基于堡垒机的内网安全运维方法、设备、介质及程序产品

By introducing zero-trust proxy and dynamic authorization mechanisms into the bastion host, and establishing end-to-end encrypted tunnels and real-time authorization policies, the security and management challenges of traditional bastion hosts in complex intranet environments are solved, achieving efficient and reliable intranet operation and maintenance management and auditing.

CN121619154BActive Publication Date: 2026-07-17BEIJING TOPSEC NETWORK SECURITY TECH +2

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING TOPSEC NETWORK SECURITY TECH
Filing Date
2025-12-15
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Traditional VPN and jump server models have problems such as complex deployment, difficult management, large attack surface, authorization difficulties and insufficient auditing and traceability in ensuring the security of internal network assets. They are especially difficult to effectively ensure the security of internal traffic in multi-cloud, hybrid cloud or deeply isolated internal network environments.

Method used

A bastion host system based on zero-trust proxy is adopted. By deploying zero-trust proxy clients on the internal network resource side, an end-to-end encrypted application layer tunnel is established. Combined with identity awareness and dynamic authorization engine, context information is obtained in real time to generate dynamic authorization policies for operation and maintenance management, and operation and maintenance traffic is transmitted through the application layer tunnel.

Benefits of technology

It enables secure operation and maintenance in complex network environments, ensures continuous verification and least privilege access for operation and maintenance terminals, improves the security and management reliability of intranet operation and maintenance, and provides refined operation and maintenance auditing and simplified deployment and expansion capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121619154B_ABST
    Figure CN121619154B_ABST
Patent Text Reader

Abstract

本申请实施例提供一种基于堡垒机的内网安全运维方法、设备、介质及程序产品,涉及运维管理技术领域。所述方法包括:响应于零信任代理客户端主动发起的连接请求,在双向认证通过的情况下,在零信任代理服务端与零信任代理客户端之间建立端到端加密的应用层隧道;获取运维终端对应的上下文信息,并基于上下文信息确定动态授权策略;基于动态授权策略对运维终端的运维操作进行运维管控,并通过应用层隧道传输运维终端与内网资源侧之间产生的运维流量。在本申请实施例通过构建以内部资源侧作为主动连接端的零信任系统模型,并通过实时获取相关上下文信息以生成动态授权策略,从而大大提升了内网运维的安全性。
Need to check novelty before this filing date? Find Prior Art