Unlock instant, AI-driven research and patent intelligence for your innovation.

Directory service-based authorization management system and implementation method thereof

A technology of authorization management and directory service, applied in transmission system, user identity/authority verification, electrical components, etc. tampering and other issues to achieve the effect of improving system availability, ensuring authenticity, and avoiding human tampering

Active Publication Date: 2014-04-16
CHANGCHUN JIDA ZHENGYUAN INFORMATION TECH CO LTD
View PDF3 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0005] (2), patent application CN 200610076491.3 (application date: 2006.04.26, name: information system or equipment security protection system and its working method), CN 200810040672.X (application date: 2008.07.17, name: digital certificate-based technology system user access management system and method), CN 200810040674.9 (application date: 2008.07.17, name: an access control method and device for an information system based on digital certificate technology), CN 200620100455.1 (application date: 2006.01.18, name : a network security authentication and authorization system) and CN 200710147233.4 (application date: 2007.08.30, name: distributed business operation support system and method for realizing distributed business) both disclose a kind of identity authentication for login users, and in Technical solutions for obtaining corresponding access rights after passing authentication, but these technical solutions lack security management of user rights information, cannot effectively avoid the possibility of human tampering, and support a limited number of users, which cannot solve a large number of users (especially A large number of users who are not registered in the system) unified authorization and security access control issues
[0007] The disadvantages of the above technical solutions are that it is impossible to authorize a large number of user groups (especially a large number of user groups that are not registered in the system), and release the authorization information in a reliable form of attribute certificates, so as to realize multiple Unified user authorization management and security access control for application systems

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Directory service-based authorization management system and implementation method thereof
  • Directory service-based authorization management system and implementation method thereof
  • Directory service-based authorization management system and implementation method thereof

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0042] Such as figure 1 As shown, it is a physical deployment diagram of a directory-based authorization management system. The system consists of an authorization management platform 1, at least one local slave directory service device 2, at least one local application device 3, and at least one user device 4, wherein the authorization management platform 1 and the local secondary directory service device 2 are connected through the Internet, and the local secondary directory service device 2, the local application device 3 and the user device 4 are connected through a local area network.

[0043] Authorization management platform 1 is used to manage and maintain authorization elements and authorization relationships including user groups and application roles in the system, issue the authorization information as attribute certificates, and provide directory services based on attribute certificates based on LDAP protocol.

[0044] The local secondary directory service device ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a directory-based authorization management system, which comprises an authorization management platform, at least one local slave directory service device, at least one local application device and at least one user device, wherein the authorization management platform, the local slave directory service device, the local application device and the user device are connected with one another through a network. Authorization management is uniformly performed on an application system and a user by the authorization management platform, authorization information between a user group and an application role is released in the form of an attribute certificate, and corresponding purchase management index (PMI) local slave directory servers are arranged in a plurality of regions and are used for copying the attribute certificate of the local application device to local according to a strategy, so that user authorization information is quickly provided for a local application system, an application mode is simplified, system security is further enhanced, and load, which is caused by concurrency of a large number of users, on the system is effectively lowered; simultaneously, system availability is enhanced and maintenance cost is lowered.

Description

technical field [0001] The present invention relates to the technical field of information security, in particular to an authorization management system based on directory services and an implementation method thereof. Background technique [0002] With the improvement of government and enterprise informatization, the number of application systems has gradually increased. When the number of users is very large, the geographical distribution is relatively wide, and the number of application systems is large, the authorization of application systems becomes a very difficult problem. In a large government or enterprise, the following situations often occur: an employee has left the job, but can still access some very important application systems normally; an employee's position has changed, and the application system still corresponds to the old permissions; Due to temporary business needs, I registered an account for someone from other places in an application system and ope...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L9/32H04L29/06
Inventor 史凤涛苏日丁肇伟
Owner CHANGCHUN JIDA ZHENGYUAN INFORMATION TECH CO LTD