基于堡垒机的内网安全运维方法、设备、介质及程序产品
By introducing zero-trust proxy and dynamic authorization mechanisms into the bastion host, and establishing end-to-end encrypted tunnels and real-time authorization policies, the security and management challenges of traditional bastion hosts in complex intranet environments are solved, achieving efficient and reliable intranet operation and maintenance management and auditing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING TOPSEC NETWORK SECURITY TECH
- Filing Date
- 2025-12-15
- Publication Date
- 2026-07-17
AI Technical Summary
Traditional VPN and jump server models have problems such as complex deployment, difficult management, large attack surface, authorization difficulties and insufficient auditing and traceability in ensuring the security of internal network assets. They are especially difficult to effectively ensure the security of internal traffic in multi-cloud, hybrid cloud or deeply isolated internal network environments.
A bastion host system based on zero-trust proxy is adopted. By deploying zero-trust proxy clients on the internal network resource side, an end-to-end encrypted application layer tunnel is established. Combined with identity awareness and dynamic authorization engine, context information is obtained in real time to generate dynamic authorization policies for operation and maintenance management, and operation and maintenance traffic is transmitted through the application layer tunnel.
It enables secure operation and maintenance in complex network environments, ensures continuous verification and least privilege access for operation and maintenance terminals, improves the security and management reliability of intranet operation and maintenance, and provides refined operation and maintenance auditing and simplified deployment and expansion capabilities.
Smart Images

Figure CN121619154B_ABST