[go: up one dir, main page]

CN118678352B - 5G user identity authentication method, device, equipment and medium based on head enhancement - Google Patents

5G user identity authentication method, device, equipment and medium based on head enhancement Download PDF

Info

Publication number
CN118678352B
CN118678352B CN202411166447.6A CN202411166447A CN118678352B CN 118678352 B CN118678352 B CN 118678352B CN 202411166447 A CN202411166447 A CN 202411166447A CN 118678352 B CN118678352 B CN 118678352B
Authority
CN
China
Prior art keywords
internet
things terminal
access
address
intranet
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN202411166447.6A
Other languages
Chinese (zh)
Other versions
CN118678352A (en
Inventor
王蕾
王德石
薛白
张潮
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Tianyi IoT Technology Co Ltd
Original Assignee
Tianyi IoT Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Tianyi IoT Technology Co Ltd filed Critical Tianyi IoT Technology Co Ltd
Priority to CN202411166447.6A priority Critical patent/CN118678352B/en
Publication of CN118678352A publication Critical patent/CN118678352A/en
Application granted granted Critical
Publication of CN118678352B publication Critical patent/CN118678352B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明实施例公开了一种基于头增强的5G用户身份认证方法、装置、设备及介质,所述方法包括:若接收到物联网终端发送的访问内网业务的内网访问请求,解析所述内网访问请求以获得所述物联网终端的标识信息;确认是否记录有与所述标识信息相匹配的头增强信息;若记录有与所述标识信息相匹配的头增强信息,则允许所述物联网终端对所述内网业务进行访问。本发明可以防止非法用户对内网业务进行访问,消除了安全隐患。

The embodiment of the present invention discloses a 5G user identity authentication method, device, equipment and medium based on header enhancement, the method comprising: if an intranet access request for accessing an intranet service sent by an IoT terminal is received, parsing the intranet access request to obtain identification information of the IoT terminal; confirming whether header enhancement information matching the identification information is recorded; if header enhancement information matching the identification information is recorded, allowing the IoT terminal to access the intranet service. The present invention can prevent illegal users from accessing intranet services and eliminate security risks.

Description

5G user identity authentication method, device, equipment and medium based on head enhancement
Technical Field
The invention relates to the technical field of the internet of things, in particular to a 5G user identity authentication method, device, equipment and medium based on head enhancement.
Background
With the popularization of remote office and the requirement on office efficiency, more and more enterprises allow the mobile terminals of staff to access the enterprise intranet to access and operate the intranet business. However, security threat exists in the case of the mobile terminal directly accessing the intranet service due to the privacy of the mobile terminal and the openness of the remote access. For example, the mobile terminal accesses the intranet service in an abnormal physical area, such as outside the campus of the enterprise, or the unauthorized terminal accesses the intranet service by misusing a legal SIM card. That is, there is currently no effective authentication method for the mobile terminal to access intranet services.
Disclosure of Invention
The embodiment of the invention provides a 5G user identity authentication method, device, equipment and medium based on head enhancement, which aim to solve the problem that the existing mobile terminal has potential safety hazard in accessing intranet service.
In a first aspect, an embodiment of the present invention provides a method for authenticating a 5G user identity based on header enhancement, where the method includes:
If an intranet access request for accessing intranet service sent by an Internet of things terminal is received, analyzing the intranet access request to obtain identification information of the Internet of things terminal;
confirming whether header enhancement information matched with the identification information is recorded or not;
and if the head enhancement information matched with the identification information is recorded, allowing the Internet of things terminal to access the intranet service.
In a second aspect, an embodiment of the present invention further provides a 5G user identity authentication device based on header enhancement, where the device includes:
The first analysis unit is used for analyzing the intranet access request to obtain the identification information of the Internet of things terminal if the intranet access request for accessing the intranet service sent by the Internet of things terminal is received;
A first confirming unit for confirming whether header enhancement information matched with the identification information is recorded;
and the first passing unit is used for allowing the internet of things terminal to access the intranet service if the head enhancement information matched with the identification information is recorded.
In a third aspect, an embodiment of the present invention further provides a computer device, which includes a memory and a processor, where the memory stores a computer program, and the processor implements the method when executing the computer program.
In a fourth aspect, embodiments of the present invention also provide a computer readable storage medium storing a computer program which, when executed by a processor, implements the above method.
The embodiment of the invention provides a 5G user identity authentication method, device, equipment and medium based on head enhancement. The method comprises the steps of analyzing an intranet access request to obtain identification information of an Internet of things terminal if the intranet access request for accessing intranet service sent by the Internet of things terminal is received, confirming whether head enhancement information matched with the identification information is recorded or not, and allowing the Internet of things terminal to access the intranet service if the head enhancement information matched with the identification information is recorded. According to the method and the device for the intranet business access, when the intranet access request sent by the user through the 5G internet of things terminal is received, the intranet access request is analyzed to obtain the identification information of the internet of things terminal, whether the head enhancement information matched with the identification information is recorded or not is confirmed, if the head enhancement information matched with the identification information is recorded, the internet of things terminal is allowed to access the intranet business, the internet of things terminal is authenticated through the head enhancement information, potential safety hazards can be eliminated, and illegal users are prevented from accessing the intranet business.
Drawings
In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly described below, and it is obvious that the drawings in the following description are some embodiments of the present invention, and other drawings may be obtained according to these drawings without inventive effort for a person skilled in the art.
Fig. 1 is a flow chart of a method for authenticating a 5G user identity based on header enhancement according to an embodiment of the present invention;
Fig. 2 is a block diagram of a method for authenticating a 5G user identity based on header enhancement according to an embodiment of the present invention;
FIG. 3 is an authentication flow chart of a 5G user identity authentication method based on header enhancement provided by an embodiment of the invention;
FIG. 4 is a schematic block diagram of a head-based enhanced 5G user identity authentication device provided by an embodiment of the present invention;
fig. 5 is a schematic block diagram of a computer device provided by an embodiment of the present invention.
Detailed Description
The following description of the embodiments of the present invention will be made clearly and fully with reference to the accompanying drawings, in which it is evident that the embodiments described are some, but not all embodiments of the invention. All other embodiments, which can be made by those skilled in the art based on the embodiments of the invention without making any inventive effort, are intended to be within the scope of the invention.
It should be understood that the terms "comprises" and "comprising," when used in this specification and the appended claims, specify the presence of stated features, integers, operations, elements, and/or components, but do not preclude the presence or addition of one or more other features, integers, operations, elements, components, and/or groups thereof.
It is also to be understood that the terminology used in the description of the invention herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. As used in this specification and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It should be further understood that the term "and/or" as used in the present specification and the appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes such combinations.
Referring to fig. 1, fig. 1 is a flow chart of a method for authenticating a 5G user identity based on header enhancement according to an embodiment of the present invention. The 5G user identity authentication method based on the head enhancement is applied to computer equipment and used for authenticating the access of the 5G user to the intranet service through the Internet of things terminal, and the security of the Internet of things terminal when accessing to the intranet service is improved. As shown in FIG. 1, the method includes steps S110 to S130.
S110, if an intranet access request for accessing intranet service sent by an Internet of things terminal is received, analyzing the intranet access request to obtain identification information of the Internet of things terminal.
In the embodiment of the present invention, the internet of things terminal is generally referred to as a 5G terminal, for example, a mobile phone, and a user may send an intranet access request through the internet of things terminal to access an intranet service. When an intranet access request of the terminal of the Internet of things is received, the intranet access request is analyzed, so that identification information of the terminal of the Internet of things is obtained.
The identification information is used for identifying different terminals of the internet of things, and can include information such as an identification number, an IP address, a device code and the like, for example, if a user sends an intranet access request through a mobile phone, the identification information can include the mobile phone number of the mobile phone, the IP address when the intranet access request is sent, and the device code of the mobile phone.
S120, confirming whether the header enhancement information matched with the identification information is recorded.
In the embodiment of the invention, for the non-primary access internet of things terminal, if the non-primary access internet of things terminal successfully accesses the intranet service before, corresponding header enhancement information is recorded, the header enhancement information is matched with the identification information of the internet of things terminal, whether authentication is successful or not can be judged by confirming whether the header enhancement information is matched with the identification information of the internet of things terminal, namely whether the internet of things terminal is allowed to access the intranet service or not.
For the first accessed internet of things terminal or the internet service is accessed before, but the rejected internet of things terminal can enter a verification process to confirm whether the internet of things terminal is authorized.
For example, if the user accesses the intranet service through the mobile phone, and the obtained identification information may include a mobile phone number, an IP address, and a device code, if header enhancement information matched with the identification information is recorded, the header enhancement information is obtained, and whether the information included in the header enhancement information is consistent with the mobile phone number, the IP address, and the device code is confirmed. That is, the header enhancement information may also include a mobile phone number, an IP address, and a device code. When the mobile phone number is recorded, the head enhancement information of the internet of things terminal is indicated to be recorded, and whether the internet of things terminal is allowed to access the intranet service can be further judged.
And S130, if the head enhancement information matched with the identification information is recorded, allowing the Internet of things terminal to access the intranet service.
In the embodiment of the invention, when the head enhancement information matched with the identification information is recorded, the terminal of the Internet of things is allowed to access the intranet service. That is, in the foregoing embodiment, when the same mobile phone number as that included in the identification information is recorded in the header enhancement information, it is indicated that the header enhancement information of the internet of things terminal is recorded, it can be further confirmed whether it is allowed to access the intranet service.
The identification information is also provided with an IP address, the IP address is recorded in the head enhancement information, the IP address recorded in the head enhancement information is an IP address allowing the Internet of things terminal to access the intranet, when the IP address in the identification information is inconsistent with the IP address in the head enhancement information, the access is refused or a re-authorization step is carried out, and when the IP address in the identification information is consistent with the IP address in the head enhancement information, the Internet of things terminal is allowed to access the intranet service.
In some embodiments, for example, the method for authenticating a 5G user identity based on header enhancement may include the following steps:
If the header enhancement information matched with the identification information is not recorded, a first redirection instruction is sent to the Internet of things terminal so that the Internet of things terminal accesses a first preset address and configures the header enhancement information for the Internet of things terminal;
if the fact that the internet of things terminal accesses the first preset address is detected, acquiring head enhancement information of the internet of things terminal, and verifying the internet of things terminal according to the head enhancement information of the internet of things terminal;
If the authentication of the internet of things terminal is passed, the head enhancement information of the internet of things terminal is recorded, and a second redirection instruction is sent to the internet of things terminal so that the internet of things terminal accesses an initial access address;
and if the authentication of the internet of things terminal is not passed, rejecting the internet of things terminal to access the intranet service.
In the embodiment of the invention, when the header enhancement information matched with the identification information is not recorded, the verification process can be entered. The method comprises the steps that firstly, a simulation server sends a first redirection instruction to an Internet of things terminal, an access target of the Internet of things terminal is changed from an access intranet service to an access first preset address, head enhancement information is configured for the Internet of things terminal, then when the first preset address is detected to be accessed by the Internet of things terminal, the Internet of things terminal is verified according to the head enhancement information of the Internet of things terminal, for example, whether the Internet of things terminal is legal in a system is verified, if the Internet of things terminal is legal in the system, the verification is passed, and if the Internet of things terminal is an illegal user in the system, the Internet of things terminal is refused to access the intranet service.
And after the verification is passed, recording the head enhancement information of the terminal of the Internet of things, sending a second redirection instruction to the terminal of the Internet of things, modifying the access address of the terminal of the Internet of things into the initial access address of the terminal of the Internet of things, and then entering step S110 to authenticate the terminal of the Internet of things again.
As shown in fig. 2, the authentication method may be configured in a 5G security management platform, and SMF (Session Management Function) G session management function in fig. 2 is used for managing sessions of the internet of things terminal, UPF (User Plane Function) is used for processing data of the internet of things terminal, and AMF (ACCESS AND Mobility Management Function) is used for completing access and mobility management of the internet of things terminal. And the internet of things terminal sends an intranet access request to the UPF through the base station, and the UPF forwards the intranet access request to the 5G security management platform.
As shown in fig. 3, the 5G security management platform analyzes the intranet access request to obtain the identification information of the internet of things terminal, when the 5G security management platform does not record the header enhancement information matched with the identification information, a first redirection instruction is sent to the internet of things terminal, that is, the access address of the internet of things terminal is modified from the intranet to a first preset address, the first preset address can be the 5G security management platform, the internet of things terminal revisits the 5G security management platform, at this time, the UPF detects that the access address of the internet of things terminal is the 5G security management platform, and then the header enhancement information is configured for the access request of the internet of things terminal before forwarding the access request to the 5G security management platform. For example, the access address may be generally represented as URL (Uniform Resource Locator) uniform resource locator, and when the UPF detects that the URL has the first preset address, header enhancement information is added to the header of the URL, where the header enhancement information may be information such as a mobile phone number, a device code, and the related information is encrypted.
After the UPF finishes adding the head enhancement information, sending an access request of the Internet of things terminal to a 5G security management platform, wherein the address received by the 5G security management platform is an enhanced first preset address, identifying the enhanced first preset address, analyzing the head enhancement information added by the UPF to obtain information such as a mobile phone number, a device code, an IP address and the like of the Internet of things terminal, and then verifying whether the Internet of things terminal is legal in a system, for example, whether the mobile phone number is legal in the system or not can be verified, if the Internet of things terminal is legal in the system, recording the head enhancement information of the Internet of things terminal, and sending a second redirection instruction to the Internet of things terminal, wherein the second redirection instruction is also used for modifying the access address of the Internet of things terminal, and modifying the access address of the Internet of things terminal from the first preset address to an initial address which the Internet of things terminal originally accesses, namely, the address of an intranet service which the Internet of things terminal needs to access.
And the internet of things terminal resends the intranet access request according to the second redirection instruction, after receiving the intranet access request, the 5G security management platform analyzes the intranet access request and acquires the identification information of the internet of things terminal, and at the moment, the 5G security management platform generally records the head enhancement information matched with the identification information, so that the internet of things terminal is allowed to access intranet services. By verifying and adding the header enhancement information, the safety of the intranet service can be ensured, and illegal users can be prevented from accessing the intranet service.
In addition, the 5G security management platform can autonomously manage user access rules or butt-joint identity authentication systems, the systems can acquire user identity information and access rights periodically or when terminal information changes, and when the access rights change, corresponding rules are updated in time. A user can associate a plurality of rules, wherein the plurality of rules are in an OR relationship, namely, hit one rule which is not to be searched for next rule continuously, a plurality of attributes can be arranged in one rule, and the plurality of attributes are in an AND relationship, namely, the plurality of attributes are met at the same time, namely, hit the rule. After the 5G security management platform identifies the user identity information, the corresponding rule is acquired, the rule is matched with the rule according to the information such as user access service, access time and the like, if the rule is hit, forwarding or discarding is carried out according to the rule requirement, and if the rule is not hit, the data is directly discarded.
In some embodiments, for example, the method for authenticating a 5G user identity based on header enhancement may include the following steps:
And confirming the access authority of the terminal of the Internet of things, and limiting the access of the terminal of the Internet of things to the intranet service according to the access authority.
In the embodiment of the invention, different internet of things terminals have different access rights, for example, different IP addresses correspond to different access rights, if a user accesses an intranet service through the internet of things terminal within a specified range, normal access rights can be granted, and if the user accesses the intranet service outside the specified range, limited access rights can be granted, for example, only partial functions are opened. Besides adjusting the access right according to the IP address, the access right of the terminal of the Internet of things can be actively adjusted, and the access right can be specifically set by an administrator.
In some embodiments, for example, the method for authenticating a 5G user identity based on header enhancement may include the following steps:
acquiring a first identification number and a first IP address of the terminal of the Internet of things according to the identification information, and confirming whether a second identification number matched with the first identification number exists in the header enhancement information;
if the second identification number matched with the first identification number exists in the header enhancement information, whether a second IP address corresponding to the second identification number is consistent with the first IP address or not is confirmed;
And if the second IP address corresponding to the second identification number is inconsistent with the first IP address, sending a first redirection instruction to the Internet of things terminal so that the Internet of things terminal accesses a first preset address and reconfigures head enhancement information for the Internet of things terminal.
In the embodiment of the invention, the first identification number can be a mobile phone number of the internet of things terminal, the first IP address is an address when the internet of things terminal accesses the intranet, the second identification number is the same as the first identification number, and if the first identification number is a mobile phone number, the second identification number is the same as the mobile phone number. When the second identification number matched with the first identification number exists in the system, whether the first IP address is consistent with the second IP address is further verified, when the first IP address is consistent with the second IP address, the Internet of things terminal is allowed to access the intranet service, if the first IP address is inconsistent with the second IP address, the head enhancement information can be reconfigured, and when the head enhancement information is reconfigured, the corresponding access authority is adjusted according to the specific IP address.
Fig. 4 is a schematic block diagram of a 5G user identity authentication device 100 based on header enhancement according to an embodiment of the present invention. As shown in fig. 4, the present invention further provides a 5G user identity authentication device 100 based on header enhancement, corresponding to the above 5G user identity authentication method based on header enhancement. The head-enhancement based 5G user identity authentication apparatus 100 includes means for performing the head-enhancement based 5G user identity authentication method described above. Specifically, referring to fig. 4, the header enhancement-based 5G user identity authentication apparatus 100 includes a first parsing unit 110, a first confirmation unit 120, and a first passing unit 130.
The first analyzing unit 110 is configured to analyze an intranet access request for accessing an intranet service if the intranet access request sent by an internet of things terminal is received, so as to obtain identification information of the internet of things terminal;
the first confirming unit 120 is configured to confirm whether header enhancement information matched with the identification information is recorded;
The first pass unit 130 is configured to allow the internet of things terminal to access the intranet service if header enhancement information matched with the identification information is recorded.
In some embodiments, for example, in this embodiment, the 5G user identity authentication device based on header enhancement further includes a first sending unit, a first detecting unit, a first verifying unit, and a second verifying unit.
The first sending unit is configured to send a first redirection instruction to the internet of things terminal if the header enhancement information matched with the identification information is not recorded, so that the internet of things terminal accesses a first preset address and configures header enhancement information for the internet of things terminal;
the first detection unit is configured to obtain header enhancement information of the internet of things terminal if the first detection unit detects that the internet of things terminal accesses the first preset address, and verify the internet of things terminal according to the header enhancement information of the internet of things terminal;
The first verification unit is used for recording the head enhancement information of the internet of things terminal and sending a second redirection instruction to the internet of things terminal if the first verification unit passes the verification of the internet of things terminal so that the internet of things terminal accesses an initial access address;
and the second verification unit is used for rejecting the internet of things terminal to access the intranet service if the second verification unit fails to verify the internet of things terminal.
In some embodiments, for example the present embodiment, the head-based enhanced 5G user identity authentication device further comprises a second validation unit.
The second confirmation unit is used for confirming the access authority of the internet of things terminal and limiting the access of the internet of things terminal to the intranet service according to the access authority.
In some embodiments, for example, in this embodiment, the apparatus for authenticating a 5G user identity based on header enhancement further includes a first obtaining unit, a third confirming unit, and a second sending unit.
The first obtaining unit is used for obtaining a first identification number and a first IP address of the terminal of the Internet of things according to the identification information, and confirming whether a second identification number matched with the first identification number exists in the header enhancement information;
The third confirming unit is used for confirming whether a second IP address corresponding to the second identification number is consistent with the first IP address or not if the second identification number matched with the first identification number exists in the head enhancement information;
and the second sending unit is used for sending a first redirection instruction to the internet of things terminal if the second IP address corresponding to the second identification number is inconsistent with the first IP address, so that the internet of things terminal accesses a first preset address and reconfigures the head enhancement information for the internet of things terminal.
It should be noted that, as those skilled in the art can clearly understand, the specific implementation process of the head-based enhanced 5G user identity authentication device and each unit may refer to the corresponding description in the foregoing method embodiment, and for convenience and brevity of description, the description is omitted here.
The head-based enhanced 5G user identity authentication apparatus described above may be implemented in the form of a computer program which may be run on a computer device as shown in fig. 5.
Referring to fig. 5, fig. 5 is a schematic block diagram of a computer device according to an embodiment of the present application. With reference to FIG. 5, the computer device 500 includes a processor 502, memory, and a network interface 505 connected by a system bus 501, where the memory may include a non-volatile storage medium 503 and an internal memory 504.
The non-volatile storage medium 503 may store an operating system 5031 and a computer program 5032. The computer program 5032, when executed, may cause the processor 502 to perform a head-enhanced 5G user identity authentication method.
The processor 502 is used to provide computing and control capabilities to support the operation of the overall computer device 500.
The internal memory 504 provides an environment for the execution of a computer program 5032 in the non-volatile storage medium 503, which computer program 5032, when executed by the processor 502, causes the processor 502 to perform a head-enhanced 5G user identity authentication method.
The network interface 505 is used to communicate with other devices. It will be appreciated by those skilled in the art that the architecture shown in fig. 5 is merely a block diagram of some of the architecture relevant to the present inventive arrangements and is not limiting of the computer device 500 to which the present inventive arrangements may be implemented, as a particular computer device 500 may include more or fewer components than shown, or may combine some of the components, or have a different arrangement of components.
It should be appreciated that in embodiments of the present application, the Processor 502 may be a central processing unit (Central Processing Unit, CPU), the Processor 502 may also be other general purpose processors, digital signal processors (FIGITAL SIGNAL processors, FSP), application SPECIFIC INTEGRATEF Circuits (ASIC), off-the-shelf Programmable gate arrays (FielF-Programmable GATE ARRAY, FPGA) or other Programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or the like. Wherein the general purpose processor may be a microprocessor or the processor may be any conventional processor or the like.
Those skilled in the art will appreciate that all or part of the flow in a method embodying the above described embodiments may be accomplished by computer programs instructing the relevant hardware. The computer program may be stored in a storage medium that is a computer readable storage medium. The computer program is executed by at least one processor in the computer system to implement the flow steps of the embodiments of the method described above.
Accordingly, the present invention also provides a storage medium. The storage medium may be a computer readable storage medium. The storage medium stores a computer program. The computer program, when executed by a processor, implements any of the embodiments of the head-based enhanced 5G user identity authentication method described above.
The storage medium may be a U-disk, a removable hard disk, a Read Only Memory (ROM), a magnetic disk, or an optical disk, or other various computer readable storage media capable of storing program codes.
Those of ordinary skill in the art will appreciate that the elements and algorithm steps described in connection with the embodiments disclosed herein may be embodied in electronic hardware, in computer software, or in a combination of the two, and that the elements and steps of the examples have been generally described in terms of function in the foregoing description to clearly illustrate the interchangeability of hardware and software. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the solution. Skilled artisans may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present invention.
In the several embodiments provided by the present invention, it should be understood that the disclosed apparatus and method may be implemented in other manners. For example, the device embodiments described above are merely illustrative. For example, the division of each unit is only one logic function division, and there may be another division manner in actual implementation. For example, multiple units or components may be combined or may be integrated into another system, or some features may be omitted, or not performed.
The steps in the method of the embodiment of the invention can be sequentially adjusted, combined and deleted according to actual needs. The units in the device of the embodiment of the invention can be combined, divided and deleted according to actual needs. In addition, each functional unit in the embodiments of the present invention may be integrated in one processing unit, or each unit may exist alone physically, or two or more units may be integrated in one unit.
The integrated unit may be stored in a storage medium if implemented in the form of a software functional unit and sold or used as a stand-alone product. Based on such understanding, the technical solution of the present invention is essentially or partly contributing to the prior art, or all or part of the technical solution may be embodied in the form of a software product stored in a storage medium, comprising several instructions for causing a computer device to perform all or part of the steps of the method according to the embodiments of the present invention.
In the foregoing embodiments, the descriptions of the embodiments are focused on, and for those portions of one embodiment that are not described in detail, reference may be made to the related descriptions of other embodiments.
It will be apparent to those skilled in the art that various modifications and variations can be made to the present invention without departing from the spirit or scope of the invention. Thus, it is intended that the present invention also include such modifications and alterations insofar as they come within the scope of the appended claims or the equivalents thereof.
While the invention has been described with reference to certain preferred embodiments, it will be understood by those skilled in the art that various changes and substitutions of equivalents may be made and equivalents will be apparent to those skilled in the art without departing from the scope of the invention. Therefore, the protection scope of the invention is subject to the protection scope of the claims.

Claims (6)

1.一种基于头增强的5G用户身份认证方法,其特征在于,所述方法包括:1. A 5G user identity authentication method based on header enhancement, characterized in that the method comprises: 若接收到物联网终端发送的访问内网业务的内网访问请求,解析所述内网访问请求以If an intranet access request for accessing an intranet service is received from an IoT terminal, the intranet access request is parsed to obtain 获得所述物联网终端的标识信息;Obtaining identification information of the Internet of Things terminal; 确认是否记录有与所述标识信息相匹配的头增强信息;confirming whether header enhancement information matching the identification information is recorded; 若记录有与所述标识信息相匹配的头增强信息,则允许所述物联网终端对所述内网业务进行访问;If header enhancement information matching the identification information is recorded, the IoT terminal is allowed to access the intranet service; 若未记录有与所述标识信息相匹配的头增强信息,则向所述物联网终端发送第一重定向指令以使所述物联网终端访问第一预设地址并为所述物联网终端配置头增强信息;If the header enhancement information matching the identification information is not recorded, sending a first redirection instruction to the Internet of Things terminal to enable the Internet of Things terminal to access a first preset address and configuring the header enhancement information for the Internet of Things terminal; 若检测到所述物联网终端访问所述第一预设地址,则获取所述物联网终端的头增强信息,并根据所述物联网终端的头增强信息对所述物联网终端进行验证;If it is detected that the Internet of Things terminal accesses the first preset address, the header enhancement information of the Internet of Things terminal is obtained, and the Internet of Things terminal is verified according to the header enhancement information of the Internet of Things terminal; 若通过对所述物联网终端的验证,则记录所述物联网终端的头增强信息,并向所述物联网终端发送第二重定向指令以使所述物联网终端访问初始访问地址;If the verification of the Internet of Things terminal is passed, the header enhancement information of the Internet of Things terminal is recorded, and a second redirection instruction is sent to the Internet of Things terminal to enable the Internet of Things terminal to access the initial access address; 若未通过对所述物联网终端的验证,则拒绝所述物联网终端对所述内网业务进行访问。If the Internet of Things terminal fails to be authenticated, the Internet of Things terminal is denied access to the intranet service. 2.如权利要求1所述的方法,其特征在于,所述若记录有与所述标识信息相匹配的头增强信息,则允许所述物联网终端对所述内网业务进行访问的步骤之后,还包括:2. The method according to claim 1, characterized in that after the step of allowing the IoT terminal to access the intranet service if header enhancement information matching the identification information is recorded, the method further comprises: 确认所述物联网终端的访问权限,并根据所述访问权限限制所述物联网终端对所述内网业务的访问。Confirm the access rights of the IoT terminal, and restrict the access of the IoT terminal to the intranet service according to the access rights. 3.如权利要求1所述的方法,其特征在于,所述方法还包括:3. The method according to claim 1, characterized in that the method further comprises: 根据所述标识信息获取所述物联网终端的第一识别号以及第一IP地址,并在所述头增According to the identification information, the first identification number and the first IP address of the Internet of Things terminal are obtained, and the first identification number and the first IP address of the Internet of Things terminal are added to the header. 强信息中确认是否存在与所述第一识别号相匹配的第二识别号;confirming in the strong information whether there is a second identification number matching the first identification number; 若在所述头增强信息中存在与所述第一识别号相匹配的第二识别号,则确认所述第二识别号所对应的第二IP地址与所述第一IP地址是否一致;If there is a second identification number matching the first identification number in the header enhancement information, confirming whether a second IP address corresponding to the second identification number is consistent with the first IP address; 若所述第二识别号所对应的第二IP地址与所述第一IP地址不一致,则向所述物联网终端发送第一重定向指令以使所述物联网终端访问第一预设地址并为所述物联网终端重新配置头增强信息。If the second IP address corresponding to the second identification number is inconsistent with the first IP address, a first redirection instruction is sent to the Internet of Things terminal to enable the Internet of Things terminal to access the first preset address and reconfigure header enhancement information for the Internet of Things terminal. 4.一种基于头增强的5G用户身份认证装置,其特征在于,所述装置包括:4. A 5G user identity authentication device based on header enhancement, characterized in that the device comprises: 第一解析单元,用于若接收到物联网终端发送的访问内网业务的内网访问请求,解析所述内网访问请求以获得所述物联网终端的标识信息;A first parsing unit is configured to, upon receiving an intranet access request for accessing an intranet service sent by an Internet of Things terminal, parse the intranet access request to obtain identification information of the Internet of Things terminal; 第一确认单元,用于确认是否记录有与所述标识信息相匹配的头增强信息;A first confirmation unit, used to confirm whether header enhancement information matching the identification information is recorded; 第一通过单元,用于若记录有与所述标识信息相匹配的头增强信息,则允许所述物联网终端对所述内网业务进行访问;A first passing unit, configured to allow the Internet of Things terminal to access the intranet service if header enhancement information matching the identification information is recorded; 第一发送单元,用于若未记录有与所述标识信息相匹配的头增强信息,则向所述物联网终端发送第一重定向指令以使所述物联网终端访问第一预设地址并为所述物联网终端配置头增强信息;A first sending unit is configured to send a first redirection instruction to the Internet of Things terminal to enable the Internet of Things terminal to access a first preset address and configure the header enhancement information for the Internet of Things terminal if the header enhancement information matching the identification information is not recorded; 第一检测单元,用于若检测到所述物联网终端访问所述第一预设地址,则获取所述物联网终端的头增强信息,并根据所述物联网终端的头增强信息对所述物联网终端进行验证;A first detection unit, configured to obtain header enhancement information of the Internet of Things terminal if it is detected that the Internet of Things terminal accesses the first preset address, and verify the Internet of Things terminal according to the header enhancement information of the Internet of Things terminal; 第一验证单元,用于若通过对所述物联网终端的验证,则记录所述物联网终端的头增强信息,并向所述物联网终端发送第二重定向指令以使所述物联网终端访问初始访问地址;A first verification unit, configured to record the header enhancement information of the Internet of Things terminal if the verification of the Internet of Things terminal is passed, and send a second redirection instruction to the Internet of Things terminal to enable the Internet of Things terminal to access an initial access address; 第二验证单元,用于若未通过对所述物联网终端的验证,则拒绝所述物联网终端对所述内网业务进行访问。The second verification unit is used to deny the Internet of Things terminal from accessing the intranet service if the Internet of Things terminal fails to be verified. 5.一种计算机设备,其特征在于,所述计算机设备包括存储器以及与所述存储器相连的处理器;所述存储器用于存储计算机程序;所述处理器用于运行所述存储器中存储的计算机程序,以执行如权利要求1-3任一项所述方法的步骤。5. A computer device, characterized in that the computer device comprises a memory and a processor connected to the memory; the memory is used to store a computer program; the processor is used to run the computer program stored in the memory to execute the steps of the method as described in any one of claims 1 to 3. 6.一种计算机可读存储介质,其特征在于,所述存储介质存储有计算机程序,所述计算机程序被处理器执行时可于计算机设备上实现如权利要求1-3中任一项所述方法的步骤。6. A computer-readable storage medium, characterized in that the storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 3 can be implemented on a computer device.
CN202411166447.6A 2024-08-23 2024-08-23 5G user identity authentication method, device, equipment and medium based on head enhancement Active CN118678352B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202411166447.6A CN118678352B (en) 2024-08-23 2024-08-23 5G user identity authentication method, device, equipment and medium based on head enhancement

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202411166447.6A CN118678352B (en) 2024-08-23 2024-08-23 5G user identity authentication method, device, equipment and medium based on head enhancement

Publications (2)

Publication Number Publication Date
CN118678352A CN118678352A (en) 2024-09-20
CN118678352B true CN118678352B (en) 2024-12-20

Family

ID=92732865

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202411166447.6A Active CN118678352B (en) 2024-08-23 2024-08-23 5G user identity authentication method, device, equipment and medium based on head enhancement

Country Status (1)

Country Link
CN (1) CN118678352B (en)

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114143788A (en) * 2021-12-10 2022-03-04 广州热点软件科技股份有限公司 Method and system for realizing authentication control of 5G private network based on MSISDN

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108156126B (en) * 2016-12-02 2020-12-08 阿里巴巴集团控股有限公司 Method and device for programming and verification of Internet of Things equipment, and method and device for identity authentication
CN109818901B (en) * 2017-11-20 2021-04-20 华为技术有限公司 Method, device and system for determining message header compression mechanism
CN113542201B (en) * 2020-04-20 2023-04-21 上海云盾信息技术有限公司 Access control method and equipment for Internet service

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114143788A (en) * 2021-12-10 2022-03-04 广州热点软件科技股份有限公司 Method and system for realizing authentication control of 5G private network based on MSISDN

Also Published As

Publication number Publication date
CN118678352A (en) 2024-09-20

Similar Documents

Publication Publication Date Title
US10110585B2 (en) Multi-party authentication in a zero-trust distributed system
JP6426189B2 (en) System and method for biometric protocol standard
US8141138B2 (en) Auditing correlated events using a secure web single sign-on login
US20040268145A1 (en) Apparatus, and method for implementing remote client integrity verification
JP2019536157A (en) System and method for transparent multi-factor authentication and security approach posture check
CN110351298A (en) Access control method, device, equipment and storage medium
US9787678B2 (en) Multifactor authentication for mail server access
US20030208694A1 (en) Network security system and method
CN113468591A (en) Data access method, system, electronic device and computer readable storage medium
CN112039878A (en) Equipment registration method and device, computer equipment and storage medium
US12406078B2 (en) Call location based access control of query to database
KR101768942B1 (en) System and method for secure authentication to user access
CN119520146A (en) Login control method, device, bastion host, system, storage medium and program product based on operation and maintenance
US10412097B1 (en) Method and system for providing distributed authentication
CN118678352B (en) 5G user identity authentication method, device, equipment and medium based on head enhancement
CN112398787B (en) Mailbox login verification method and device, computer equipment and storage medium
CN115529156B (en) Access authentication method and device, storage medium and computer equipment
US12401639B2 (en) Computer access control using registration and communication secrets
CN116866010A (en) Port control method and device
JP7510340B2 (en) Authentication device, authentication method, and authentication program
KR101975041B1 (en) Security broker system and method for securing file stored in external storage device
CN115174181B (en) Method, device, equipment and storage medium for realizing single sign-on
CN119743305B (en) Protocol self-adaptive double-factor authentication method based on Linux system
CN117574349B (en) Single sign-on authentication method, device, electronic device and storage medium
CN119885150A (en) Double-factor authentication method based on user information and mobile terminal verification code

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant