Terminal network access control method, apparatus, device, and storage medium

By performing identity verification and compliance checks in the terminal network access control method, and using compliance plugins and third-party software or SMS to transmit compliance information, the risk of identity information leakage in Portal authentication and the terminal burden of 802.1x authentication are resolved, thus achieving efficient and secure terminal network access control.

WO2026011833A1PCT designated stage Publication Date: 2026-01-15BEIJING XINWANG RUIJIE NETWORK TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/084288
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-10
Filing Date
2025-03-24
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

In existing Portal authentication methods, network traffic between user terminals and Portal servers and switches is not encrypted, resulting in a high risk of identity information leakage. Furthermore, 802.1x authentication requires the installation of a client on each user terminal, increasing the burden on the terminals.

Method used

By obtaining the target terminal's identity information for authentication, a secure channel is established. A lightweight compliance assessment is performed using a compliance plugin to ensure the terminal's security status is compliant, allowing compliant terminals to access the network. Compliance information is then sent via third-party software or SMS, reducing the maintenance costs of the client software.

Benefits of technology

It improves the reliability of terminal network access verification, reduces network security risks, reduces terminal memory consumption and client software maintenance costs, and enhances network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025084288_15012026_PF_FP_ABST
    Figure CN2025084288_15012026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in embodiments of the present application are a terminal network access control method, an apparatus, a device, and a storage medium. The terminal network access control method comprises: acquiring identity information sent by a target terminal, and performing identity verification on the target terminal on the basis of the identity information; when it is determined that the identity information passes the identity verification, in response to a compliance request triggered by the target terminal on the basis of a preset compliance entry, determining a current compliance state of the target terminal, wherein the compliance entry is an invocation link corresponding to a compliance plugin required for determining the compliance state; and if the current compliance state of the target terminal is compliant, allowing the target terminal to access a target network, and authorizing the target terminal to access all network resources in the target network.
Need to check novelty before this filing date? Find Prior Art

Description

Terminal network access control methods, devices, equipment and storage media

[0001] Cross-reference to related applications

[0002] This application claims priority to Chinese Patent Application No. 202410925463.2, filed on July 10, 2024, entitled "A Terminal Network Access Control Method and Related Device", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of network security technology, and in particular to a terminal network access control method, apparatus, device, and storage medium. Background Technology

[0004] With the rapid development of network application technologies, network security issues are becoming increasingly prominent. In order to ensure the security of various user terminals and prevent unauthorized users from threatening to intrude into the network, it is necessary to effectively control the network access behavior of user terminals, thereby ensuring the safe operation of enterprise networks.

[0005] Under relevant technologies, the traditional method for addressing network security issues in terminal network access is to ensure the security of user terminals by combining portal authentication with terminal compliance verification processes. Portal authentication forces user terminals to enter a web authentication page when they access any website, verifies the user terminal's identity information (such as account password or verification code), and authorizes the user terminal to access network resources after successful verification, thereby ensuring the security of the network environment.

[0006] However, during the Portal authentication process, the network traffic between the user terminal, the Portal server, and the switch is not encrypted. The data security during transmission is low, and there is a risk of identity leakage due to packet capture over the air interface, which could lead to network attacks.

[0007] Furthermore, port-based network access control protocol authentication (802.1x authentication) establishes a secure channel by mutually verifying the identities of user terminals and authentication servers. Compared with Portal authentication, it reduces the risk of identity information leakage and is gradually becoming the mainstream terminal network access method. Summary of the Invention

[0008] Exemplary embodiments of this application provide a terminal network access control method, apparatus, device, medium, and program product.

[0009] In a first aspect, embodiments of this application provide a terminal network access control method, the method comprising:

[0010] Obtain the identity information sent by the target terminal, and verify the identity of the target terminal based on the identity information;

[0011] After confirming that the identity information has passed the authentication, in response to a compliance request triggered by the target terminal based on a preset compliance entry point, the current compliance status of the target terminal is determined, wherein the compliance entry point is the call link corresponding to the compliance plugin required to determine the compliance status; and

[0012] If the target terminal is currently compliant, then the target terminal is allowed to access the target network and is authorized to access all network resources in the target network.

[0013] In one possible implementation, the identity information sent by the target terminal includes the account and password information entered by the target terminal based on the 802.1x authentication input box.

[0014] In this implementation, 802.1x authentication can be used to improve the security of verification; in addition, this implementation can achieve clientless identity authentication and compliance, reducing terminal memory consumption and the operation and maintenance costs of client software.

[0015] In one possible implementation, after determining that the identity information has passed the identity verification, the method further includes: if the most recent historical compliance record is compliant, then determining that the current compliance status of the target terminal is compliant.

[0016] In one possible implementation, after determining that the identity information has passed the authentication, before responding to a compliance request triggered by the target terminal based on a preset compliance entry, the method further includes: if the most recent historical compliance record is non-compliant, or the target terminal does not have a historical compliance record, then sending an alarm message to the target terminal, the alarm message containing the compliance entry.

[0017] In one possible implementation, sending the alarm information to the target terminal includes: sending the alarm information to the target terminal via third-party software or SMS.

[0018] In this implementation, alarm information is sent to the target terminal via third-party software or SMS, enabling clientless compliance verification and reducing terminal memory consumption and client software maintenance costs.

[0019] In one possible implementation, the alarm information also includes a compliance log, which is used to modify the security status information of the target terminal.

[0020] In one possible implementation, before determining the current compliance status of the target terminal, the method includes: obtaining one or more compliance items from a list of security status information compliance items, wherein the one or more compliance items contain at least the software name of the software to be judged.

[0021] In one possible implementation, the one or more compliance items include multiple compliance items, and determining the current compliance status of the target terminal includes: obtaining the weight corresponding to each of the multiple compliance items based on the status information corresponding to each of the multiple compliance items; and if the sum of the weights of the multiple compliance items is less than a preset weight threshold, then determining that the current compliance status of the target terminal is compliant.

[0022] In one possible implementation, obtaining the weight corresponding to each compliance item among the plurality of compliance items includes: determining the status code corresponding to the first compliance item among the plurality of compliance items; wherein the status code corresponding to the first compliance item corresponds to an abnormal situation of the first compliance item; and determining the weight corresponding to the first compliance item based on the status code corresponding to the first compliance item.

[0023] In one possible implementation, the plurality of compliance items further includes at least one of the following: the Internet Protocol (IP) address of the target terminal; or the Media Control Access (MAC) address of the target terminal.

[0024] In one possible implementation, the status information corresponding to the plurality of compliance items includes at least one of the following: a security status information blacklist, a security status information whitelist, IP address compliance, IP address non-compliance, MAC address compliance, or MAC address non-compliance.

[0025] In one possible implementation, obtaining the identity information sent by the target terminal includes: obtaining the identity information sent by the target terminal based on a preset network security channel.

[0026] In one possible implementation, the step of obtaining the identity information sent by the target terminal based on a preset network security channel and verifying the identity of the target terminal based on the identity information includes: obtaining the validity verification result of the target terminal's server digital certificate and verifying the validity of the device digital certificate from the target terminal; when the validity verification results of the server digital certificate and the device digital certificate are both passed, and the pre-stored historical identity information of the target terminal matches the identity information sent by the target terminal, the identity verification is determined to be successful.

[0027] In one possible implementation, the step of obtaining the identity information sent by the target terminal and verifying the identity of the target terminal based on the identity information further includes: if the verification fails, then re-obtaining the identity information of the target terminal.

[0028] In one possible implementation, the method further includes: if the current compliance status of the target terminal is non-compliant, then controlling the target terminal to access restricted network resources in the target network.

[0029] In one possible implementation, the method further includes: during the process of the target terminal accessing network resources, performing compliance verification on the security status information of the target terminal at preset time intervals, and adjusting the network resource access permissions of the target terminal in the target network based on the result of the compliance verification.

[0030] In this embodiment, the server obtains the identity information sent by the target terminal and performs identity verification on the target terminal based on the identity information; after determining that the identity information passes the identity verification, in response to a compliance request triggered by the target terminal based on a preset compliance entry, the server determines the current compliance status of the target terminal, wherein the compliance entry is the call link corresponding to the compliance plugin required to determine the compliance status; and if the current compliance status of the target terminal is compliant, the server allows the target terminal to access the target network and authorizes the target terminal to access all network resources in the target network.

[0031] This approach, based on the identity verification of terminals applying for network access, uses a lightweight compliance plugin to make compliance judgments on the security status information of the terminals, ensuring that only terminal devices that meet a certain security level are allowed to access the network. This enhances the reliability of terminal network access verification, reduces network security risks, and, compared to the traditional 802.1x authentication method, reduces terminal memory consumption and client software maintenance costs.

[0032] Secondly, embodiments of this application also provide a terminal network access control device, the device comprising:

[0033] The acquisition module is used to acquire the identity information sent by the target terminal and to authenticate the target terminal based on the identity information;

[0034] The verification module, after confirming that the identity information has passed authentication, responds to a compliance request triggered by the target terminal based on a preset compliance entry point, and determines the current compliance status of the target terminal, wherein the compliance entry point is the call link corresponding to the compliance plugin required to determine the compliance status; and

[0035] The control module is configured to allow the target terminal to access the target network and authorize the target terminal to access all network resources in the target network if the target terminal's current compliance status is compliant.

[0036] In one possible implementation, the device further includes: a sending module for sending alarm information to the target terminal; wherein the alarm information includes the compliance entry point.

[0037] Thirdly, embodiments of this application provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method as described in any of the first aspects.

[0038] Fourthly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of any of the methods described in the first aspect.

[0039] Fifthly, embodiments of this application provide a computer program product that, when invoked by a computer, causes the computer to execute the method described in the first aspect. Attached Figure Description

[0040] To more clearly illustrate the technical solutions in the embodiments of the present invention or related technologies, the accompanying drawings used in the description of the embodiments or conventional technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other embodiments can be obtained based on these drawings without creative effort. The accompanying drawings are incorporated in and constitute a part of this specification, illustrating embodiments consistent with this application, and are used together with the description to explain the principles of this application.

[0041] Figure 1 is a schematic diagram of possible application scenarios in the embodiments of this application;

[0042] Figure 2 is a flowchart of a terminal network access control method in an embodiment of this application;

[0043] Figure 3 is a flowchart of an authentication method based on a secure channel in an embodiment of this application;

[0044] Figure 4 is a flowchart of a security status information compliance verification method according to an embodiment of this application;

[0045] Figure 5 is a flowchart of a compliance verification method in an embodiment of this application;

[0046] Figure 6 is an example table of compliance judgment weight assignment in an embodiment of this application;

[0047] Figure 7 is a flowchart of a terminal network access scenario in an embodiment of this application;

[0048] Figure 8 is a schematic diagram of the structure of a terminal network access control device in an embodiment of this application;

[0049] Figure 9 is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation

[0050] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this application. Obviously, the described embodiments are only some embodiments of the technical solutions of this application, and not all embodiments. Based on the embodiments recorded in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the technical solutions of this application.

[0051] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in sequences other than those illustrated or described herein.

[0052] The following explanations of some terms used in the embodiments of this application are provided to facilitate understanding by those skilled in the art.

[0053] (1) Authentication server: Its function is to authenticate and authorize users, determine whether the terminal attempting to access the network is legitimate, and specify the network access permissions that a legitimate terminal can have.

[0054] (2) Extensible authentication protocol (EAP): is a layer 2 process that allows the network to authenticate wireless clients.

[0055] (3) Portal authentication: also known as web authentication, it can provide users with identity verification and personalized information services in the form of web pages. The terminal needs to be authenticated through the Portal page before it can access network resources.

[0056] (4) 802.1x authentication: It is a port-level network authentication protocol. Unauthenticated terminals cannot communicate through the network port, which provides strong security.

[0057] (5) Terminal access: The process by which a terminal goes from accessing the network to obtaining network access permissions.

[0058] (6) Terminal compliance: The network administrator formulates compliance policies, and the system performs compliance checks on the terminals according to the policies.

[0059] (7) Identity verification: Verify the legitimacy of the terminal's identity, commonly using methods such as account password authentication, SMS authentication, and facial verification.

[0060] (8) Digital Certificates: Digital certificates provide electronic authentication for secure communication between parties. They are used for identity verification and encryption of electronic information on the Internet, company intranets, or extranets. A digital certificate contains identification information of the key pair (public and private keys), and the authenticity of this information is verified to authenticate the certificate holder's identity.

[0061] The preferred embodiments of this application are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit this application. Furthermore, the embodiments and features in the embodiments of this application can be combined with each other without conflict.

[0062] Referring to Figure 1, it is a schematic diagram of possible application scenarios in the embodiments of this application.

[0063] This application scenario includes terminal device 110 (including terminal device 1101, terminal device 1102... terminal device 110n) and server 120. Terminal device 110 and server 120 can communicate with each other through a communication network.

[0064] In one alternative implementation, the communication network can be a wired network or a wireless network. Therefore, the terminal device 110 and the server 120 can be connected directly or indirectly via wired or wireless communication. For example, the terminal device 110 can be indirectly connected to the server 120 via a wireless access point, or the terminal device 110 can be directly connected to the server 120 via the Internet; this application does not impose any limitations on this.

[0065] In this embodiment, the terminal device 110 includes, but is not limited to, mobile phones, tablets, laptops, desktop computers, e-book readers, smart voice interaction devices, smart home appliances, vehicle terminals, and other devices. Various clients can be installed on the terminal device 110. These clients can be applications that support functions such as video preview and video playback (e.g., browsers, game software, etc.). The terminal device 110 can also run web pages, mini-programs, plugins, and other programs.

[0066] Server 120 is a backend server corresponding to the client, webpage, mini-program, or plugin installed on terminal device 110. Server 120 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.

[0067] It should be noted that the terminal network access control method in this application embodiment can be executed by an electronic device, which can be a server 120 or a terminal device 110. That is, the method can be executed by the server 120 or the terminal device 110 alone, or by the server 120 and the terminal device 110 together.

[0068] It should be noted that the following text mainly uses the example of the server running alone, and no specific limitations are made here.

[0069] It should be noted that Figure 1 is only an example, and the actual number of terminal devices 110 and servers 120 is not limited, and no specific limitation is made in this embodiment.

[0070] In this embodiment of the application, when there are multiple servers 120, the multiple servers 120 can form a blockchain, and each server 120 is a node on the blockchain.

[0071] Portal authentication and 802.1x authentication are two mainstream authentication methods. In traditional technologies, Portal authentication uses HTTP plaintext transmission between the terminal and the server, which carries the risk of identity information leakage due to packet sniffing, resulting in low security. 802.1x authentication, on the other hand, is client-based, requiring the installation of a specific client on each user terminal, increasing the burden on the user's device.

[0072] Referring to Figure 2, this application embodiment provides a terminal network access control method. The specific execution steps will be described in detail below with reference to the method flowchart in Figure 2.

[0073] Step S201: Obtain the identity information sent by the target terminal based on the preset network security channel, and verify the identity of the target terminal.

[0074] Specifically, in this embodiment of the application, 802.1x authentication is enabled on the authentication server, requiring terminals connected to the access device port to authenticate themselves and obtain the identity information sent by the target terminal.

[0075] Furthermore, to prevent identity information from being intercepted and tampered with during transmission, the authentication server and the target terminal verify each other's digital certificates, thereby establishing a secure channel.

[0076] For example, see Figure 3, which is a flowchart of an authentication method based on a secure channel in an embodiment of this application.

[0077] Step S2011: Obtain the validity verification result of the target terminal's digital certificate for the server, and verify the validity of the device digital certificate sent by the target terminal.

[0078] For example, the authentication server sends its own server digital certificate to the target terminal. The target terminal uses the stored server certificate chain to verify the validity of the server certificate. After successful verification, the target terminal informs the authentication server of the verification result.

[0079] Step S2012: When the validity verification results of both the server digital certificate and the device digital certificate are passed, and the pre-stored historical identity information of the target terminal matches the identity information sent by the target terminal, the identity verification is confirmed to be successful.

[0080] For example, the authentication server uses the stored device certificate chain to verify the validity of the device digital certificate. When both the device digital certificate and the server digital certificate pass the validity verification, the security of the channel between the target terminal and the authentication server is determined. Furthermore, if the historical identity information of the target terminal pre-stored by the authentication server matches the identity information sent by the target terminal, the authentication server determines that the identity verification of the target terminal is successful.

[0081] When the authentication server verifies the identity of the target terminal, it may use account password, SMS verification code or facial recognition verification method, or a combination of account password and SMS verification code verification method. This application does not restrict this.

[0082] In addition, when reporting identity information, the target terminal can also use methods such as asymmetric keys to encrypt the identity information, further ensuring data security.

[0083] Step S202: After confirming that the identity information has been verified, in response to the compliance request triggered by the target terminal based on the preset compliance entry, determine the current compliance status of the target terminal according to the preset security status information compliance list.

[0084] The compliance entry point is the link to the compliance plugin required to determine the compliance status, and the security status information includes at least software information. Those skilled in the art will understand that for target terminals without the compliance plugin installed, the compliance plugin can be installed by clicking the compliance entry point; for target terminals with the compliance plugin already installed, clicking the compliance entry point will take you to the compliance page, where the compliance entry point is the link to the compliance plugin.

[0085] As those skilled in the art will understand, after verifying the identity information, the server sends a preset compliance entry to the target terminal. In some possible implementations, the server sends the preset compliance entry to the target terminal through third-party service software. Sending the compliance entry through third-party service software allows information to be sent using the third-party service software without needing to download a dedicated client, thus achieving clientless compliance authentication. Those skilled in the art will understand that third-party service software can be software capable of sending information to the target terminal, such as instant messaging software like WeChat and QQ; it can also be office software like DingTalk, Lark, and Zoom. In other possible implementations, the server may also send the preset compliance entry to the target terminal via SMS or other means.

[0086] Specifically, in this embodiment, to prevent malicious programs from existing on the target terminal and posing a threat to the network environment after the target terminal joins the network, the authentication server will perform compliance verification on the security status information of the target terminal after authenticating its identity. Those skilled in the art will understand that compliance verification will also check for some essential software, such as antivirus software.

[0087] Before responding to a compliance request triggered by the target terminal based on a preset compliance entry, the server first determines whether the target terminal has a historical compliance record.

[0088] Referring to Figure 4, which is a flowchart of a security status information compliance verification method according to an embodiment of this application, the server includes two cases, A and B, when executing the compliance verification process to determine whether the target terminal has historical compliance records and whether the most recent historical compliance record is compliant.

[0089] Step S2021A: If the most recent historical compliance record is compliant, then directly determine the current compliance status of the target terminal as compliant.

[0090] In one optional embodiment, for a target terminal with a historical compliance record, when the most recent historical compliance record is compliant, the authentication server will directly determine that the target terminal's current compliance status is compliant. This can improve the compliance verification speed, enabling the target terminal to quickly access the target network. Furthermore, by detecting historical compliance records to determine the target terminal's current compliance status, users with a current compliance status can directly access the network.

[0091] Step S2021B: If the most recent historical compliance record is non-compliant, or if the target terminal does not have a historical compliance record, then send an alarm message to the target terminal.

[0092] The alarm information includes compliance logs and compliance entry points. The compliance logs are used to modify the security status information of the target terminal; the compliance entry points are used to provide the installation of compliance plugins and / or compliance testing.

[0093] As will be understood by those skilled in the art, the compliance log includes at least one of the following: the name of the currently non-compliant software and a suggested operation to change the non-compliant status. Based on the compliance log, the target terminal can perform relevant operations to modify or change the current non-compliant status; after the operation is completed, the target terminal will then perform compliance verification again through the compliance portal, and its security status information will be the modified installation status information.

[0094] If a historical compliance record exists but the most recent historical compliance record is non-compliant, the authentication server directly determines that the target terminal's current compliance record is non-compliant and sends an alarm message to the target terminal.

[0095] In another optional embodiment, when the target terminal has no historical compliance record, it indicates that the target terminal is requesting access to the target network for the first time. At this time, the authentication server directly determines the current security status information of the target terminal as non-compliant and sends an alarm message carrying the compliance entry to the target terminal, so that the target terminal can actively enter the compliance process based on the compliance entry.

[0096] Specifically, when the target terminal first enters the compliance process through the compliance portal, it will download a dedicated compliance plugin locally and complete the compliance verification by running the compliance plugin.

[0097] In this way, compared with the traditional 802.1x authentication method that combines the client, this application does not require the installation of specific client software locally, which can reduce the memory consumption of the terminal and reduce the maintenance cost of the client software.

[0098] Optionally, the compliance plugin can also be configured on the authentication server, with the compliance entry point designed as a link to remotely call the compliance plugin. This eliminates the need to save and run the compliance plugin locally on the terminal, further reducing the terminal's memory resource consumption.

[0099] Step S2022B: In response to the compliance request triggered by the target terminal based on the compliance entry, determine the current compliance status of the target terminal according to the preset security status information compliance list.

[0100] Furthermore, in this embodiment of the application, after the target terminal enters the compliance process through the compliance portal, the authentication server or the terminal runs a compliance plugin locally, and performs compliance verification on the target terminal in conjunction with the compliance list of security status information.

[0101] Referring to Figure 5, which is a flowchart of a compliance verification method in an embodiment of this application, it specifically includes:

[0102] Step S501: Obtain multiple compliance items from the security status information compliance list.

[0103] Among these, several compliance items must include at least the name of the software to be assessed.

[0104] It should be noted that the security status information compliance list in this application embodiment is a security status information blacklist or whitelist. In addition, the server may also set only a security status information whitelist or a security status information blacklist as the security status information compliance list, and this application does not restrict this.

[0105] Specifically, the authentication server presets a blacklist and whitelist of security status information for terminals requesting network access, which includes multiple compliance items. In this embodiment, the multiple compliance items include at least the name of the software to be judged.

[0106] For example, the security status information blacklist includes multiple compliance items such as the names of software that the target terminal cannot install, while the security status information whitelist includes multiple compliance items such as the names of software that the target terminal must install. Those skilled in the art will understand that blacklists and whitelists can be configured according to the administrator's management needs.

[0107] In one alternative embodiment, the compliance items may further include the target terminal's Internet Protocol Address (IP address) and Media Access Control Address (MAC address), which are not limited in this application.

[0108] For example, when IP addresses are included in the compliance criteria, if a company's internal LAN only allows terminals with IP addresses in the range of 192.168.1.2 to 192.168.2.254 to access the network, then terminals with IP addresses outside this range will be deemed non-compliant and thus unable to access the company's internal LAN. The same applies to MAC addresses. Those skilled in the art will understand that if an IP address is outside the allowed range, its compliance status in the terminal compliance criteria is "IP address non-compliant"; if it is within the allowed range, its compliance status is "IP address compliant." Similarly, if a MAC address is not on the allowed list, its compliance status is "MAC address non-compliant"; if it is on the allowed list, its compliance status is "MAC address compliant."

[0109] Step S502: Perform compliance judgments on the status information corresponding to each of the multiple compliance items to obtain the corresponding compliance judgment results and the weight of each compliance judgment result.

[0110] In this embodiment of the application, the authentication server first determines whether the target terminal has installed any software that cannot be installed or must be installed as recorded in the security status information blacklist and whitelist. If the target terminal has installed any software in the blacklist or has not installed any software in the whitelist, the server immediately determines that the compliance status of the target terminal is non-compliant.

[0111] For example, when the target terminal has installed software corresponding to a compliance item in the blacklist, the weight of the compliance judgment result of that compliance item can be set to infinitely large. In this case, to save time, the compliance verification process can be terminated immediately. The same applies to the whitelist.

[0112] When the software installed on the target terminal meets the requirements of the blacklist and whitelist, the authentication server further performs a compliance judgment on the status information corresponding to the software in the whitelist, and obtains the weight corresponding to the compliance judgment result.

[0113] For example, referring to Figure 6, which is an example table of compliance judgment weight assignment in an embodiment of this application, the authentication server checks the current status of a software to obtain a status code, each status code corresponds to an abnormal situation, and each abnormal situation has a preset corresponding weight.

[0114] Step S503: If the sum of the weights corresponding to the compliance judgment results of multiple compliance items is less than the preset weight threshold, then the current compliance status of the target terminal is determined to be compliant.

[0115] Furthermore, after obtaining the compliance judgment results of all software and their corresponding weights, the certification server calculates the weight sum and compares it with the preset weight threshold. If the weight sum is less than the weight threshold, the current compliance status of the target terminal is determined to be compliant.

[0116] For example, suppose the security status information blacklist and whitelist contain three compliance items, and the status codes corresponding to the three compliance items are 500, 200 and 504 respectively. According to Figure 6, the sum of the weights corresponding to the compliance judgment results of the three compliance items is 102. If the preset weight threshold is 100, the sum of the weights is greater than the weight threshold, then the current compliance status of the target terminal is determined to be non-compliant.

[0117] For example, assuming the status codes corresponding to the three compliance items are 500, 501, and 504 respectively, as shown in Figure 6, the sum of the weights corresponding to the three compliance items and the compliance judgment result is 3. If the sum of the weights is less than the weight threshold, then the current compliance status of the target terminal is determined to be compliant.

[0118] Furthermore, in practical applications, the authentication server can directly use status codes to represent the compliance judgment results of compliance items, or it can use status codes in combination with other parameters to accurately classify the compliance judgment results and adjust the corresponding weights according to the actual situation. This application does not impose any restrictions on this.

[0119] In another alternative embodiment, if the sum of the weights is greater than or equal to the weight threshold, the current compliance status of the target terminal is determined to be non-compliant.

[0120] The weighting threshold is determined by relevant personnel based on the actual situation, and this application does not impose any restrictions on it.

[0121] It should be noted that the compliance process in this application embodiment is a visual interface. Users can change the software information and other security status information of the target terminal at any time based on the current compliance page, thereby ensuring that the target terminal can successfully pass the compliance verification.

[0122] In addition, when the target terminal's current compliance status is non-compliant, the authentication server will send an alarm message to the target terminal. At this time, the alarm message carries a compliance log. Users can modify the compliance log to change the security status information of the target terminal and re-enter the compliance process based on the compliance entry point carried in the first alarm message.

[0123] Optionally, the authentication server can include the compliance entry only in the first alarm message to reduce data redundancy, or it can include the compliance entry in every alarm message to deal with situations where the compliance entry is updated or lost.

[0124] Based on step S503, the final compliance status of the target terminal is determined by summing the weights of the compliance judgment results of each compliance item. Compared with the traditional method that determines the compliance status of the target terminal to be non-compliant as long as there is one non-compliant item, the method provided in this application can avoid the problem of misjudging the status of some compliance items, which would lead to the target terminal being judged as non-compliant.

[0125] Step S203: If the target terminal is currently compliant, then allow the target terminal to access the target network and authorize the target terminal to access all network resources in the target network.

[0126] Specifically, in this embodiment of the application, when the target terminal is verified and its compliance status is determined to be compliant, the authentication server will allow the target terminal to access the target network and authorize the target terminal to access all network resources in the target network.

[0127] In another alternative embodiment, if the authentication and / or the target terminal's current compliance status is non-compliant, the authentication server controls the target terminal's access to restricted network resources in the target network.

[0128] In this application embodiment, all network resources refer to the sum of various information resources that can be utilized with the help of the network environment, and the restricted network resources are the target terminal's local data and some websites allowed by the authentication server.

[0129] Furthermore, in this embodiment of the application, during the process of the target terminal accessing network resources, the authentication server will also perform dynamic compliance verification on the security status information of the target terminal at preset time intervals, and adjust the network resource access permissions of the target terminal in the target network according to the dynamic compliance verification results.

[0130] For example, every half hour, the authentication server sequentially traverses multiple terminals on the access port, performing dynamic compliance verification on each terminal. If the security status information of any terminal does not meet the prescribed security level, its access to network resources is immediately restricted. In one possible implementation, the security levels in this application embodiment are only divided into two levels: secure and insecure, with compliance considered secure and non-compliance considered insecure. In another possible implementation, the server divides multiple security levels based on the sum of the weights corresponding to the compliance judgment results of each compliance item of the terminal, thereby enabling fine-grained control over terminal network access permissions and providing visual warnings to users. This application does not impose any limitations on this aspect.

[0131] It should be noted that in this embodiment of the application, when the authentication server adjusts the target terminal's access permissions to network resources, it needs to first kick the target terminal out of the target network, that is, cut off the connection between the target terminal and the target network, and then allow the target terminal to reconnect and obtain new access permissions. When the target terminal reconnects to the network, there is no need to prompt the user to re-enter identity information for identity verification. The process is seamless for the user to reconnect to the network.

[0132] The above embodiments will be further described in detail below using a specific application scenario.

[0133] Referring to Figure 7, which is a flowchart of a terminal network access scenario in an embodiment of this application, wherein:

[0134] Step S701: The user terminal requests network access.

[0135] As will be understood by those skilled in the art, a user terminal's request to join the network can be an association signal or connection signal when the user associates with an access device. The access device can be an access switch, a wireless access controller (AC), etc.

[0136] Step S702: A pop-up 802.1x authentication account and password input box appears.

[0137] As those skilled in the art will understand, after a user terminal sends a network access request, the access device interacts with the user terminal via 802.1x authentication, and an 802.1x authentication username and password input box pops up on the user terminal. To achieve clientless 802.1x authentication, it can be performed in conjunction with the Active Directory (AD) server built into the Windows system.

[0138] Step S703: Enter your account and password.

[0139] As will be understood by those skilled in the art, in response to the pop-up 802.1x authentication account and password input box, the user terminal enters the account and password to perform authentication.

[0140] Step S704: Determine if the account password is correct. If yes, proceed to step S705; otherwise, return to step S703.

[0141] As those skilled in the art will understand, the server receives the account and password from the user terminal and determines whether the account and password are correct.

[0142] If the server determines that the account and password are correct, the 802.1x authentication process is completed. In some possible implementations, the compliance process is integrated into the authentication process, and the server continues to execute the compliance authentication process in step S705.

[0143] If the server determines that the account and password are incorrect, it returns S703, requiring the user terminal to enter the account and password again for re-authentication.

[0144] Step S705: Verify whether the security status information is compliant. If yes, proceed to step S706; otherwise, proceed to step S707.

[0145] As will be understood by those skilled in the art, before verifying the security status information, the server sends a preset compliance entry to the user terminal, and the user terminal sends the security status information to the server through the compliance entry; the server determines whether the user terminal's security status information is compliant based on the security status information.

[0146] Those skilled in the art will understand that the server sends a preset compliance entry point to the target terminal through third-party service software. Sending the compliance entry point through third-party service software allows information to be sent without needing to download a dedicated client, thus achieving clientless compliance authentication. As will be understood by those skilled in the art, the third-party service software can be software capable of sending information to the target terminal, such as instant messaging software like WeChat and QQ; it can also be office software like DingTalk, Lark, and Zoom. In other possible implementations, the server may also send the preset compliance entry point to the target terminal via SMS or other means.

[0147] Step S706: Allow the user's terminal to access all network resources.

[0148] As will be understood by those skilled in the art, allowing a user terminal to access all network resources means allowing the user terminal to access all network resources under the network permissions corresponding to that user terminal. A server can allow a user terminal to access all network resources by including Virtual Local Area Network (VLAN) information in the authorization information. The user terminal then accesses network resources based on the VLAN information.

[0149] Step S707: Control the user terminal's access to restricted network resources and send an alarm message carrying the compliance entry point.

[0150] As will be understood by those skilled in the art, controlling a user terminal's access to restricted network resources refers to a server controlling a user terminal's access to restricted network resources. The server controls the network resources that a user terminal can access by issuing VLAN information. These restricted network resources include network resources capable of performing compliance authentication.

[0151] Because the implementation scheme of this application achieves identity authentication and compliance verification without a user terminal, those skilled in the art will understand that the server sends alarm information carrying the compliance entry to the user terminal through third-party service software or SMS to solve the problem of not being able to send messages without a client.

[0152] Step S708: Click the compliance entry to enter the compliance process and return to step S705.

[0153] In summary, this embodiment employs a dual authentication method of identity verification and compliance verification to control terminal network access, thereby improving network security. Furthermore, the use of a compliance plugin for terminal compliance verification enables users to perform self-service through a compliance entry point. Compared to the traditional 802.1x authentication method using client software, this reduces local terminal resource consumption and client software maintenance costs. Additionally, dynamic compliance verification of terminal security status information at preset time intervals allows for dynamic adjustment of access permissions for terminals already connected to the network, further enhancing network security.

[0154] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0155] Based on the same technical concept, referring to Figure 8, this application embodiment also provides a terminal network access control device, which includes:

[0156] The acquisition module 801 is used to acquire the identity information sent by the target terminal based on a preset network security channel and to authenticate the target terminal.

[0157] The verification module 802 is used to determine the current compliance status of the target terminal in response to a compliance request triggered by the target terminal based on a preset compliance entry after the identity information has been verified. The compliance entry is the call link corresponding to the compliance plugin required to determine the compliance status, and the security status information includes at least software information.

[0158] The control module 803 is used to allow the target terminal to access the target network and authorize the target terminal to access all network resources in the target network if the current compliance status of the target terminal is compliant.

[0159] Optionally, when verifying the identity information sent by the target terminal based on a preset network security channel, the verification module 802 is used for:

[0160] Obtain the validity verification result of the target terminal's digital certificate to the server, and verify the validity of the device digital certificate sent by the target terminal;

[0161] When the validity verification results of both the server digital certificate and the device digital certificate are passed, and the pre-stored historical identity information of the target terminal matches the identity information sent by the target terminal, the identity verification is deemed successful.

[0162] Optionally, after confirming that the identity information has passed authentication, and before responding to the compliance request triggered by the target terminal based on a preset compliance entry, the verification module 802 is used to:

[0163] If the most recent historical compliance record is compliant, then the current compliance status of the target terminal is directly determined to be compliant;

[0164] If the most recent historical compliance record is non-compliant, or if the target terminal does not have a historical compliance record, an alarm message is sent to the target terminal. The alarm message contains the compliance log and the compliance entry point. The compliance log is used to modify the security status information of the target terminal.

[0165] Optionally, when determining the current compliance status of the target terminal based on a preset list of security status information compliance, the verification module 802 is used to:

[0166] Obtain multiple compliance items from the security status compliance list, where each compliance item must contain at least the software name of the software to be assessed.

[0167] For each of the multiple compliance items, a compliance judgment is made on the status information corresponding to each compliance item, and the corresponding compliance judgment results and the weight of each compliance judgment result are obtained.

[0168] If the sum of the weights corresponding to the compliance judgment results of multiple compliance items is less than the preset weight threshold, then the current compliance status of the target terminal is determined to be compliant.

[0169] Optionally, the control module 803 is also used for:

[0170] If authentication fails and / or the target terminal's current compliance status is non-compliant, then the target terminal's access to restricted network resources in the target network will be restricted.

[0171] Optionally, the verification module 802 is also used for:

[0172] During the process of the target terminal accessing network resources, the security status information of the target terminal is dynamically verified for compliance at preset time intervals, and the network resource access permissions of the target terminal in the target network are adjusted according to the dynamic compliance verification results.

[0173] Based on the same technical concept, this application also provides an electronic device that can implement the terminal network access control method provided in the above embodiments of this application.

[0174] In one embodiment, the electronic device may be a server, a terminal device, or other electronic devices.

[0175] Referring to Figure 9, the electronic device may include:

[0176] At least one processor 901 and a memory 902 connected to at least one processor 901 are included. In this embodiment, the specific connection medium between the processor 901 and the memory 902 is not limited. Figure 9 illustrates an example where the processor 901 and the memory 902 are connected via a bus 900. The bus 900 is represented by a thick line in Figure 9. The connection methods between other components are for illustrative purposes only and are not intended to be limiting. The bus 900 can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in Figure 9, but this does not indicate that there is only one bus or one type of bus. Alternatively, the processor 901 can also be called a controller; the name is not limited.

[0177] In this embodiment, the memory 902 stores instructions executable by at least one processor 901. By executing the instructions stored in the memory 902, the at least one processor 901 can execute a terminal network access control method described above. The processor 901 can implement the functions of each module in the device shown in FIG8.

[0178] The processor 901 is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory 902 and calling data stored in memory 902, the processor can perform various functions and process data, thereby monitoring the device as a whole.

[0179] In one possible design, processor 901 may include one or more processing units. Processor 901 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may also not be integrated into processor 901. In some embodiments, processor 901 and memory 902 may be implemented on the same chip; in some embodiments, they may also be implemented on separate chips.

[0180] The processor 901 can be a general-purpose processor, such as a CPU, digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the terminal network access control method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or being executed by a combination of hardware and software modules within the processor.

[0181] Memory 902, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 902 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 902 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 902 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.

[0182] By designing and programming the processor 901, the code corresponding to a terminal network access control method described in the foregoing embodiments can be embedded into the chip, enabling the chip to execute the steps of a terminal network access control method as shown in Figure 2 during operation. How to design and program the processor 901 is a technique well-known to those skilled in the art and will not be elaborated upon here.

[0183] Based on the same inventive concept, embodiments of this application also provide a storage medium storing computer instructions that, when executed on a computer, cause the computer to perform a terminal network access control method described above.

[0184] In some possible implementations, various aspects of the terminal network access control method provided in this application can also be implemented in the form of a program product, which includes program code. When the program product is run on a device, the program code is used to cause the control device to perform the steps in the terminal network access control method according to various exemplary embodiments of this application described above.

[0185] It should be noted that although several units or sub-units of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.

[0186] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0187] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0188] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.

[0189] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.

[0190] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.

[0191] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A terminal network access control method, comprising: Obtain the identity information sent by the target terminal, and verify the identity of the target terminal based on the identity information; After confirming that the identity information has passed the identity verification, in response to the compliance request triggered by the target terminal based on the preset compliance entry, the current compliance status of the target terminal is determined, wherein the compliance entry is the call link corresponding to the compliance plugin required to determine the compliance status; as well as If the target terminal is currently compliant, then the target terminal is allowed to access the target network and is authorized to access all network resources in the target network.

2. The method as described in claim 1, wherein, The identity information sent by the target terminal includes the account and password information entered by the target terminal based on the 802.1x authentication input box.

3. The method as described in claim 1, wherein, After determining that the identity information has passed the identity verification, the method further includes: If the most recent historical compliance record is compliant, then the current compliance status of the target terminal is determined to be compliant.

4. The method according to any one of claims 1-3, wherein, Before responding to a compliance request triggered by the target terminal based on a preset compliance entry after confirming that the identity information has passed the authentication, the method further includes: If the most recent historical compliance record is non-compliant, or if the target terminal does not have a historical compliance record, an alarm message is sent to the target terminal, and the alarm message contains the compliance entry point.

5. The method of claim 4, wherein, Sending the alarm information to the target terminal includes: sending the alarm information to the target terminal via third-party software or SMS.

6. The method as described in claim 4 or 5, wherein, The alarm information also includes a compliance log, which is used to modify the security status information of the target terminal.

7. The method according to any one of claims 1-6, wherein, Before determining the current compliance status of the target terminal, the method includes: Obtain one or more compliance items from the security status information compliance list, wherein the one or more compliance items contain at least the software name of the software to be judged.

8. The method of claim 7, wherein, The one or more compliance items include multiple compliance items, and determining the current compliance status of the target terminal includes: Based on the status information corresponding to each of the multiple compliance items, the weight corresponding to each compliance item is obtained; and If the sum of the weights of the multiple compliance items is less than a preset weight threshold, then the current compliance status of the target terminal is determined to be compliant.

9. The method of claim 8, wherein, Obtaining the weight corresponding to each of the plurality of compliance items includes: Determine the status code corresponding to the first compliance item among the plurality of compliance items; wherein the status code corresponding to the first compliance item corresponds to an abnormal situation of the first compliance item; and The weight of the first compliance item is determined based on the status code corresponding to the first compliance item.

10. The method of claim 8 or 9, wherein, The multiple compliance items also include at least one of the following: the Internet Protocol (IP) address of the target terminal; or the Media Control Access (MAC) address of the target terminal.

11. The method of claim 10, wherein, The status information corresponding to the multiple compliance items includes at least one of the following: security status information blacklist, security status information whitelist, IP address compliance, IP address non-compliance, MAC address compliance, or MAC address non-compliance.

12. The method according to any one of claims 1-11, wherein, The step of obtaining the identity information sent by the target terminal includes: The identity information sent by the target terminal is obtained based on a preset network security channel.

13. The method of claim 12, wherein, The step of obtaining the identity information sent by the target terminal based on a preset network security channel, and verifying the identity of the target terminal based on the identity information, includes: Obtain the validity verification result of the server digital certificate from the target terminal, and verify the validity of the device digital certificate from the target terminal; When the validity verification results of the server digital certificate and the device digital certificate are both passed, and the pre-stored historical identity information of the target terminal matches the identity information sent by the target terminal, the identity verification is determined to be successful.

14. The method according to any one of claims 1-13, wherein, The step of obtaining the identity information sent by the target terminal and verifying the identity of the target terminal based on the identity information further includes: If the identity verification fails, the identity information of the target terminal is retrieved again.

15. The method according to any one of claims 1-14, wherein, The method further includes: If the target terminal is currently in an uncompliant state, then control the target terminal to access restricted network resources in the target network.

16. The method according to any one of claims 1-15, wherein, The method further includes: During the process of the target terminal accessing network resources, the security status information of the target terminal is verified for compliance at preset time intervals, and the network resource access permissions of the target terminal in the target network are adjusted according to the results of the compliance verification.

17. A terminal network access control device, comprising: The acquisition module is used to acquire the identity information sent by the target terminal and to authenticate the target terminal based on the identity information; The verification module is used to determine the current compliance status of the target terminal in response to a compliance request triggered by the target terminal based on a preset compliance entry after the identity information has been verified. The compliance entry is the call link corresponding to the compliance plugin required to determine the compliance status. as well as The control module is configured to allow the target terminal to access the target network and authorize the target terminal to access all network resources in the target network if the target terminal's current compliance status is compliant.

18. The apparatus of claim 17, wherein, The device further includes: The sending module is used to send alarm information to the target terminal; wherein the alarm information includes the compliance entry point.

19. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein, When the processor executes the computer program, it implements the method as described in any one of claims 1-16.

20. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1-16.

Citation Information

Patent Citations

  • Terminal security access method and system

    CN116390091A

  • Network access control method and device, equipment and storage medium

    CN116939608A

  • Method of controlling network access and its system

    CN1753364A

  • Compliance tool

    US20110219059A1