, and the like made within the principles of the present disclosure shall be included within the scope of protection of the present disclosure.

Claims

1. A front-end security control method, the method comprising: Setting at least one security policy entry in the back-end security policy module through the network management software interface, wherein the security policy entry is a combination of front-end security rules; When the triggering conditions for the front-end policy update are met, the front-end security policy module obtains the security policy entry from the back-end security policy module so as to perform security control on the front end based on the security policy entry, wherein asynchronous listening communication and synchronous communication are supported between the front-end security policy module and the back-end security policy module.

2. The method according to claim 1, wherein: The triggering conditions for the front-end policy update include: The front-end security policy module receives an indication of active front-end policy update generated based on human-computer interaction operation; And / or, the front-end security policy module monitors the policy update message actively pushed by the back-end security policy module.

3. The method according to claim 2, wherein: Before the front-end security policy module obtains the security policy entry from the back-end security policy module, the method further includes: Upon receiving an indication of active front-end policy update based on human-computer interaction, the front-end security policy module sends a security policy synchronization request for querying the security policy entry to the back-end security policy module, wherein the security policy synchronization request is a synchronization message.

4. The method according to claim 3, wherein: The front-end security policy module obtains the security policy entry from the back-end security policy module, including: After receiving the security policy synchronization request, the back-end security policy module returns a security policy synchronization response to the front-end security policy module, wherein the security policy synchronization response carries the security policy entry; The front-end security policy module receives the security policy synchronization response and obtains the security policy entry from the security policy synchronization response.

5. The method according to claim 4, wherein: After the front-end security policy module obtains the security policy entry from the back-end security policy module, the method further includes: The front-end security policy module verifies the security policy entry; If the verification fails, the security policy synchronization request continues to be sent to the back-end security policy module until the security policy entry is verified successfully.

6. The method according to claim 2, wherein: Before setting at least one security policy item in the back-end security policy module through the network management software interface, the method further includes: The front-end security policy module asynchronously monitors the push message of the back-end security policy module.

7. The method according to claim 6, wherein: After setting at least one security policy item in the back-end security policy module through the network management software interface, the method further includes: The back-end security policy module pushes a policy update message to at least one of the front-end security policy modules within a preset security policy issuance time period, wherein the policy update message is an asynchronous message and carries the security policy entry.

8. The method according to claim 7, wherein: The front-end security policy module obtains the security policy entry from the back-end security policy module, including: In the case where the front-end security policy module monitors the policy update message actively pushed by the back-end security policy module, the front-end security policy module obtains the security policy entry from the policy update message.

9. The method according to claim 6, wherein: The front-end security policy module asynchronously monitors the push message of the back-end security policy module, including: At each preset first time interval, a monitoring duration of a preset second time is started, wherein the difference between the preset first time and the preset second time is greater than a preset threshold; During the monitoring duration, the front-end security policy module asynchronously monitors the push messages of the back-end security policy module.

10. The method according to claim 9, wherein: During the monitoring duration, the front-end security policy module asynchronously monitors the push message of the back-end security policy module, including: When the monitoring duration begins, the front-end security policy module opens an event message monitoring channel for the back-end security policy module; During the monitoring duration, the front-end security policy module asynchronously monitors the push messages of the back-end security policy module through the event message monitoring channel; When the monitoring duration ends, the front-end security policy module closes the event message monitoring channel.

11. The method according to claim 1, wherein: Each of the security policy entries includes at least one of the following: an identifier, a name, a content description, a processing type, a policy effective location, and a processing rule.

12. The method according to claim 1, wherein: After the front-end security policy module obtains the security policy entry from the back-end security policy module, the method further includes: The front-end security policy module stores the security policy entries in the front-end storage to complete the configuration of the front-end security policy.

13. The method according to claim 12, wherein: After the front-end security policy module stores the security policy entry in the front-end storage to complete the configuration of the front-end security policy, the method further includes: When the front-end service module sends a service request to the back-end, the front-end security policy module reads the front-end security policy from the front-end storage; The front-end security policy module processes the service request according to the front-end security policy; The processed service request is sent to the back-end service module via the back-end security policy module.

14. The method according to claim 13, wherein: Sending the processed service request to the back-end service module via the back-end security policy module includes: The front-end security policy module sends the processed service request to the back-end security policy module; The back-end security policy module performs security policy verification on the processed service request according to the security policy entry; When the security policy verification is successful, the back-end security policy module sends the processed service request to the back-end service module.

15. The method according to claim 14, wherein: The method further comprises: In the event that the security policy verification fails, the back-end security policy module returns a policy exception message to the front-end security policy module; After receiving the policy exception message, the front-end security policy module sends a security policy synchronization request for querying the security policy entry to the back-end security policy module, wherein the security policy synchronization request is a synchronization message.

16. A front-end safety control system, the system comprising: The back-end security policy module is used to manage at least one security policy entry under the settings of the network management software interface, wherein: The security policy entry is a combination of front-end security rules; The front-end security policy module is used to obtain the security policy entry from the back-end security policy module when the triggering condition of the front-end policy update is met, wherein the front-end security policy module and the back-end security policy module support asynchronous monitoring communication and synchronous communication.

17. A computer-readable storage medium, wherein a computer program is stored in the storage medium, wherein: When the computer program is executed by a processor, the method described in any one of claims 1 to 15 is executed.

18. An electronic device comprising a memory and a processor, wherein: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method according to any one of claims 1 to 15.

Citation Information

Patent Citations

  • Intelligent security policy configuration method based on target perception

    CN113328996A

  • Safety control method and system

    CN113835698A

  • Strategy processing method and system

    CN114338231A

  • Method and device for repairing security policy configuration of terminal, and electronic equipment

    CN116506170A

  • Systems and methods for generating policy coverage information for security-enhanced information handling systems

    US20200210598A1