Data resource security control method in thin client mode

A data resource and thin client technology, applied in the field of network security, can solve problems such as data loss, leakage or tampering, and achieve the effect of ensuring legality and authenticity

CN103441986AActive Publication Date: 2013-12-11706 INST SECOND RES INST OF CHINAAEROSPACE SCI & IND
3 Cites 71 Cited by

Patent Information

Authority / Receiving Office
CN · China
Current Assignee / Owner
Publication Date
2013-12-11

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention belongs to the field of network security, and particularly relates to a data resource security control method in a thin client mode. The data resource security control method in the thin client mode comprises eight subsystems, namely the identity authentication subsystem, the remote application service subsystem, the security label subsystem, the file access control subsystem, the security communication subsystem, the security audit subsystem, the security storage subsystem and the management platform subsystem. Storage and control of files are mainly performed on a background server, the files are stored in different partitions according to user types or security levels of the files, the files are stored and protected, and a server side can not recognize the content of the files. When a user needs to have access to and process the files, the user logs in on a browser, identity authentication is conducted between the user and a server, and then file access connection is established. The files of a thin client are processed on the server side (provided by a physical application server or a virtual application server), no application or agent needs to be installed on the thin client, and interface interoperability is supported by related services released by remote application services.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention belongs to the technical field of network security, in particular to a data resource security management and control method in a thin client mode. Background technique

[0002] With the improvement of informatization popularization, the military, party and government or government agencies have established internal networks. Network erection and information system construction have brought many conveniences to these units, such as resource sharing, office automation, and convenient information transmission. Greatly improved work efficiency. However, with the improvement of the openness of the closed system, more and more information security issues have emerged at the same time. The openness and sharing characteristics of the network make the important information resources distributed in each host in a high-risk state, and these data are vulnerable to various malicious attacks such as illegal monitoring, illegal copying, and illegal acc...

Examples

Embodiment Construction

[0060] The method of the present invention will be described in detail below in conjunction with the flow chart.

[0061] Step 1: Start the browser, the user logs in to the server through the USBKEY and user name and password, and the server completes the user's identity authentication through the identity authentication subsystem.

[0062] Server security management and control software supports multiple identity authentication methods: user name + password, USBKey + PIN code, CA digital certificate. At the same time, it supports custom configuration of password strength policy, account lock policy, pull KEY lock screen, terminal binding and other auxiliary functions.

[0063] Considering that the CA digital certificate system has been widely used and has been used as the basic condition of informatization, the identity authentication is completed by using the bottom library of the authentication device, authentication client and authentication server that has provided the CA...