Access control system and method between domains based on domain name

An access control and cross-domain technology, applied in the transmission system, digital transmission system, user identity/authority verification, etc., can solve the problem of increasing access control delay, poor user service experience, and affecting the service quality of network service providers, etc. problem, to achieve the effect of reducing authentication delay

Active Publication Date: 2009-07-01
EWELL TEHCNOLOGY CO LTD
View PDF0 Cites 22 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0020] (1) When accessing across domains, that is, when the user is not a user in the current domain, the identity authentication data packet to the identity authentication server in the home domain must be forwarded by the access domain server, which increases the access control delay and improves the service experience for the user. Relatively poor, affecting the service quality of network service providers
[0021] (2) On the identity authentication server, the identity authentication server information corresponding to the domain to which the user belongs is statically configured, so that only users in a limited number of pre-configured domains can be identified, and users in other domains cannot access the current network, so that the system not scalable
In addition, when the identity authentication server of a certain domain changes, such as changing the IP address, it is necessary to modify the configuration on each identity authentication server one by one, which increases the workload of management personnel and causes service interruption

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Access control system and method between domains based on domain name
  • Access control system and method between domains based on domain name
  • Access control system and method between domains based on domain name

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0054] The technical features of the present invention will be described in detail below in conjunction with the embodiments and accompanying drawings.

[0055] see image 3Shown is a schematic structural diagram of the domain name-based cross-domain access control system of the present invention.

[0056] The cross-domain access control system 300 includes a user client 301 , a network access control server 302 , a domain name server 304 , and an identity authentication server 306 .

[0057] The user client 301 sends a user authentication request or a logout request when accessing / disconnecting from the network, and provides necessary information to prove the user's identity. Wherein, each user in the system has a globally unified identifier, and the identifier includes information about the domain to which the user belongs. The request sent by the user client 301 includes the identifier. The identification can use user name / password identification, special identification,...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses a cross-domain access control system based on a domain name and a method. The method comprises the step as follows: in step one, a network access control server extracts user domain information in a certification request sent by a user client; in step two, corresponding relation information between a domain and an identity authentication server is stored in the network access control server; the network access control server searches the corresponding identity authentication server according to the user domain information, and transmits the certification request to the searched identity authentication server; and in step three, the identity authentication server performs the user identity authentication according to the received certification request. The network access control server can be directly communicated with a native-place identity authentication server, and a data packet need not to be transmitted through accessing a domain identity authentication server, so that the authentication delay is reduced, and the extensibility is strong.

Description

technical field [0001] The invention belongs to the technical field of access control in network security technology, and in particular relates to a network access control system and method across management domains. Background technique [0002] At present, various network service providers generally implement different degrees of access control on network users. Access control refers to the process of identifying the user's identity through the user identity authentication system, determining whether the user can access the network and setting access rights before the user accesses network resources. [0003] At the same time, sites and resources on the network may belong to different management domains, provided and managed by different organizations, so that the entire network is divided into multiple different management domains. With the increasing abundance of resources on the Internet and the enhancement of user roaming and mobility, more and more users use the netw...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L9/32H04L29/06H04L12/56H04L12/28
Inventor 许智君张玉军
Owner EWELL TEHCNOLOGY CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products