WO2024183779A1 - 资源访问控制方法及装置、计算机可读介质和电子设备 - Google Patents
资源访问控制方法及装置、计算机可读介质和电子设备 Download PDFInfo
- Publication number
- WO2024183779A1 WO2024183779A1 PCT/CN2024/080454 CN2024080454W WO2024183779A1 WO 2024183779 A1 WO2024183779 A1 WO 2024183779A1 CN 2024080454 W CN2024080454 W CN 2024080454W WO 2024183779 A1 WO2024183779 A1 WO 2024183779A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- access
- target object
- resource
- information
- target
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/102—Entity profiles
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
Definitions
- the present disclosure relates to a resource access control method and device, a computer-readable medium and an electronic device.
- the present disclosure provides a resource access control method, applied to a network control device, the method comprising:
- the present disclosure provides a resource access control method, which is applied to a business system, and the method includes:
- the target resource belongs to a target type resource
- sending an authentication request to the network control device wherein the authentication request includes the identity information of the target object and the target resource that the target object is to access, and the authentication request is used to enable the network control device to obtain the historical resource access information and the historical security status information of the target object from the business system according to the identity information of the target object, and determine the access permission information of the target object for the target resource according to the historical resource access information and the historical security status information, and send the access permission information to the business system;
- an operation for the resource access request is determined according to the access permission information.
- the present disclosure provides a resource access control device, applied to a network control device, the device comprising:
- a first receiving module is configured to receive an authentication request sent by a business system, wherein the authentication request is sent by the business system when it is determined that a target resource to be accessed by the target object belongs to a resource of a target type according to a resource access request sent by the target object, and the authentication request includes identity information of the target object and the target resource to be accessed by the target object;
- an acquisition module configured to, in response to the authentication request, acquire historical resource access information and historical security status information of the target object from the business system according to the identity information of the target object;
- a determination module configured to determine access permission information of the target object for the target resource according to the historical resource access information and the historical security status information
- the first sending module is configured to send the access permission information to the business system, wherein the access permission information is used to enable the business system to determine an operation for the resource access request according to the access permission information.
- the present disclosure provides a resource access control device, applied to a business system, the device comprising:
- a second receiving module is configured to receive a resource access request sent by a target object, wherein the resource access request is used to request access to a target resource;
- a second sending module configured to send an authentication request to the network control device when the target resource belongs to a target type of resource, wherein the authentication request includes the identity information of the target object and the target resource to be accessed by the target object, and the authentication request is used to enable the network control device to obtain historical resource access information and historical security status information of the target object from the business system according to the identity information of the target object, determine access permission information of the target object for the target resource according to the historical resource access information and the historical security status information, and send the access permission information to the business system;
- the third receiving module is configured to determine an operation for the resource access request according to the access permission information when receiving the access permission information sent by the network security device.
- the present disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the method described in the first aspect, or implements the steps of the method described in the second aspect.
- an electronic device including:
- a processing device is used to execute the computer program in the storage device to implement the steps of the method described in the first aspect, or to implement the steps of the method described in the second aspect.
- Fig. 1 is a schematic diagram of an application scenario of a resource access control method provided according to an exemplary embodiment.
- FIG2 is a schematic flow chart of a resource access control method according to an exemplary embodiment.
- Fig. 3 is a schematic flow chart of a resource access control method provided according to yet another exemplary embodiment.
- Fig. 4 is a schematic flow chart of a resource access control method provided according to yet another exemplary embodiment.
- FIG5 is a schematic flow chart of a resource access control method according to another exemplary embodiment.
- Fig. 6 is a schematic diagram of the structure of a resource access control device provided according to an exemplary embodiment.
- FIG7 is a schematic diagram of a resource access control device according to another exemplary embodiment.
- Fig. 8 is a schematic structural diagram of an electronic device according to an exemplary embodiment.
- a prompt message is sent to the user to clearly prompt the user that the operation requested to be performed will require obtaining and using the user's personal information.
- the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, application, server, or storage medium that performs the operation of the technical solution of the present disclosure according to the prompt message.
- the prompt information in response to receiving an active request from the user, may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form.
- the pop-up window may also carry a selection control for the user to choose "agree” or “disagree” to provide personal information to the electronic device.
- FIG1 is a schematic diagram of an application scenario of a resource access control method provided according to an exemplary embodiment.
- the resource access control method provided by the embodiment of the present disclosure is applicable to the application scenario shown in FIG1 .
- the application scenario includes a terminal device 101, a business system 102, and a network control device 103.
- the terminal device 101 is connected in communication with the business system 102
- the business system 102 is connected in communication with the network control device 103.
- the communication connection may refer to data interaction by means of a wired connection or a wireless connection.
- the terminal device 101 sends a resource access request of a target object to the business system 102.
- the resource access request may include the security status information of the target object and the target resource to be accessed by the target object, wherein the security status information includes the identity information of the target object.
- the business system 102 sends an authentication request to the network control device 103 when the target resource belongs to a resource of the target type, wherein the authentication request includes the identity information of the target object and the target resource to be accessed.
- the network control device 103 obtains the historical resource access information and the historical security status information of the target object from the business system 102 according to the identity information of the target object, and determines the access permission information of the target object for the target resource according to the historical resource access information and the historical security status information.
- the historical resource access information is the resources accessed by the target object each time the business system 102 accesses the business system 102, and the historical security status information is the information recorded by the business system 102.
- the network control device 103 records the security status information of the target object each time it accesses the business system 102. After obtaining the access permission information, the network control device 103 sends the access permission information to the business system 102.
- the business system 102 receives the access permission information released by the network control device 103, and determines the operation for the resource access request according to the access permission information. For example, when the access permission information indicates that the target object is allowed to access the target resource, the business system 102 can forward the resource access request of the target object to the target business, so that the target object can access the target resource of the target business.
- the terminal device 101 can be a mobile terminal such as a mobile phone, a laptop computer, a digital broadcast receiver, a PDA (personal digital assistant), a PAD (tablet computer), a PMP (portable multimedia player), a vehicle terminal (such as a vehicle navigation terminal), etc., and a fixed terminal such as a digital TV, a desktop computer, etc.
- the target object can send a resource access request to the business system 102 through a client installed in the terminal device 101, and the client can be a web client or an application.
- the business system 102 may include an authentication service and a background server for deploying an application system, wherein the authentication service is used to verify the access rights of the target object and forward the resource access request to the application system so that the target object can access the resources in the application system.
- the authentication service is used to verify the access rights of the target object and forward the resource access request to the application system so that the target object can access the resources in the application system.
- the terminal device 101 logs in to the authentication service by entering the target object's account and password, and the authentication service creates a session after successful authentication.
- the target object initiates a resource access request to the application system of the background server through the authentication server to access the resources in the application system.
- the network control device 103 acts as a server for verifying the access permission information of the target object for the target resource.
- the network control device 103 can deploy a dynamic control engine to implement the resource access control method provided in the embodiment of the present disclosure and executed by the network control device 103. It should be understood that since the number of business systems 102 used by the enterprise is large, the business systems 102 connected to the network control device 103 may include multiple ones.
- Fig. 2 is a flow chart of a resource access control method provided according to an exemplary embodiment.
- the resource access control method provided by the embodiment of the present disclosure can be applied to the network control device 103 shown in Fig. 1.
- the resource access control method can include the following steps.
- step 210 an authentication request sent by the business system is received, wherein the authentication request is sent by the business system when it is determined, based on the resource access request sent by the target object, that the target resource to be accessed by the target object is a resource of the target type, and the authentication request includes the identity information of the target object and the target resource to be accessed by the target object.
- the network control device receives the authentication request sent by the business system through a communication connection with the business system.
- the authentication request may include the identity information of the target object and the target resource that the target object is going to access.
- the target object refers to the account logged in to the terminal device, and the identity information of the target object may refer to the target object's account, password, verification code, and other information used to verify the identity.
- the identity information may also refer to facial information, fingerprint information, and other biometric features used to verify the identity.
- the target resource that the target object is going to access refers to a specific resource in the business system that the resource access request sent by the target object this time needs to access.
- the target resource may refer to a resource in the application system, or may refer to a network resource, such as VPN, Wi-Fi (Wireless Fidelity, wireless local area network), and other network resources.
- the authentication request is a resource access request sent by the target object to the business system through the terminal device, and is sent to the network control device when the target resource to be accessed by the target object is determined to be a resource of the target type according to the resource access request.
- the authentication request is used to request the network control device to determine whether to allow the target object to access the target resource.
- resources belonging to the target type indicate that the resource is a sensitive resource in the business system, and the target object requires a higher security level when accessing the resource. Therefore, when the target resource that the target object is going to access is a resource belonging to the target type, the network control device is required to evaluate whether there is a risk for the target object to access the target resource under the current security state.
- the business system can control the access of the target object through a data access policy.
- a data access policy includes resources that the target object can access and resources that it cannot access.
- step 220 in response to the authentication request, historical resource access information and historical security status information of the target object are obtained from the business system according to the identity information of the target object.
- the network control device responds to the authentication request sent by the business system, accesses the business system, and obtains historical resource access information and historical security status information matching the identity information of the target object from the business system.
- Historical resource access information refers to information about resources that the target object has accessed in the past, such as resource information about the business system that the target object has recently accessed. For example, each time the target object accesses a resource of the business system, the business system can record the time, geographic location, name of the resource accessed, and operation behavior of the target object to access the resource, forming a historical record. It should be understood that the operation behavior on the resource can be viewing, modifying, and sending to the external network.
- Historical security status information refers to the security status information when the target object accesses the business system at a historical time.
- the resource access request sent by the target object may carry the security status information of the target object.
- the business system receives the resource access request, it records the security status information carried by the resource access request to form historical security status information.
- the security status information may include the identity information of the target object and the network security information used to characterize the security status of the network environment where the target object is located.
- the network security information may include at least one of the device information, software environment information and geographic location information of the terminal device corresponding to the target object.
- the device information may refer to information such as the IP (Internet Protocol) address and MAC (Media Access Control) address of the terminal device.
- the software environment information may refer to information used to characterize the security status of the network environment of the terminal device when accessing the business system.
- the software environment information may include the applications installed by the terminal device, the ports opened by the terminal device, the network type used, etc. Among them, the software environment information may be used to determine whether the terminal device is in a secure state when accessing the business system. For example, when the applications installed by the terminal device include risky applications, it indicates that the terminal device is in an unsafe state. When the applications installed on the terminal device do not include antivirus applications, it means that the terminal device is in an unsafe state. For example, when a risky port is opened on the terminal device, it means that the terminal device is in an unsafe state. For another example, when the network type used by the terminal device is a public network, it means that the terminal device is in an unsafe state.
- the network control device can read the historical resource access information and historical security status information of the target object from the log database of the business system.
- the business system can store the resource access information and security status information of the target object each time it accesses the business system in the log database in the form of a log, forming the historical resource access information and historical security status information.
- the network control device receives an authentication request, the network control device responds to the authentication request and reads the log data matching the identity information of the target object from the log database of the business system to obtain the historical resource access information and historical security status information of the target object.
- step 230 the access permission information of the target object to the target resource is determined according to the historical resource access information and the historical security status information.
- the network control device obtains the historical resource access information of the target object from the business system. After obtaining the historical resource access information and the historical security status information, the network control device determines whether the target object can access the target resource and obtains the access permission information according to the historical resource access information and the historical security status information.
- the target object when the historical resource access information of the target object indicates that the target object has visited risky websites in the past, the target object cannot access the target resource.
- the target object when the historical security status information of the target object indicates that the terminal device of the target object has installed a risky application, the target object cannot access the target resource.
- historical resource access information and historical security status information may be input into an access policy model to obtain access permission information output by the access policy model.
- the access policy model may be obtained by training a neural network model using sample resource access information and sample security status information marked with access permission information.
- the historical resource access information and historical security status information required to access the resource may be different.
- the target object is at the highest security level to access the resource, which requires the target object's historical resource access information and historical security status information to meet higher requirements.
- step 240 access permission information is sent to the business system, wherein the access permission information is used to enable the business system to determine an operation for the resource access request according to the access permission information.
- the network control device can send the access permission information to the business system through the communication connection with the business system, so that the business system determines the operation for the resource access request according to the access permission information.
- the operation for the resource access request can be to determine whether the target object is allowed to access the target resource and/or whether a higher level of authentication is required for the target object.
- the business system blocks the target object's resource access request to the target resource.
- the business system releases the target object's resource access request to the target resource so that the target object can access the target resource.
- the business system sends an identity authentication request to the target object's terminal device. This allows the target object to perform a higher level of authentication.
- the VPN service system After the VPN service system receives the resource access request sent by the target object, if the service system determines that the target resource to be accessed by the resource access request belongs to the target type of resource, it sends an authentication request to the network control device to obtain the access permission information sent by the network control device in response to the authentication request. If the access permission information indicates that the target object is not allowed to access the target resource, the VPN service system blocks the forwarding of the target resource so that the target object cannot access the target resource. If the access permission information indicates that the target object is allowed to access the target resource, the VPN service system forwards the target resource to the terminal device of the target object so that the target object can access the target resource.
- the business system determines the operation for the resource access request according to the access permission information, so as to dynamically determine the permission of the target object to access the target resource belonging to the target type, so as to prohibit the target object from accessing the target resource when the real-time security status of the terminal device does not support the target object to access the target resource, and protect the business system from being damaged.
- the business system determines the operation for the resource access request according to the access permission information, so as to dynamically determine the permission of the target object to access the target resource belonging to the target type, so as to prohibit the target object from accessing the target resource when the real-time security status of the terminal device does not support the target object to access the target resource, and protect the business system from being damaged.
- the resource access control method it is possible to prohibit the target object from accessing the target resource when the real-time security status of the terminal device does not support the target object to access the target resource without affecting the working performance of the business system.
- the network control device may store the access permission information in a disposal log database, so that in a subsequent traceability audit process, the source can be traced based on the data in the disposal log database.
- the target risk item triggered by the target object can be determined based on historical resource access information and historical security status information in combination with a preset mapping relationship, wherein the mapping relationship includes the correspondence between different combinations of historical resource access information and historical security status information and different risk items, and the access permission information of the target object for the target resource can be determined based on the target risk item.
- mapping relationship refers to the corresponding relationship between different risk items and different combinations of historical resource access information and historical security status information.
- a plurality of corresponding relationships can be pre-stored in the network control device to determine whether there is a risk when the target object accesses the business system.
- historical resource access information includes resource access time, geographic location, name information of the accessed resource, and operation behavior on the resource.
- Security status information may include the identity information of the target object and network security information used to characterize the security status of the network environment where the target object is located. If the geographic location information in the historical resource access information represents that the geographic location of the target object when requesting access to the target resource is not the target object's usual location for accessing the business system, the geographic location change risk item is triggered. Accordingly, the access permission information corresponding to the geographic location change risk item may be to perform multiple authentications on the target object and allow access to the target resource after the authentication is passed.
- the data outbound risk item is triggered. Accordingly, the access permission information corresponding to the data outbound risk item may be that the target object is prohibited from accessing the target resource.
- the device security risk item is triggered. Accordingly, the access permission information corresponding to the device security risk item may be to prohibit the target object from accessing the target resource and/or prohibit the target object from accessing the business system.
- mapping relationship is a calculation rule used to calculate whether there are risk items in historical resource access information and historical security status information. If it is determined based on all mapping relationships that the target object does not trigger any risk items, the target object can be allowed to access the target resource.
- historical security status information can reflect changes in the security status information of terminal devices within historical time periods. For example, historical security status information can be used to determine whether the terminal device used by the target object to access the business system has changed, whether the network environment has changed, and so on. Historical resource access information can reflect changes in the behavior habits of the target object in accessing resources in the business system within historical time periods. For example, historical resource access information can be used to determine whether the type of resources accessed by the target object has changed, whether the operation behavior on the resources has changed, and so on.
- the historical behavior of the target object in accessing the business system can be analyzed to dynamically adjust the target object's access rights to sensitive resources in the business system according to changes in behavior, thereby protecting sensitive resources in the business system from damage.
- Fig. 3 is a schematic flow chart of a resource access control method provided according to yet another exemplary embodiment. As shown in FIG. 3 , in some practicable implementations, the resource access control method may include the following steps.
- step 310 when the security status information of the target object accessing the business system changes, a data access policy of the target object is determined according to the security status information, wherein the data access policy includes resources that the target object can access and resources that it cannot access.
- the network control device re-determines the data access policy of the target object according to the latest security status information of the target object, including the resources that the target object can access and the resources that it cannot access.
- the data access policy refers to the access rights for resources in the business system that are not of the target type when the target object accesses the business system.
- the data access policy may include a first resource set that is not accessible to the target object and a second resource set that is accessible to the target object.
- the resources included in the first resource set and the second resource set may be all other resources that are not of the target type that can be provided by the business system.
- Each target object has a default data access policy, which can be an initial data access policy configured for the target object according to the target object's own permission level.
- the business system provides the target object with resources that the object can access according to the default data access policy.
- the network control device recalculates the data access policy of the target object according to the security status information of the target object, so that the business system can adjust the target system's access rights to resources in the business system according to the recalculated data access policy.
- determining the data access policy of the target object according to the security status information may be to calculate the security level of the terminal device according to the security status information, and determine the data access policy according to the security level.
- the first security status information corresponds to the first security level
- the target object can access resources A, resource B, resource C, resource D, and resource E.
- the security level of the target object is changed to the second security level, since the second security level is lower than the first security level, and the second security level cannot reach the minimum security level required to access resources D and resource E, then under the identity level of the target object and the second security level, the target object can access resources A, resource B, and resource C.
- the network control device may receive an information change event sent by a security information data source, wherein the information change event is a change in the security information data source after detecting the security status of the target object. Sent to the network control device when the information changes.
- the information change event is used to notify the network control device that the security status information of the target object accessing the business system has changed.
- the security information data source will record the latest security status information of the target object, and generate an information change event when the latest security status information changes from the last recorded security status information.
- the network control device subscribes to the information change event, and when the information change event is detected, it determines that the security status information of the target object accessing the business system has changed, and begins to recalculate the target object's data access policy for the business system based on the target object's latest security status information.
- the security information data source can be set in the business system. For example, each time the business system receives a resource access request sent by a terminal device, the business system records the security status information carried in the resource access request through the security information data source.
- the security information data source can also be set in the network control device.
- the network control device can store the security status information of the target object, and the administrator or the terminal device can update the security status information of the target object stored in the network control device.
- a data access policy is sent to the business system, wherein the data access policy is used to enable the business system to determine the access rights of the target object to other resources in the business system except for the target type of resources according to the data access policy.
- the network control device sends the data access policy to the business system, so that the business system adjusts the target object's access rights to the business system according to the data access policy.
- the business system allows the target object to access resources that the target object can access, and denies the target object access to resources that the target object cannot access.
- the data access policy is the access rights for resources other than the target type in the business system.
- the access rights for the target object to the target type resources can be determined according to the above steps 210 to 240.
- the network control device can create a permission change task, save the permission change task in a task queue, execute the permission change task in the task queue, and store the data access policy in a data access table, where the data access table is used for the business system to pull the data access policy from the data access table.
- the network control device responds to the information change event and determines the data according to the security status information. Access policy, create a permission change task, and deliver the permission change task to the task queue. Then, the network control device executes the permission change task in the task queue and stores the corresponding data access policy in the data access table.
- the data access table is used for the business system to pull the data access policy from the data access table. For example, the business system can periodically pull the data access policy from the data access table and update the data access policy in the business system.
- the permission change task in the task queue will be completed only after the corresponding data access strategy is successfully pulled by the business system. If the data access strategy has not been successfully pulled by the business system, the permission change task in the task queue will not be completed. Instead, the permission change task can be executed multiple times so that the data access strategy can be successfully pulled by the business system.
- the above data access strategy can be used to control the business system's access rights to resources other than the target resource for the target object, and can also be used to control the access rights to the target resource. In actual application, it can be set as needed.
- the data access policy of the target object is determined according to the security status information of the target object, and the data access policy is sent to the business system, so that the business system adjusts the access rights of the target object to the business system according to the data access policy, so that the business system does not need to evaluate every access to the target object, but directly determines the resource access rights of the target object according to the data access policy, thereby not affecting the performance of the business system, especially for a business system with large traffic, if every access to the target object is evaluated, the performance of the business system will be reduced.
- the process of determining the data access policy is placed in the network control device, so that the permission change behavior of the target object will not invade the function of the business system, thereby ensuring the normal operation of the business system.
- the network control device can obtain a permission change message based on a data access policy and send the permission change message to a business system, wherein the permission change message is used to enable the business system to send the permission change message to the terminal device through a long connection channel between the business system and the terminal device of the target object, so as to display the permission change message on the terminal device.
- the network control device can generate a permission change message according to the data access policy.
- the permission change message is used to indicate that the target object's resource access rights to the business system have changed. For example, when the data access policy indicates that the target object's access rights to the business system have been downgraded, a permission change message can be generated to indicate that the target object's access rights to the business system have been downgraded.
- the network control device After generating the permission change message, the network control device sends the permission change message to the business system.
- the business system receives the permission change message and sends the permission change message to the terminal device through the long connection channel between the terminal device and the target object to display the permission change message in the terminal device so that the target object can eliminate the risk information according to the permission change message.
- the long connection channel can refer to a long connection between the terminal device and the business system through WebSocket (a protocol for full-duplex communication on a single TCP (Transmission Control Protocol) connection).
- WebSocket a protocol for full-duplex communication on a single TCP (Transmission Control Protocol) connection.
- the network control device may store the permission change message in a message queue, wherein the message queue is used for the business system to pull the permission change message from the message queue.
- the business system pulls the permission change message from the message queue, it sends the permission change message to the terminal device through WebSocket.
- the terminal device displays the received WebSocket message in the client as a reminder or notification to remind the target object to repair the existing risks.
- the network control device will update the data access policy for the target object in the business system, so that the target object can resume access to the business system.
- the target object can perceive the change in access rights according to the permission change message, and guide the target object to repair the existing risk items.
- Fig. 4 is a flow chart of a resource access control method provided according to another exemplary embodiment.
- the resource access control method provided by the embodiment of the present disclosure can be applied to the business system 102 shown in Fig. 1.
- the resource access control method can include the following steps.
- step 410 a resource access request sent by a target object is received, wherein the resource access request is used to request access to a target resource.
- the business system receives a resource access request sent by the target object to the business system through the terminal device through the communication connection between the business system and the terminal device.
- the resource access request is used to request access to the target resource in the business system.
- step 420 if the target resource is a resource of the target type, in response to the resource access request sent by the target object, an authentication request is sent to the network control device, wherein the authentication request includes: The authentication request includes the identity information of the target object and the target resource that the target object is going to access. The authentication request is used to enable the network control device to obtain the historical resource access information and historical security status information of the target object from the business system based on the identity information of the target object, and determine the access permission information of the target object for the target resource based on the historical resource access information and historical security status information, and send the access permission information to the business system.
- the business system receives the resource access request sent by the target object, and in response to the resource access request, when it is determined that the target resource to be accessed by the target object is a resource of the target type, sends an authentication request to the network control device through the communication connection with the network control device.
- the authentication request may include the identity information of the target object and the target resource to be accessed by the target object.
- the target object refers to the account logged in to the terminal device
- the identity information of the target object may refer to the target object's account, password, verification code, etc. for verifying the identity.
- the identity information may also refer to biometric features such as face information and fingerprint information for verifying the identity.
- the target resource to be accessed by the target object refers to a specific resource in the business system that the resource access request sent by the target object this time needs to access.
- the target resource may refer to a resource in the application system, or may refer to a network resource, such as a VPN, Wi-Fi, or other network resource.
- the authentication request is a resource access request sent by the target object to the business system through the terminal device, and is sent to the network control device when the target resource to be accessed by the target object is determined to be a resource of the target type according to the resource access request.
- the authentication request is used to request the network control device to determine whether to allow the target object to access the target resource.
- resources belonging to the target type indicate that the resource is a sensitive resource in the business system, and the target object requires a higher security level when accessing the resource. Therefore, when the target resource that the target object is going to access is a resource belonging to the target type, the network control device is required to evaluate whether there is a risk for the target object to access the target resource under the current security state.
- the business system can control the access of the target object through a data access policy.
- a data access policy includes resources that the target object can access and resources that it cannot access.
- step 430 when access permission information sent by the network security device is received, an operation for the resource access request is determined according to the access permission information.
- the business system receives the access permission information sent by the network control device and In the case of access permission information sent by the network security device, the operation for the resource access request is determined according to the access permission information.
- the business system blocks the target object's resource access request to the target resource.
- the business system releases the target object's resource access request to the target resource so that the target object can access the target resource.
- the business system sends an identity authentication request to the target object's terminal device so that the target object performs a higher level of identity authentication.
- the business system may determine the access rights of the target object to other resources in the business system except for the target type of resources according to the data access policy.
- the data access policy refers to the access rights for resources in the business system that are not of the target type when the target object accesses the business system.
- the data access policy may include a first resource set that is not accessible to the target object and a second resource set that is accessible to the target object.
- the resources included in the first resource set and the second resource set may be all other resources that are not of the target type that can be provided by the business system.
- the data access policy is the access rights for resources other than the target type in the business system.
- the business system can determine the access rights of the target object for the target type resources according to the above steps 410 to 430.
- Data access policy is determined by the network control device based on the security status information when the security status information of the target object of the access business system changes.
- the data access policy includes the target object, The resources that the target object can access and the resources that it cannot access.
- the business system does not need to evaluate every access to the target object, but directly determines the resource access rights of the target object based on the data access policy, so as not to affect the performance of the business system, especially for business systems with large traffic, if every access to the target object is evaluated, it will reduce the performance of the business system.
- the process of determining the data access policy is placed in the network control device, so that the permission change behavior of the target object will not invade the function of the business system, thereby ensuring the normal operation of the business system.
- a business system when a business system receives a permission change message sent by a network control device, it can send the permission change message to the terminal device through a long connection channel between the terminal device and the target object, so as to display the permission change message on the terminal device, wherein the permission change message is generated by the network control device according to the data access policy, and the permission change message is used to indicate that the resource access rights of the target object to the business system have changed.
- the target object can perceive the change of access rights according to the permission change message, and guide the target object to repair the existing risk items.
- Fig. 5 is a flow chart of a resource access control method provided according to another exemplary embodiment. As shown in Fig. 5, the resource control method may include the following steps.
- the terminal device sends a resource access request to the business system
- the business system receives a resource access request
- the business system sends an authentication request to the network control device
- the network control device receives the authentication request
- the network control device requests the business system for historical resource access information and historical security status information of the target object
- the business system sends historical resource access information and historical security status information of the target object to the network control device;
- the network control device receives the historical resource access information and historical security status of the target object. Status information;
- the network control device determines access permission information according to historical resource access information and historical security status information
- the network control device sends access permission information to the business system
- S510 The business system receives access permission information.
- FIG6 is a schematic diagram of the structure of a resource access control device provided according to an exemplary embodiment. As shown in FIG6 , the embodiment of the present disclosure provides a resource access control device, which is applied to a network control device.
- the resource access control device 600 may include:
- the first receiving module 601 is configured to receive an authentication request sent by a business system, wherein the authentication request is sent by the business system when it is determined that a target resource to be accessed by the target object belongs to a target type of resource according to a resource access request sent by the target object, and the authentication request includes identity information of the target object and the target resource to be accessed by the target object;
- the acquisition module 602 is configured to obtain historical resource access information and historical security status information of the target object from the business system according to the identity information of the target object in response to the authentication request;
- the determination module 603 is configured to determine the access permission information of the target object for the target resource according to the historical resource access information and the historical security status information;
- the first sending module 604 is configured to send access permission information to the business system, wherein the access permission information is used to enable the business system to determine an operation for the resource access request according to the access permission information.
- the determination module 603 is specifically configured to:
- the target risk item triggered by the target object is determined, wherein the mapping relationship includes the corresponding relationship between different combinations of historical resource access information and historical security status information and different risk items;
- the apparatus 600 further includes:
- a policy adjustment module is configured to determine a data access policy for a target object according to the security status information when the security status information of the target object accessing the business system changes, wherein the data access policy includes resources that the target object can access and resources that it cannot access;
- the policy sending module is configured to send a data access policy to the business system, wherein the data access policy is used to enable the business system to determine the access rights of the target object to other resources in the business system except for the target type of resources according to the data access policy.
- the apparatus 600 further includes:
- the message generation module is configured to obtain a permission change message according to the data access policy, wherein the permission change message is used to indicate that the resource access rights of the target object to the business system have been changed;
- the message sending module is configured to send a permission change message to the business system, wherein the permission change message is used to enable the business system to send the permission change message to the terminal device through a long connection channel between the business system and the terminal device of the target object, so as to display the permission change message in the terminal device.
- FIG7 is a schematic diagram of a structure of a resource access control device provided according to another exemplary embodiment. As shown in FIG7 , the embodiment of the present disclosure provides a resource access control device, which is applied to a business system.
- the resource access control device 700 may include:
- the second receiving module 701 is configured to receive a resource access request sent by a target object, wherein the resource access request is used to request access to a target resource;
- the second sending module 702 is configured to send an authentication request to the network control device when the target resource belongs to a target type of resource, wherein the authentication request includes the identity information of the target object and the target resource to be accessed by the target object, and the authentication request is used to enable the network control device to obtain historical resource access information and historical security status information of the target object from the business system according to the identity information of the target object, determine the access permission information of the target object for the target resource according to the historical resource access information and the historical security status information, and send the access permission information to the business system;
- the third receiving module 703 is configured to determine an operation for the resource access request according to the access permission information when receiving the access permission information sent by the network security device.
- the apparatus 700 further includes:
- a policy receiving module is configured to determine, upon receiving a data access policy of a target object sent by a network control device, access rights of the target object to other resources in the business system except for resources of the target type according to the data access policy;
- the data access policy is determined by the network control device based on the security status information when the security status information of the target object accessing the business system changes. Includes the resources that the target object can access and the resources that it cannot access.
- the apparatus 700 further includes:
- the message receiving module is configured to send the permission change message to the terminal device through the long connection channel between the terminal device and the target object when receiving the permission change message sent by the network control device, so as to display the permission change message in the terminal device, wherein the permission change message is generated by the network control device according to the data access policy, and the permission change message is used to indicate that the resource access rights of the target object to the business system have changed.
- FIG8 shows a schematic diagram of the structure of an electronic device 800 (such as the business system 102 or the network control device 103 in FIG1 ) suitable for implementing the embodiment of the present disclosure.
- the terminal device in the embodiment of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc.
- the electronic device shown in FIG8 is only an example and should not bring any limitation to the functions and scope of use of the embodiment of the present disclosure.
- the electronic device 800 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 801, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage device 808 to a random access memory (RAM) 803.
- a processing device 801 e.g., a central processing unit, a graphics processing unit, etc.
- RAM random access memory
- various programs and data required for the operation of the electronic device 800 are also stored.
- the processing device 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804.
- An input/output (I/O) interface 805 is also connected to the bus 804.
- the following devices may be connected to the I/O interface 805: input devices 806 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; output devices 807 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 808 including, for example, a magnetic tape, a hard disk, etc.; and communication devices 809.
- the communication device 809 may allow the electronic device 800 to communicate wirelessly or wired with other devices to exchange data.
- FIG. 8 shows an electronic device 800 with various devices, it should be understood that it is not required to implement or have all the devices shown. More or fewer devices may be implemented or have alternatively.
- an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart.
- the computer program can be downloaded and installed from the network through the communication device 809, or installed from the storage device 808, or installed from the ROM 802.
- the processing device 801 the above functions defined in the method of the embodiment of the present disclosure are executed.
- the computer-readable medium disclosed above may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two.
- the computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above.
- Computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
- a computer-readable storage medium may be any tangible medium containing or storing a program that may be used by or in combination with an instruction execution system, device or device.
- a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried.
- This propagated data signal may take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above.
- the computer readable signal medium may also be any computer readable medium other than a computer readable storage medium, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device.
- the program code contained on the computer readable medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
- the terminal devices, business systems, and network control devices may communicate using any currently known or future developed network protocol such as HTTP (HyperText Transfer Protocol), and may be interconnected with any form or medium of digital data communication (e.g., a communication network).
- HTTP HyperText Transfer Protocol
- Examples of communication networks include a local area network ("LAN”), a wide area network ("WAN”), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.
- the computer-readable medium may be included in the electronic device, or may exist independently without being installed in the electronic device.
- the above-mentioned computer-readable medium carries one or more programs.
- the electronic device receives an authentication request sent by a business system, wherein the authentication request is sent by the business system in response to a resource access request sent by a target object, and the authentication request includes the identity information of the target object and the target resource that the target object is to access; in response to the authentication request, obtains historical resource access information and historical security status information of the target object from the business system based on the identity information of the target object; determines the access permission information of the target object for the target resource based on the historical resource access information and the historical security status information; and sends the access permission information to the business system, wherein the access permission information is used to enable the business system to determine the operation for the resource access request based on the access permission information.
- the electronic device in response to a resource access request sent by the target object, sends an authentication request to the network control device, wherein the authentication request includes the identity information of the target object and the target resource that the target object is to access, and the authentication request is used to enable the network control device to obtain the historical resource access information and historical security status information of the target object from the business system based on the identity information of the target object, and determine the access permission information of the target object for the target resource based on the historical resource access information and the historical security status information, and send the access permission information to the business system; when receiving the access permission information sent by the network security device, determine the operation for the resource access request based on the access permission information.
- Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or a combination thereof, including, but not limited to, object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages.
- the program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server.
- the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
- LAN local area network
- WAN wide area network
- Internet service provider e.g., via the Internet using an Internet service provider
- Each square frame in the block diagram can represent a module, a program segment, or a part of a code, and this module, a program segment, or a part of a code comprises one or more executable instructions for realizing the logical function of a regulation.
- the function marked in the square frame can also occur in a sequence different from that marked in the accompanying drawings. For example, two square frames represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the function involved.
- each square frame in the block diagram and/or the flow chart, and the combination of the square frames in the block diagram and/or the flow chart can be realized by a dedicated hardware-based system that performs the function or operation of a regulation, or can be realized by a combination of dedicated hardware and computer instructions.
- modules involved in the embodiments described in the present disclosure may be implemented by software or hardware, wherein the name of a module does not, in some cases, constitute a limitation on the module itself.
- exemplary types of hardware logic components include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.
- FPGAs field programmable gate arrays
- ASICs application specific integrated circuits
- ASSPs application specific standard products
- SOCs systems on chip
- CPLDs complex programmable logic devices
- a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment.
- a machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium.
- a machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing.
- a more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
- RAM random access memory
- ROM read-only memory
- EPROM or flash memory erasable programmable read-only memory
- CD-ROM portable compact disk read-only memory
- CD-ROM compact disk read-only memory
- magnetic storage device or any suitable combination of the foregoing.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (11)
- 一种资源访问控制方法,应用于网络控制设备,包括:接收业务系统发送的认证请求,其中,所述认证请求是所述业务系统在根据目标对象发送的资源访问请求,确定到所述目标对象将要访问的目标资源属于目标类型的资源的情况下发送的,所述认证请求包括所述目标对象的身份信息以及所述目标对象将要访问的所述目标资源;响应于所述认证请求,根据所述目标对象的身份信息,从所述业务系统中获取所述目标对象的历史资源访问信息以及历史安全状态信息;根据所述历史资源访问信息以及所述历史安全状态信息,确定所述目标对象针对所述目标资源的访问权限信息;向所述业务系统发送所述访问权限信息,其中,所述访问权限信息用于使得所述业务系统根据所述访问权限信息确定针对所述资源访问请求的操作。
- 根据权利要求1所述的方法,其中,所述根据所述历史资源访问信息以及所述历史安全状态信息,确定所述目标对象针对所述目标资源的访问权限信息,包括:根据所述历史资源访问信息以及所述历史安全状态信息,结合预设的映射关系,确定所述目标对象触发的目标风险项,其中,所述映射关系包括不同的所述历史资源访问信息和所述历史安全状态信息的组合与不同的风险项之间的对应关系;根据所述目标风险项,确定所述目标对象针对所述目标资源的访问权限信息。
- 根据权利要求1或2所述的方法,还包括:在访问所述业务系统的目标对象的安全状态信息发生变更的情况下,根据所述安全状态信息,确定所述目标对象的数据访问策略,其中,所述数据访问策略包括所述目标对象能够访问的资源以及不能访问的资源;向所述业务系统发送所述数据访问策略,其中,所述数据访问策略用于 使得所述业务系统根据所述数据访问策略,确定所述目标对象针对所述业务系统中除所述目标类型的资源外的其他资源的访问权限。
- 根据权利要求3所述的方法,还包括:根据所述数据访问策略,获得权限变更消息,其中,所述权限变更消息用于表征所述目标对象针对所述业务系统的资源访问权限已发生变更;向所述业务系统发送所述权限变更消息,其中,所述权限变更消息用于使得所述业务系统通过与所述目标对象的终端设备之间的长连接通道向所述终端设备发送所述权限变更消息,以在所述终端设备中展示所述权限变更消息。
- 一种资源访问控制方法,应用于业务系统,包括:接收目标对象发送的资源访问请求,其中,所述资源访问请求用于请求访问目标资源;在所述目标资源属于目标类型的资源的情况下,向网络控制设备发送认证请求,其中,所述认证请求包括所述目标对象的身份信息以及所述目标对象将要访问的所述目标资源,所述认证请求用于使得所述网络控制设备根据所述目标对象的身份信息,从所述业务系统中获取所述目标对象的历史资源访问信息以及历史安全状态信息,并根据所述历史资源访问信息以及所述历史安全状态信息,确定所述目标对象针对所述目标资源的访问权限信息,以及向所述业务系统发送所述访问权限信息;在接收到所述网络安全设备发送的所述访问权限信息的情况下,根据所述访问权限信息确定针对所述资源访问请求的操作。
- 根据权利要求5所述的方法,还包括:在接收到所述网络控制设备发送的所述目标对象的数据访问策略的情况下,根据所述数据访问策略,确定所述目标对象针对所述业务系统中除所述目标类型的资源外的其他资源的访问权限;其中,所述数据访问策略是所述网络控制设备在访问所述业务系统的目标对象的安全状态信息发生变更的情况下,根据所述安全状态信息确定到的, 所述数据访问策略包括所述目标对象能够访问的资源以及不能访问的资源。
- 根据权利要求6所述的方法,还包括:在接收到所述网络控制设备发送的权限变更消息的情况下,通过与所述目标对象的终端设备之间的长连接通道,向所述终端设备发送所述权限变更消息,以在所述终端设备中展示所述权限变更消息,其中,所述权限变更消息是所述网络控制设备根据所述数据访问策略生成的,所述权限变更消息用于表征所述目标对象针对所述业务系统的资源访问权限已发生变更。
- 一种资源访问控制装置,应用于网络控制设备,包括:第一接收模块,被配置为接收业务系统发送的认证请求,其中,所述认证请求是所述业务系统在根据目标对象发送的资源访问请求,确定到所述目标对象将要访问的目标资源属于目标类型的资源的情况下发送的,所述认证请求包括所述目标对象的身份信息以及所述目标对象将要访问的所述目标资源;获取模块,被配置为响应于所述认证请求,根据所述目标对象的身份信息,从所述业务系统中获取所述目标对象的历史资源访问信息以及历史安全状态信息;确定模块,被配置为根据所述历史资源访问信息以及所述历史安全状态信息,确定所述目标对象针对所述目标资源的访问权限信息;以及第一发送模块,被配置为向所述业务系统发送所述访问权限信息,其中,所述访问权限信息用于使得所述业务系统根据所述访问权限信息确定针对所述资源访问请求的操作。
- 一种资源访问控制装置,应用于业务系统,包括:第二接收模块,被配置为接收目标对象发送的资源访问请求,其中,所述资源访问请求用于请求访问目标资源;第二发送模块,被配置为在所述目标资源属于目标类型的资源的情况下,向网络控制设备发送认证请求,其中,所述认证请求包括所述目标对象的身份信息以及所述目标对象将要访问的所述目标资源,所述认证请求用于使得 所述网络控制设备根据所述目标对象的身份信息,从所述业务系统中获取所述目标对象的历史资源访问信息以及历史安全状态信息,并根据所述历史资源访问信息以及所述历史安全状态信息,确定所述目标对象针对所述目标资源的访问权限信息,以及向所述业务系统发送所述访问权限信息;以及第三接收模块,被配置为在接收到所述网络安全设备发送的所述访问权限信息的情况下,根据所述访问权限信息确定针对所述资源访问请求的操作。
- 一种计算机可读介质,其上存储有计算机程序,其中,所述计算机程序被处理装置执行时实现权利要求1-4中任一项所述的资源访问控制方法,或者实现权利要求5-7中任一项所述的资源访问控制方法。
- 一种电子设备,其特征在于,包括:存储装置,其上存储有计算机程序;以及处理装置,被配置为执行所述存储装置中的所述计算机程序,以实现权利要求1-4中任一项所述的资源访问控制方法,或者实现权利要求5-7中任一项所述的资源访问控制方法。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP24766493.1A EP4557132A4 (en) | 2023-03-07 | 2024-03-07 | METHOD AND APPARATUS FOR CONTROLLING ACCESS TO A RESOURCE, COMPUTER-READABLE MEDIA AND ELECTRONIC DEVICE |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202310238262.0A CN116821869B (zh) | 2023-03-07 | 2023-03-07 | 资源访问控制方法、装置、介质及电子设备 |
| CN202310238262.0 | 2023-03-07 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024183779A1 true WO2024183779A1 (zh) | 2024-09-12 |
Family
ID=88119139
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2024/080454 Ceased WO2024183779A1 (zh) | 2023-03-07 | 2024-03-07 | 资源访问控制方法及装置、计算机可读介质和电子设备 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20240305639A1 (zh) |
| EP (1) | EP4557132A4 (zh) |
| CN (1) | CN116821869B (zh) |
| WO (1) | WO2024183779A1 (zh) |
Families Citing this family (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116821869B (zh) * | 2023-03-07 | 2024-10-11 | 北京火山引擎科技有限公司 | 资源访问控制方法、装置、介质及电子设备 |
| CN118200923B (zh) * | 2024-02-08 | 2024-10-01 | 中国联合网络通信有限公司广东省分公司 | 访问控制方法、装置及存储介质 |
| CN119051927A (zh) * | 2024-08-12 | 2024-11-29 | 中国建设银行股份有限公司 | 权限的配置方法、装置、设备及存储介质 |
| CN119210838A (zh) * | 2024-09-23 | 2024-12-27 | 南方电网科学研究院有限责任公司 | 基于零信任的业务系统访问方法、装置、计算机设备、可读存储介质和程序产品 |
| CN119363492A (zh) * | 2024-12-30 | 2025-01-24 | 北京中诺链捷数字科技有限公司 | 一种基于物联网的金融安全控制方法和装置 |
| CN120455156B (zh) * | 2025-06-20 | 2026-03-06 | 国富瑞数据系统有限公司 | 一种业务系统的访问权限管理方法、装置、电子设备及存储介质 |
| CN120603062B (zh) * | 2025-07-24 | 2025-11-14 | 广脉科技股份有限公司 | 一种高铁沿线通信业务调度方法及系统 |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20160212113A1 (en) * | 2015-01-21 | 2016-07-21 | Onion ID Inc. | Techniques for facilitating secure, credential-free user access to resources |
| CN111274595A (zh) * | 2020-01-20 | 2020-06-12 | 北京合信力科技有限公司 | 一种资源访问的控制方法及装置 |
| CN111382421A (zh) * | 2020-03-19 | 2020-07-07 | 深信服科技股份有限公司 | 一种业务访问控制方法、系统及电子设备和存储介质 |
| CN115333840A (zh) * | 2022-08-15 | 2022-11-11 | 中国电信股份有限公司 | 资源访问方法、系统、设备及存储介质 |
| CN115730324A (zh) * | 2021-08-30 | 2023-03-03 | 北京字节跳动网络技术有限公司 | 业务系统的访问方法、装置、存储介质及电子设备 |
| CN116821869A (zh) * | 2023-03-07 | 2023-09-29 | 北京火山引擎科技有限公司 | 资源访问控制方法、装置、介质及电子设备 |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11985132B2 (en) * | 2018-05-02 | 2024-05-14 | Samsung Electronics Co., Ltd. | System and method for resource access authentication |
| CN112055029B (zh) * | 2020-09-16 | 2023-04-07 | 全球能源互联网研究院有限公司 | 用于零信任电力物联网设备的用户实时信任度评估方法 |
-
2023
- 2023-03-07 CN CN202310238262.0A patent/CN116821869B/zh active Active
-
2024
- 2024-03-07 EP EP24766493.1A patent/EP4557132A4/en active Pending
- 2024-03-07 WO PCT/CN2024/080454 patent/WO2024183779A1/zh not_active Ceased
- 2024-03-07 US US18/598,891 patent/US20240305639A1/en active Pending
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20160212113A1 (en) * | 2015-01-21 | 2016-07-21 | Onion ID Inc. | Techniques for facilitating secure, credential-free user access to resources |
| CN111274595A (zh) * | 2020-01-20 | 2020-06-12 | 北京合信力科技有限公司 | 一种资源访问的控制方法及装置 |
| CN111382421A (zh) * | 2020-03-19 | 2020-07-07 | 深信服科技股份有限公司 | 一种业务访问控制方法、系统及电子设备和存储介质 |
| CN115730324A (zh) * | 2021-08-30 | 2023-03-03 | 北京字节跳动网络技术有限公司 | 业务系统的访问方法、装置、存储介质及电子设备 |
| CN115333840A (zh) * | 2022-08-15 | 2022-11-11 | 中国电信股份有限公司 | 资源访问方法、系统、设备及存储介质 |
| CN116821869A (zh) * | 2023-03-07 | 2023-09-29 | 北京火山引擎科技有限公司 | 资源访问控制方法、装置、介质及电子设备 |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP4557132A4 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN116821869A (zh) | 2023-09-29 |
| US20240305639A1 (en) | 2024-09-12 |
| EP4557132A4 (en) | 2026-04-15 |
| EP4557132A1 (en) | 2025-05-21 |
| CN116821869B (zh) | 2024-10-11 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12137091B2 (en) | Single sign-on enabled with OAuth token | |
| WO2024183779A1 (zh) | 资源访问控制方法及装置、计算机可读介质和电子设备 | |
| US11329989B2 (en) | Token-based access control and grouping | |
| US11075903B2 (en) | Facilitation of service login | |
| US11316689B2 (en) | Trusted token relay infrastructure | |
| US11245682B2 (en) | Adaptive authorization using access token | |
| US10880292B2 (en) | Seamless transition between WEB and API resource access | |
| JP6563134B2 (ja) | 証明書更新及び展開 | |
| US11750590B2 (en) | Single sign-on (SSO) user techniques using client side encryption and decryption | |
| US10715514B1 (en) | Token-based credential renewal service | |
| US10673862B1 (en) | Token-based access tracking and revocation | |
| US10587591B2 (en) | Generating a password | |
| JP6707127B2 (ja) | エンドユーザによって起動されるアクセスサーバ真正性チェック | |
| US9819668B2 (en) | Single sign on for native and wrapped web resources on mobile devices | |
| US11283793B2 (en) | Securing user sessions | |
| US11233776B1 (en) | Providing content including sensitive data | |
| US20200110859A1 (en) | Controlling access to computer resources by user authentication based on unique authentication patterns | |
| US20260032153A1 (en) | Separate access control for managing bastions and bastion sessions | |
| CN120602156B (zh) | 保护智能体数据安全的方法、装置、系统、介质、电子设备及程序产品 | |
| CN116702205A (zh) | 鉴权方法、装置和电子设备 | |
| CN118842605A (zh) | 数据资源访问方法、装置、电子设备及可读存储介质 | |
| JP2022165032A (ja) | 中継サーバ及びアクセス制御システム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24766493 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024766493 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 2024766493 Country of ref document: EP Effective date: 20250213 |
|
| WWP | Wipo information: published in national office |
Ref document number: 2024766493 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |