Digital certificate and multilevel field based unified identification management and authentication method

A technology of identity management and digital certificate, which is applied in the field of unified identity management and authentication, can solve problems such as increasing the complexity of user business operations, untimely user information and data, and inconsistent user passwords, so as to facilitate management and maintenance and enhance security , the effect of unified user identity

Inactive Publication Date: 2008-05-14
JIANGSU ELECTRIC POWER CO
View PDF0 Cites 19 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Since these business systems are only oriented to their respective business departments, each business department has to maintain a set of independent user identity management and authentication; at the same time, in the actual business process, once the user's information changes, such as job changes, etc. , and related business systems need to be adjusted to adapt to this change. The direct problem brought about by this change is that user information data is not timely and out of sync.
In addition, with the continuous improvement of business system construction, users use multiple business systems at the same time more and more frequently, and the authentication of each business system is independent of each other, and user passwords are not unified. Various user login names and passwords are used to log in, causing users to remember multiple user accounts and passwords, even including the corresponding access addresses of various business systems, which virtually increases the complexity of user business operations

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0013] A unified identity management and authentication method based on digital certificates and multi-level domains according to the present invention is characterized in that it includes the following steps:

[0014] (1) First, maintain user identity; first, use timing to synchronize user identity information with the human resources system; second, complete user data information management through manual maintenance;

[0015] (2) The user identity information is synchronized to the domain; the user identity information is synchronized to the corresponding AD subdomain according to the user's affiliation through the standard LDAP protocol; among them, the change of the user password is through the CA distributed by the AD root domain, through the LDAPS method finished editing;

[0016] (3) User authentication; the authentication service uses the Single Pass Negotiate Identity Assertion Provider provided in WebLogic Platform8.1 for Single Sign-On with Windows clients; combine...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses a unified identification management and authentication method based on digital certificates and multi-leveled domains. At first, user identification is maintained. User identification information is synchronized with the human resource system. User data information management is then completed by means of manual maintenance. User identification information is synchronized to the domain. By the standard LDAP agreement, user identification information is synchronized to the corresponding AD sub-domain according to the unit the information belongs to. Then user authentication is realized. The user can logon in two ways. First, when the computer of the user logons onto the AD domain, all the business systems can be visited without inputting the user name and password. Second, all the business systems can be visited after the user has input the user name and password for once. The invention avoids the possibility that user information does not agree or is not in time. Besides, single sign-on among all the business systems is realized, thus avoiding logon for twice or multiple times. Then technical and developing cost to realize single sign-on is reduced.

Description

technical field [0001] The invention belongs to the field of information security and authentication, in particular to a unified identity management and authentication method based on digital certificates and multi-level domains. Background technique [0002] With the continuous development and acceleration of information construction, business system construction has gradually been enriched in various business departments and daily work. Since these business systems are only oriented to their respective business departments, each business department has to maintain a set of independent user identity management and authentication; at the same time, in the actual business process, once the user's information changes, such as job changes, etc. , and related business systems need to be adjusted to adapt to this change. The direct problem brought about by this change is that user information and data are not timely and out of sync. In addition, with the continuous improvement o...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L9/32H04L12/24
Inventor 许海清王纪军唐巍
Owner JIANGSU ELECTRIC POWER CO
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products