Domain Name Access Control for Secure SaaS Application Recognition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies struggle to efficiently secure and manage network access for applications, particularly in environments where existing technologies fail to effectively address the challenge of ensuring secure access to Software as a Service (SaaS) applications, leading to potential data security risks due to false or missing recognition of IP addresses.
Innovation Solution
An access control method and system utilizing a security management application client, central domain name system, and application gateway to perform domain name resolution and determine targeted access policies based on configuration files, ensuring accurate application access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IP address-based access control is used for SaaS applications, then network access management is simplified, but false or missing recognition occurs leading to security risks
Solution Approach 1:
The patent changes the identification parameter from IP address to domain name. Instead of controlling access based on IP addresses which cause false or missing recognition, the system resolves domain names to identify applications, thereby improving recognition accuracy while maintaining ease of management through centralized domain name configuration
Solution Approach 2:
The patent introduces a domain name resolution mechanism as an intermediary between the access control system and SaaS applications. The gateway performs domain name resolution to accurately identify target applications, acting as a mediator that transforms IP-based control into domain name-based control to eliminate recognition errors
2Reliability
If domain name resolution is implemented for accurate application identification, then access security is improved, but system complexity increases
Solution Approach 1:
The patent makes the gateway server perform multiple functions: it acts as both a domain name resolver and an access control gateway. By integrating these functions into a single component, the system achieves accurate application identification through domain name resolution without proportionally increasing overall system complexity
Solution Approach 2:
The gateway server autonomously performs domain name resolution when receiving access requests. Instead of requiring external resolution services, the gateway self-resolves domain names using its integrated resolution capability, reducing the need for additional external system components
3Measurement precision
If centralized domain name system is used for resolution, then access control accuracy is improved, but network communication overhead increases
Solution Approach 1:
The system performs domain name resolution in advance when the gateway receives an access request, before the actual application access occurs. This preliminary resolution action ensures accurate application identification is established beforehand, reducing delays during the actual access operation
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The present disclosure relates to the field of network technologies and discloses an application access control method and system, and a device, a medium and a program product thereof. The present disclosure provides an application access control method. The method includes: generating, by a security management application client, an access request after detecting access to a target application, and sending the access request to a central domain name system; performing, by the central domain name system, domain name resolution on the access request to obtain a target application domain name of the target application, and sending the target application domain name to an application gateway; and determining, by the application gateway, a target access policy for the target application based on a matching result of the target application domain name in a first configuration file, and controlling, based on the target access policy, a terminal device.