The invention belongs to the technical field of
network security, and relates to a terminal security
access control method and device,
computer equipment and a storage medium, the method comprises the following steps: deploying an infrastructure for terminal security access, the infrastructure comprising a
client, a
security system and a
server component; the method comprises the following steps: performing initial registration on
terminal equipment, and realizing unique binding of a terminal identity and loading of a basic
security policy by acquiring an equipment
fingerprint, issuing a
certificate and configuring a policy; the user identity and the equipment credibility are verified in real time through a multi-factor dynamic
authentication mechanism; through signature
verification and encrypted transmission, application and
network communication authentication is carried out, and application legality,
communication channel security and operation environment credibility are ensured; and after the
authentication is passed, trusted connection is established, fine-grained
authorization is implemented, and security isolation of a
service layer is realized through dynamic token and API management and control. The problems that in existing terminal
access control, the authentication dimension is single, the
authorization granularity is rough, and
dynamic management and control are lacked are effectively solved.