Generalized policy server
Abstract
A scalable access filter that is used together with others like it in a virtual private network to control access by users at clients in the network to information resources provided by severs in the network. Each access filler use a local copy of an access control data base to determine whether an access request made by a user. Changes made by administrators in the local copies are propagated to all of the other local copies. Each user belongs to one or more user groups and each information resource belongs to one or more information sets. Access is permitted or denied according to of access policies which define access in term? of the user groups and information sets. I he rights of administrators are similarly determined by administrative policies. Access is further permilled only if the trusi leveis of a mode of identification of the user and of the path in the network by which the access is made are sufficient for the sensitivity level of the information resource. If necessary, the access filter automatically encrypts the request with an encryption method whose trust level is sufficient. The first access filter in the path performs the access check and encrypts and authenticates the request; the other access filters in the path do not repeat the access check. A policy server component of the access filter has been separated from the access fitter and the policies have been generalized to permit administrators of the policy server to define new types of actions and new types of entities For which policies can be made Policies mav now f>.irtlier have specifications For time Intervals during which the policies are in iurce and the entities inav be associated with attributes that specify how the entity is to be used wlien the policy applies

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
12 claims: 9 independent, 3 dependent
- 1A decision execution system used to execute a decision, the decision will be defined; the first entities defined in the computer system may perform actions belonging to the first type among the second entities defined in the computer system The types of the decision execution system include:a decision server, which includes a decision database of many decisions;and a decision executor;it controls the performance of the first action type, and can The request for performing the first type of action is transmitted to the decision server;only if one of the decision servers responds to the instruction: the decision allows the action, the decision executor allows the execution of the action, and the decision execution system has characteristics To: The decision database can be expanded to include decisions for actions that belong to the additional types therein;therefore, an additional decision executor that can control the execution of additional types of actions may be added to the decision execution system. 1.一種用來施行決策的決策施行系統,該決策會定義;在電腦系統中所定義的諸多第一實體可能針對在電腦系統中所定義的諸多第二實體執行哪些屬於其中第一類型的行動,該決策施行系統所屬的類型,包括:一決策伺服器,它包括諸多決策之一決策資料庫;以及一決策施行器;它會控制第一行動類型之執行(performance),並且能夠將一項用來執行第一類型之行動的請求傳達給決策伺服器;唯若來自決策伺服器之一回應指示:決策允許該行動,決策施行器才會允許行動之執行,而該決策施行系統則具有特徵為:決策資料庫是可以擴充的,以便包括針對屬於其中附加類型之諸行動的決策;因此,可能將一種會控制附加類型之行動之執行的附加決策施行器增加到決策施行系統。 經濟部智慧財產局員工消費合作社印製 448387 A7 ------- B7 五、發明說明() 1. -種用來施行決策的決策施行系統,該決策會克義:在 7腦系,中所定義的諸多第—實趙可能針對在電腦系 統中所足義的諸多第二實體執行哪些屬於其中第一麵 型的行動,該決策施行系^所屬的類型,包括:' :決策词服器’它包括諸多決策之一決策資料庫;以及 一決策施行器;它會控制第—行動類型之執行 (performance),並且能夠將一項用來執行第—類型之行 動的請求傳達給決策伺服器;唯若來自決策伺:器之 =回應指示:決策允許該行動,決策施行器才舍允許 盯動疋執行,而該決策施行系統則具有特微為: 決策資料庫是可以擴充的,以便包括釺對屬於其中 附加類型之諸行動的決策;因此,可能將—種會控制 附加類型之朽·動之勃_行的附加》策施行器増加到決策 施行系統。 2 .根據申請專利範圍第i項之決策施行系統’進一 特徵為: 決策資料庫是屬於依據第一實體之集合和第二實體之 集合來定義決策的類別;以及 、 ”決策資料庫是可以進—步擴充的,以便包括:—附加 第一贯體類型及/或一附加第二實體類型。 3 .根據申請專利範圍第2項之決策施行系統,進—步具有 特徵為: 〃 一項行動屬性可能在資料庫中與第一實體之集合及/或 第二實體之集合有關聯,該行動屬性會載明:打算執行 -138· 本紙張尺度適用中國國家標準(CNS)A4規格(210 x297公楚) 4 ,---------.裝--------訂·--------^ (請先閱讀背面之注意事項再填寫本頁) 448387 A8 B8 C8 D8 六、申請專利範圍 第—’體々集合中的諸多實體及,或在第二實-i 不δ中的諸多實體而載明在― 、 依照的一種方式。 弋決策中的—項行動所 4.根據中請專利範園第3項之決 特徵爲: 仃系..无’堪一步具有 決策資料庫是可以進一步撼一。 齡’… 5 ·根據申請專利範圍第 有特徵爲: 附加決策施行器會在電腦系 執行,該層級與決策施行器控層級處㈣行動之 不同。 之執行所處的層級 6·根據申請專利範圍第 有特徵爲: 電中至少有—個是在遠離決策词服器之 4系統中的一個位置 7-根據申請專利範園第 有特徵爲: fk 行系統,進一步具 行系統,進一步具 行系統,進一步具 k--------訂---------線. ί請先閲讀背面之注意事項再填寫本頁) 經濟部智慧財產局員工消費合作社印M 決策施行器會控制不是電腦系統之—部份的第二實 體。 、 8.種屬於依據第一實體之集合,第二實體之集合,以及 著多行動來定義決策之類別的決策資料庫,—既定決 朿會疋義:屬於既定第一實體之集合之—實體可能針 對屬於既定於第二實體之集合之—實體執行的一項既 -139- 本纸張尺度適用中國國家標準(CNS)A4規格(21〇 x 297公釐) 448387 A7 ---------B7 五、發明說明() 定行動;該決策資料庫具有特徵為: 一項另加條件可能在資料庫中與既定決策有關聯,該 另加條件會在屬於既定第一實體之集合之一請求實體 提出一項詩求以執行針對屬於既定第二實體之集合之 -實體的既定行動之時決定:請求實體是否可能執行 該行動。 9.根據申請專利範圍第8項之決策資料庫,進一步具有特 徵為: —另加條件是一種與既定決策有關聯的時間間隔規 範’時間間隔規範會載明時間之間㈤;在#問間隔期 間,屬於載明在既定決策中的既定第一實體之集合的 諸多實體可能執行:針對屬於其中所載明的既定第二 實體之集合的諸多實體,其中所載明的既定行動。 Π)‘-種屬於依據第一實體之集合,第二實體之集合,以及 諸多行動來定義決策之類別的決策資料庫一既定決策 會定義:屬於既定第—實體之集合之—實體可能針對屬 於既^二實體之集合之—實體執行的—項既定行動; 該決策資料庫具有特徵為: -項行Μ性可能在資料庫中與既定第—實體之集合 及/或既定第二實體之集合有關聯,該行動屬性會載明: 打算執行載明在既定決策中之既定行動所依照的一種方 式。 η.根據申請專利範圍第10項之決策資料庫, 徵為: -140 表紙張尺度適用中國國家標準(CNS)A4規格(210x297公发 (請先閱讀背面之注意事項再填寫本頁) .si---------訂---------,¾ 經濟部智慧財產局員工消費合作社印製 44838 7 0088¾ ABCS 六 經濟部智慧財產局員工消費合作社印製 圍 々孝專 青 =° 申 ㈣策資科庫是可《擴充的,《便包括諸多新行動屬性⑽线州庫卞步具有特 -種行動屬性條件可能在資料庫 -行動屬性有關聯,該行動屬性條件會在十::決策之 請求之時決定:屬於既定第—實請求貫證提出 是否能夠執行針對在既定第二實體二=-請求實體 既定行動’該行動是如行動屬性中所:二-艾體的 -141 - 本纸張尺度適用中固國家標準(CNS)A4規格(210 X 297公釐) ------ ( -I I n I I I-- - 1« n - - 一。,* It - - I f[ I f (請先閱讀背面之注意事項再填寫 頁)
- 2The decision execution system according to item 1 of the scope of patent application, further having the characteristics that the decision database is a category that defines decisions based on the collection of the first entity and the collection of the second entity; and the decision database can be further expanded So as to include:an additional first entity type and / or an additional second entity type. 2.根據申請專利範圍第1項之決策施行系統,進一步具有特徵為:決策資料庫是屬於依據第一實體之集合和第二實體之集合來定義決策的類別;以及決策資料庫是可以進一步擴充的,以便包括:一附加第一實體類型及/或一附加第二實體類型。
- 3The decision execution system according to item 2 of the scope of patent application, further having the feature that an action attribute may be associated with a collection of the first entity and / or a collection of the second entity in the database, and the action attribute may be contained in the database. Description:A manner in which an action is intended to be carried out in relation to a number of entities in the collection of the first entity and / or a number of entities in the collection of the second entity, in a given decision. 3.根據申請專利範圍第2項之決策施行系統,進一步具有特徵為:一項行動屬性可能在資料庫中與第一實體之集合及/或第二實體之集合有關聯,該行動屬性會載明:打算執行關於在第一實體之集合中的諸多實體及/或在第二實體之集合中的諸多實體而載明在一既定決策中的一項行動所依照的一種方式。
- 4The decision execution system according to item 3 of the scope of patent application, further having the feature that the decision database can be further expanded to include an additional action attribute type. 4.根據申請專利範圍第3項之決策施行系統,進一步具有特徵為:決策資料庫是可以進一步擴充的,以便包括一附加行動屬性類型。
- 8A decision database that is based on the collection of the first entity, the collection of the second entity, and many actions to define the type of decision. A given decision defines:an entity that belongs to the given first entity may An established action performed by an entity that is a collection of second entities;the decision-making database is characterized by: an additional condition may be associated with the established decision in the database, and the additional condition will belong to the established first One of the set of entities asks the entity to make a request to perform a given action against one of the entities belonging to the set of established second entities;whether it is possible for the requesting entity to perform the action. 8.一種屬於依據第一實體之集合,第二實體之集合,以及諸多行動來定義決策之類別的決策資料庫,一既定決策會定義:屬於既定第一實體之集合之一實體可能針對屬於既定於第二實體之集合之一實體執行的一項既定行動;該決策資料庫具有特徵為:一項另加條件可能在資料庫中與既定決策有關聯,該另加條件會在屬於既定第一實體之集合之一請求實體提出一項請求以執行針對屬於既定第二實體之集合之一實體的既定行動之時決定;請求實體是否可能執行該行動。
- 9The decision database according to item 8 of the scope of patent application is further characterized by:the additional condition is a time interval specification associated with a given decision, and the time interval specification will specify the time interval;during the time interval, Many entities that specify the set of established first entities in a given decision may perform: for many entities that belong to the set of established second entities contained therein, the set actions stated therein. 9.根據申請專利範圍第8項之決策資料庫,進一步具有特徵為:另加條件是一種與既定決策有關聯的時間間隔規範,時間間隔規範會載明時間之間隔;在時間間隔期間,屬於載明在既定決策中的既定第一實體之集合的諸多實體可能執行:針對屬於其中所載明的既定第二實體之集合的諸多實體,其中所載明的既定行動。
- 10A decision database that is based on the collection of the first entity, the collection of the second entity, and many actions to define the type of decision. A given decision defines:an entity belonging to the given first entity may An established action performed by one of the collections of the second entity;the decision database has the feature that an action attribute may be associated with the set of the established first entity and / or the set of the established second entity in the database , The attribute of the action will indicate the method by which the intended action stated in the stated decision is to be performed. 10.一種屬於依據第一實體之集合,第二實體之集合,以及諸多行動來定義決策之類別的決策資料庫,一既定決策會定義:屬於既定第一實體之集合之一實體可能針對屬於既定第二實體之集合之一實體執行的一項既定行動;該決策資料庫具有特徵為:一項行動屬性可能在資料庫中與既定第一實體之集合及/或既定第二實體之集合有關聯,該行動屬性會載明:打算執行載明在既定決策中之既定行動所依照的一種方式。
- 11The decision database according to item 10 of the patent application scope is further characterized by that the decision database can be expanded to include many new action attribute types. 11.根據申請專利範圍第10項之決策資料庫,進一步具有特徵為:決策資料庫是可以擴充的,以便包括諸多新行動屬性類型。
- 12The decision database according to item 10 of the scope of patent application is further characterized by:an action attribute condition may be associated with one of the action attributes for a given decision in the database, and the action attribute condition will be requested by the requesting entity. It is determined whether the requesting entity belonging to the set of the given first entity is able to perform a given action against one of the entities in the set of the given second entity, as specified in the action attribute. 12.根據申請專利範圍第10項之決策資料庫,進一步具有特徵為:一種行動屬性條件可能在資料庫中與針對既定決策之一行動屬性有關聯,該行動屬性條件會在請求實體提出請求之時決定:屬於既定第一實體之集合之一請求實體是否能夠執行針對在既定第二實體之集合中之一實體的既定行動,該行動是如行動屬性中所載明的。
Independent claims9
450 paragraphs, as filed
Generalized decision server
1Secure delivery of information on the network
See the related patent application
2 Cross-refer to related patent applications
The patent application is: On June 29a, 1998, a request from Flannel, Lipstone, Schneider, and the title "General Decision Servo" "Shame Week"-Provisional Patent Application No. 601091,130 enjoys priority. "This patent is filed and is: In March 1998, 4EI was filed by David Schneider and others, The continuation of one of the patent applications (USSN) No. 091034,507 entitled "Base for Distributed Management of Access Information"; therefore, it contains the entire description and drawings of the patent application. The new material in this patent application begins with the section entitled "General Rules for Many Techniques Used in the Access Filter 203" and includes some new drawings 26 to 37.
Background of the invention
2 BACKGROUND OF THE INVENTION 1. Field of Invention
31. Field of Invention
The present invention is generally related to the control of accessing data; more specifically, it is related to the control of accessing data in a distributed environment.
2. Description of skills
32. Description of Skills
The Internet has revolutionized data communications. It has been achieved by providing many protocols and addressing schemes, regardless of the physical hardware of the computer system, the type of physical network to which it is connected, or the type of physical network used to send the information from a computer system What kind of physical network to another computer system, this solution makes it possible for any computer system anywhere in the world to exchange information with any other computer system anywhere in the world. All requirements for two computer systems to exchange information are: each computer system must have an Internet address and software required for the communication protocol; and, with some combination of many physical networks, two machines There will be a route between them, which may be used to carry messages constructed according to communication protocols.
However, the ease with which computer systems may exchange information via the Internet has caused problems. On the one hand, it has made accessing information easier and cheaper than ever; on the other hand, it has made it more difficult to protect information. The Internet has made it more difficult to protect information in two ways:
It is more difficult to restrict access operations. If it is possible to access information via the Internet, it is said that it is possible to access anyone's information as the Internet information is accessed. Once information is accessed via the Internet, blocking skilled intruders becomes a difficult technical problem.
It is difficult to maintain security enroute via the Internet. Constructing the Internet as a packet switching network cannot predict what route a message will take through the network. It is even more impossible to guarantee the security of all information exchanges, or to include those parts of the message that specify their source or destination: they have not been read or changed on the way.
Figure 1 shows the current technology used to increase the security of networks that can access information via the Internet. Figure 1 shows: Network 101, which is composed of two separate internal networks 103 (A) and 103 (B), which are all connected to the mountain Internet 111. Although the two networks 103 (A) and 103 (B) are generally inaccessible, in a sense, they are both part of the Internet. 'Computer systems in these networks Both have Internet addresses, and both use Internet Protocols to exchange information. "Two such computer systems appear in Figure 1, like the requestor 105 and 103 in network 103 (A). Like the server 113 in the network 103 (b). The requester 105 is requesting access to the data that can be provided by the server 113. Attached to the server 113 is a mass storage device 115 which contains the request being requested by Of course, for other data, the server 113 may be the requester, and the requester 105 may be the server. Moreover, in the current context, the access operation is considered to be able to read Or change the information stored on the server 113 or any operation that can change the status of the server 113. In making requests, the requester 105 is using many benchmark TCPIIP (Transmission Control Protocol / Internet Protocol) protocols An agreement As used herein, the communication protocol is a description of which can be used to exchange information between collections of one of the many computer systems.
Some actual messages sent between computer systems that are communicating according to a communication protocol are collectively referred to as "sessions." During a conversation, the requester 105 sends messages to the Internet of the server 113 according to the communication protocol. Address, and the server 113 sends the message to the Internet address of the requester 105 according to the communication protocol. Both the request and the response will be transmitted through the Internet III on the two internal networks 103 (A) and I03 (B), if the server 113 allows the requester 105 to access the data, some messages will flow from the server 113 to the requester 105 in the dialogue. The soap will include the requested data 117 and will be used by the Internet if necessary. Many software components of the server 113 that responds to messages over the Internet are called services.
If the owners of the two internal networks 103 (A and B) want to be sure: Only users of computer systems directly connected to network 103 (A and B) can access data 117, and request and respond to The content is unknown outside those networks: the owner must address two issues: make sure server 113 is not responding to requests from computer systems that are different from those connected to the internal network; And I am sure that although it is in transit through the Internet 111, anyone who accesses the information of the Internet 111 cannot access or modify the request and response. Two technologies that are likely to achieve these goals are: firewalls and tunneling using encryption.
Conceptually, the firewall is a barrier between the internal network and its ringing Internet 111. Prevent the wall from appearing at 109 (A) and (B). The firewall 109 (A) protects the internal network 103 (A), and the firewall 109 (B) pIl protects the internal network 103 (B). The firewall is constructed by a gateway operating in a computer system. Installed where the intranet is connected to the internet. Included in the path is an access filter: a set of hardware and software components in a computer system that responds to all requests from outside the internal network for information stored within the internal network And, if it comes from a source that has access to the information, it will only send the request on the intranet. "Otherwise, it will discard the request. Two such access filters, access filter 107 (A) The access filter 107 (B) appears in FIG.
If two questions can be answered with certainty, the source has access to the requested information:
Is the source actually the rightful person or thing?
Does the source have access to the data?
The process of finding the answer to the first question is called identification. By providing information to the firewall that identifies the user, the user personally authenticates the firewall. There are several items in this information.
White is information provided by the user-owned authentication token (sometimes called a smartcard); the operating system identification of the user's machine; and the IP address and Internet access of the user's machine Domain name.
The information used by the firewall for authentication may be inband, that is: it is part of the communication protocol; or it may be outofband, that is: it is composed of a separate communication protocol As apparent from the list of identification information provided above, the firewall can rely on the identification information to identify the extent to which the user has reached, depending on the type of identification information. The police say that an IP address in a packet can be coupped by anyone who can intercept the packet: therefore, the firewall can give a little trust to it, so the identification by IP address is called Has a very low level of trust. On the other hand, when the identification information comes from a token, the firewall can give the identification information a higher level of trust. This is fixed: only if the token is already owned by someone else, it should not identify the user. "Usually, for a discussion on authentication, see the book by S. Bellovin," W. Cheswick: "Firewall and Internet Security" The book was printed by Addison Wesley Book Company, KAJ-N, 1994 edition.
In modern access filters, access operations are checked at two levels: the Internet subcontracting information or IP level for short, and the application level. Starting from the IP level, messages used in the Internet are carried in subcontracting methods, called datagrams. Each of these subcontractors has a header, which contains instructions for subcontracting. Source and destination information. The source and destination are each represented by an IP address and a portnumber. The port number is a number from 1 to 55535 which is used to separate the multiple traffic softraffic in the computer. It will be aimed at some well-known Internet communication protocols such as HTTP (Super Text Transfer Protocol) or FTP (File Transfer Protocol) services specify a number of well-known ports that they "listento to. Access filters have a set of rules that indicate which targets may receive IP subcontracting information from which sources: and if the source and target specified in the header do not follow these rules, the subcontracting information is discarded. For example, the rule may allow or disallow all access operations from one computer to another; or restrict access to a specific service based on the source of the IP subcontracting information (specified by the port number) . However, in the title of the IP subcontracting information, there is no information about the individual pieces of information being accessed, and the only information about the user is the source information. Therefore, access verification cannot be done at the IP level, but must be done at the information protocol level. The access verification involves: not identifying users who are unlikely to use the source information, say whether to determine whether the user Right to access a snippet.
Access checks at the application level are usually done in the firewall by proxies. A proxy server is a software component that accesses a filter. The reason why it is called a proxy server is that it can be used as a stand-in of the communication protocol in the access filter. In order to achieve user authentication and / or storage of the information fragments that the user has requested Take check. Police ju "vk, a commonly used TCPIIP protocol is the Hyper-Text Transfer Protocol (HTTP), which is used to transfer World-WideWeb pages from a computer system. Such a computer system. If access control of individual web pages is required, the content of the agreement must be reviewed in order to decide which specific web page request is being requested. For a detailed discussion of firewalls, see and look forward to k and jade. Yarn front reference.
Although a properly implemented access filter operation prevents unauthorized access to data stored on the intranet via Internet III, it does not prevent unauthorized access via Internet III Information. This is prevented by the use of encrypted tunneling operations. This tunneling operation is deactivated; when the access filter 3107 (A) receives an IP packet from a computer system in the internal network 103 (A) with the target address in the internal network 103 (B) Information, it encrypts the IP subcontracting information, including its title; and adds a new title that states: use the IP address of the access filter 107 (A) as the source of the subcontracting information Address, and the access filter 107 (B) 0IP address is used as the target address. The new title may also include: authentication information identifying access filter 107 (A) as the source of encrypted subcontracting information; and access filter 107 (B) from which it can determine whether the encrypted subcontracting information has been intervened Information.
Because the original IP subcontracting information has been encrypted: when it is passing through the Internet 111, both the header and the content of the original IP subcontracting information are read in the same way, and the data of the header or the original IP subcontracting information It ca nt be without}; under Rll, the government was revised. "When it has accessed 107b-107 (B) to receive the IP subcontracting information, it uses any identifying information to determine whether the subcontracting information really comes from access filter 107 (A ), If it is, it will remove the header of the subcontracting information added by the access filter 107 (A), and decide whether the subcontracting information is predicted; if not, decrypt the subcontracting information (decrypt ), And perform an IP-level access check on the original title. If the title passes, the access filter 107 (B) forwards the subcontracting information to the internal network specified in the original title. IP address; or forwarded to a proxy server for protocol-level access control. The original IP subcontracting information is called tunneling through the Internet 111. In Figure 1, one such tunnel 112 is shown in Between two access filters 107 (A) Ia107 (B). An additional advantage of the Tao operation is that it will hide the structure of the internal network from those who have access to the information only from Internet Mills 111, because only unencrypted IP addresses are access filters. IP address.
The owner of the two internal networks 103 (A) and 103 (B) can also use tunneling operations together with the Internet 111; thus making the two internal networks 103 (A and B) a single virtual private network (VPN) 119 Through tunnel 112, computer systems on networks 103 (A) and 103 (B) can communicate with each other securely and are suitable for other computers; it seems that both networks 103 (A) and 103 (B) It is connected by a dedicated physical link (physicallink) rather than by the Internet lil. Indeed, it is possible to extend the virtual private network 119 to include any user who has access to Internet III information, and thus be able to perform the following items:
Encrypt the Internet subcontracting information addressed to one of the computer systems in the internal network 103 in a way that allows the access device 107 to decrypt the subcontracting information; add a header to the addressing to storage Fetch the subcontracted information of the filter 107; and authenticate the access filter 107 in person.
The police say that an employee who has a portable computer connected to the Internet and has the necessary encryption and authentication capabilities can use a virtual private network to securely retrieve one of many internal networks Information about a computer system on a network.
Once many intranets begin to use internet addressing operations and internet communication protocols, and are connected to the virtual private network; some browsers that have been developed for the internet can also be used on the intranet 103; and from the user's point of view, there is no difference between accessing data in the Internet 111 and accessing data in the intranet 103. As a result, intranet 103 has become an intranet, which is "an intranet with the same user interface as Internet III. Of course, once all intranets belonging to an entity have been When combined into a single virtual private enterprise intranet, access control problems that are characteristic of the Internet will occur again. At this time, except for internal access to data. Although the intranet is connected to the Internet 111 Many firewalls in this area are perfect enough to prevent outsiders from accessing data on the internal network, but they cannot prevent insiders from accessing the data. For example, it may be said that companies guard their personnel It's just as important to keep data from its employees as to prevent it from being affected by outsiders. At the same time, companies may want to make it easy for anyone with access to Internet 111 information: among many intranets 103 On one of the computer systems on a network, its World Wide Web site.
One solution to the many security issues caused by virtual private corporate intranets is to use firewalls to subdivide many intranets, and to protect the intranet from unauthorized access to information via the Internet influences. Modern access filters 107 are designed to protect the perimeter of the intranet from unauthorized access to information; and, in general, there is only one access per Internet connection If the filter 107p intends to use many access filters in the internal network, there will be more of them, so the virtual private network using multiple modern access filters 107 is not easy to scale. Scalability, that is: in a virtual private network with a small number of access filters, many access filters are not a serious burden: in a network with a large number of access filters, they are Is a burden. The access filter described in the section entitled "General Principles of Many Technologies Used in the Access Filter 203" before this patent application actually solves the scale of prior art access filters Scalability issues; thus, it becomes easier to build a network with a large number of access filters.
In the further operation of the access filter described in the first part of the application in this patent, it has become apparent that if the technology can be generalized, the storage in the access filter 203 is performed. Checking the many technologies developed should be more useful: if they can be used in a different context than the access filters that are operating at the IP level or the Internet protocol level, and if they can be extended; Enables decisions to be made not only for accessing information sets, but also for any actions that may be performed against an entity that can access information through a computer system; enabling groups of users to include the ability to perform an action through a computer system Any kind of entity acting; and enabling information sets to become resource sets, one of which is any entity that can be controlled via a computer system. It is further obvious that if the decision is allowed to include a temporal component, for example, a component that allows a group of users to access certain resources only during non-working hours, the decision should be more useful And, it should be useful to be able to correlate many attributes with a decision that describes how to execute the decision. For example, a decision may specify not only members of a known user group that have access to a known resource, but also the class of web service intended for the access operation "thus, One of the purposes of the present invention is to provide a technique for generalized access checking, and further provide a decision in which both time components and attributes may be related to the decision.
Summary of invention
The present invention achieves the foregoing objective by a decision execution system, in which the task of decision execution is shared between the following two components:
Including a decision server of a scalable decision database, and a policy enforcer, when the decision implementer receives a request from a first entity to perform an action against a second entity, the decision implementer The request is passed to the decision server: and only if a response from one of the decision servers indicates that the decision in the database allows the action, the action is allowed. The extensible decision database may be expanded to include many types of actions that are not performed by the decision executor. For this reason, the decision execution system can deal with many new action types by expanding the decision database to provide those types of decisions, and adding decision implementers for many types of actions. Indeed, as long as the action is controlled by a decision implementer in the computer system, the computer system need not perform the action.
Separating the decision evaluation from the decision execution, but also Coron makes: the decision execution system can easily handle decision execution at many different levels of the computer system to which the decision execution system belongs; and makes: the decision implementers are positioned away from the decision servo Device.
In another point of view, based on: the set of the first entity, the set of the second entity, and an action that an entity of the first set may perform against one of the entities of the second set; define many decisions in the decision execution system In one embodiment. In this embodiment, in addition to the action type, both the first entity type and the second entity type are extensible.
In this implementation, the action attribute may be attached to the set of the first entity or the set of the second entity, and the action attribute will decide how to execute the action that is the subject of the decision. For example, priority may be assigned to a set of users, or bandwidth may be assigned to a set of services. The decision database of this embodiment is expandable to include many new action attribute types.
In another aspect of the invention, conditions may be attached to decisions in a decision database of a decision execution system. Even when an action for a decision should be allowed in other sentiments, the action will not be allowed if the conditions attached to the decision are not fulfilled. One category of these conditions is time conditions. "For example, a decision that defines access to information may be made, and a time condition about one of the decisions may limit the validity of the decision to normal business hours.
Following the description and drawings below, other objects and advantages of the present invention related to the present invention will be apparent to those skilled in the art, among which:
The reference numbers in the various figures have at least three digits. The two rightmost numbers are reference numbers in the figure; the numbers to the left of those numbers are the figure numbers, in the figure: the item identified by the reference number appears first. Police. That is, in FIG. 2, the item with the reference number 203 appears first.
Narrate
2 elaboration
The next article will first provide: some easy-to-scale scalability access filters, how they can be used to control access operations on the gold intranet, and how they can be used to build virtual private networks The total cable. Therefore, the description will provide: an access control database used in access filters; ways to change it, and then distribute those changes across many access filters; and individual access filters to control access Details of the method used.
A network with access filters that do not hinder scalability;
figure 2
3A A network with access filters that do not hinder scale scalability: Figure 2 Figure 2 shows a virtual private network (VPN) 201, in which: access data is designed to avoid Access filters are controlled by access filters that cause problems. VPN201 is composed of four internal networks 103, and they are connected to each other through the Internet 121. "The VPN201 is also connected to the Internet through the Internet 121. A roamer 217 is a computer system. By users who may have access to the data on the corporate intranet 201, but will only connect to many intranets via the internet 121. Each intranet 103 has: many computer systems or belong to the user Terminal 209, and a number of servers 21l; the server contains: data that may be accessed by users at many computer systems or terminals 209, or by a user at intruder 217. However, the computer system or terminal 209, or the intruder 2 kg, is not directly connected to a server 211; instead, they are connected via an access filter 203, so that: All queries made by the user against data items on the server pass at least one access filter 203. Therefore, the user system 209 (1) is connected to the network 213 (1), which is Connect to storage Take the filter 203 (a) 'and the server 211 (1) is connected to the network 215 (1). This network is also connected to the access filter 3203 (x). The user system 209 (1) Any attempt made by a user at i) to access data on server 211 (i) will pass access filter 203 (a), where the user is not authorized to access the data, Will be rejected.
Since VPN 201 is of any size, it is said that there will be a considerable number of access filters 203; therefore, scaling problems will occur immediately. The access filter 203 avoids these problems because they are designed according to the following principles:
"Distributed access control database" Each access filter 203 has its own copy of the access control database used to control access to the data in VPN 201. Changes to be made in one of the copies of the database Spread to all other copies.
Distributed management. Any number of administrators may be entrusted with responsibility for the child collections of the system. All administrators may perform their work at the same time.
Distributed access control. The access control functions are performed at the near-end access filter 203. That said, the first access filter 203 in the path between the client and the server determines; whether the access operation is allowed; and many subsequent access filters in the path are not repeated by the first An access check performed by an access filter. End-to-end encryption takes place between the near-end access filter and the farthest possible encryption endpoint. This endpoint is not the information server itself, it is said that the far-end access filter 203 is the last one in the route from the client to the server. Dynamic tunnels are established based on current network routing conditions.
Adaptability plus WIQ4 !.}. Variable encryption levels and authentication requirements are applied to traffic passing through the VPN based on the sensitivity of the information being transmitted.
All these design ideas are discussed in more detail below.
It should be pointed out at this time that the access filter 203 may be constructed in any way, which guarantees that all inquiries on the data in VPN201 made by many users who may access the data without authorization will pass An access filter 203 In a preferred embodiment, the access filter 203 is constructed on a server and is installed on Windows NT. (New technology version of Windows software) manufactured by Microsoft Corporation. Operates under the operating system. In other embodiments, the access filter 203 may be constructed as a component of an operating system, and / or may be constructed in a router in the VPN 201.
Distributed decision database: Figure 3
3 Distributed Decision Database: Figure 3
Each access filter 203 has one of the access control databases 301 which copies all data related to the access control in the VPN 201. An access filter as shown in the access filter 203 (a) in FIG. 2 has a master copy 205 of an access control database 301. Because of this, the access filter 203 (a) is referred to as a master decision manager (MasterPolicyManager). The master copy 205 is the one that is used to initialize some new access filters 203 or replace the damaged access control database 301. The backup device of the master decision management computer is an access filter Fa203 (b). The backup copy 207 is a mirror image of the master copy 205. Finally, the report management program 209 includes software for generating reports; the reports are derived from information in the access control database 301, and from the access control data obtained from all other access filters. 203 Any copy of the library 301 may be changed by any user who must perform such an access operation; as will be described in more detail later, any such changes are first propagated to the master decision management program 205, and then To all other access filters 203 in the virtual private network 201.
FIG. 3 is a conceptual overview of the access control database 301. The main function of the database is to respond to an access request 309 from one of the access filters 203. The access filter uses an indication 311 of whether the request will be approved or denied. lJ If both are true, the request will be granted:
The user belongs to a user group, and the database 301 indicates that it is possible to access an information set to which the information resource belongs; and that the request has a trust level at least as high as the sensitivity level belonging to the information resource.
Each user belongs to one or more user groups, and each information resource belongs to one or more information sets: If none of the user groups to which the user belongs is denied access to the information resource An information set, and any user group to which the user belongs is allowed to access any information set to which the information resource belongs; the user may access the information resource if the request has the necessary level of trust.
The sensitivity level of a resource is only one of the values that indicates the level of trust required to access the resource. "In general, the more information resources need to be protected, the higher the sensitivity level. The requested trust level has many components:
The level of trust in the identification technology used to identify the user; the warning says that identifying a user with a token has a higher level of trust than identifying the user with an I1 'address.
The child of the path taken by the access request via the network; for example, a path that includes the Internet has a lower level of trust than a path that includes only some intranets.
If the access request is encrypted, the trust level of the encryption technology is used; the more stringent the encryption technology, the higher the trust level.
Consider the trust level of the identification technology and the trust level of the path separately. However, the trust level of a path may be affected by the trust level of the encryption technology used to encrypt the access request. If the request is encrypted using an encryption technology whose trust level is higher than the trust level of a part of the path, the trust level of part of the path is increased to the trust level of the encryption technology. Therefore, if the trust level of a part of the path is less than that required for the sensitivity level of the resource; the problem can be solved by encrypting the access request with an encryption technology street with the necessary trust level.
The information contained in database 301 may be divided into six categories:
User identification information 313, which identifies the user;
User group 315, which defines the group to which the user belongs;
Information resource 320, which defines individual information items that are protected and specifies where to find them;
Information set 321, which defines groups of information resources;
Trust level information 323, which will indicate the sensitivity level of information resources, and the trust level of user identification and network paths; and decision information 303, which will be defined according to the many objects of user groups detained in VPN201 Access rights.
The decision-making information is further divided into: access decision 307, management decision 305, and decision maker decision 306.
The access decision 307 defines the right of the user group to access the information set;
Management decision 305 will define the right of user groups to define / delete / modify many objects in VPN201. Among many objects: access decisions, information sets, user groups, location servers in VPN201, And services; and decision maker decision 306 defines the right of the user group to make access decisions to the information set.
Specify the user group decision-making are two parts of the tube in the management database 301 of the decision-buckle decision makers User Group administrator of. In VPN 201, administrative authority is delegated by defining the administrator group and the objects under their jurisdiction in the database 301. Of course, a given user may be a member of both the general user group 317 and the administrative user group 319.
User identification
3 user identification
The user group uses the user identification information 313 to identify their members. Identification information identifies its users through a set of extensible identification technologies. Currently, these identification technologies include "X.509 certificates, Windows NT domain identification, authentication tokens, and IP addresses / domain names. The type of identification technology used to identify a user determines the level of confidence in the identification.
Where string power is needed to identify users or other entities communicating with access filter 203, VPN201 says that it will use "" Internet communications developed by SunMicrosystem, Inc. " "SimpleKeyManagementforInternetProtocols (SKIP)" communication protocol. This communication protocol manages public key exchange, key authentication, and session encryption. By a method from the parties that are exchanging data, Transport keys generated from public and private keys are used to perform session encryption. The public key is included in the X.509 certificate, which is used in a certificate called "CertificateDiscoveryProtocol" (Referred to as CDP), which is a separate communication protocol exchanged between SKIP parties: In addition to encrypted messages, a message encrypted using SKIP includes: an encrypted transmission key for one of the messages, and the source and The identifier of the target's certificate. The recipient of the message uses the identifier of the certificate of the source of the message to indicate the identity of the source. Use the location of the key; use its key and the public key of the source to decrypt the transmission key; and then use the transmission key to decrypt the message. SKIP messages are self-authenticating from a certain In a sense, it contains an authentication title that includes a cryptographic digest of the subcontracted information content, and any kind of modification will make the abstract incorrect. For details about SKIP, see 1Check the article "Simple Key Management (SKIP) for Internet Protocol" published by Ashar Aziz and Martin Patterson, which can be accessed online .: February 28, 1998 The address is http: /Iwww.skip.orglinet-95.html. For details about the X.509 certificate, please refer to the description available on the Internet: September 2q, 1997, and the website address is http: / Iwww. rnbo.comIPROD / rmadillo / plpdoc2.htm.
In VPN201, SKIP will also be used by many access filters 203 to identify themselves and other access filters 203 in the VPN; and then to encrypt TCPIIP conversations where encryption is needed. Many access filters 203 can also use certificates against SKIP keys to identify users when they are performing access checks. Such an identification method is particularly trustworthy and therefore has a fairly high level of trust. One of the uses of this identification method by certificate is: a trusted identification method for the "overrunner" 217. X.509 certificates can be used for user identification because "they associate key information with information about users.
The access filter 203 uses the following information fields from the certificate:
Expiration date: After this date, the certificate is invalid.
Public key: A public half-pair key that uses a public-private key pair as it is used in SKIP-based cryptography used by Conclave.
Certificate Authority (CertificateAuthority) signature: a distinguished name associated with the authority that issued the certificate.
Certificate serial number.
Subject name: The name of the entity to which the certificate was issued.
The subject name includes the following subfields (the words in parentheses are the general abbreviations for the fields):
Common Name (CN): The established name of the subject, such as JohnQ.Publ; c.
Country (C): The country where the subject is located. The country codes are two-letter codes specified in the X.509 specification.
Place of deposit (L): The location of the subject. This field is usually the city where the subject is located, but any location-related values may be used.
Organization (O): The group to which the subject belongs. This field is usually the name of the organization.
Organizational Unit (OU): The organizational unit of the subject. This field is usually the main body's department. For example, "business department" and "X.509 certificate" allow up to four of these fields to exist.
The certificate authority used with many access filters 203 will issue certificates with all of these fields. Also, four OU fields may be used to define additional classifications. The information used to describe the user in the certificate can be used by the administrator of the database 301, which is used when defining the user group. If the information in the certificate correctly reflects the organizational structure of the industry; the certificate will not only Identifies users, and shows where the users are suitable for the enterprise organization; to the extent that the user groups in the database 301 reflect "organizational structure, user groups to which users belong."
As will be explained in more detail later, one way in which membership in many user groups may be defined is through the use of "certificate matching criteria", which defines members who belong to a given user group The value of the field that the certificate must have. Certificate matching criteria may be based on as few or as many of the above fields as required. The police say that the certificate matching for the engineering user group may be the "organization field and the organizational unit field specifying the engineering department. Other information identifying users may also be used to define members of many user groups .
Information Set
3 information set
An information set holds information about many individual information sources. A resource may be as small as a WWW (World Wide Web) web page or newsgroup, but it is most often made up of the "Webdirectorytree" and its contents, FTP accounts, or the main Usenet ( (New open network) news category is composed of "in one of the many servers in Figure 2, there are two information sets" 219 (j) and (k) although the administrator of the access control database 301 should completely decide : What kind of information is included in an information set: However, the information in a given set is usually: information related to both the subject and the intended audience (audience). An example of a company's information set may be: HRpolicies (HR decision), HRPersonnelRecords (HR personnel records), and PublicInformation (public information).
Access Decision 307
3 Access Decision 307
Conceptually, the access decision 307 consists of a simple statement in the following format: Engineersallowedaccessto Engineers are allowed to access engineeringdata Engineering data Internetallowedaccessto Internet is allowed to access publicwebsite
The first column contains the user group; the bottom column contains the information set. The middle column is the access decision-allow or deny.
The database 301 allows hierarchical definition of user groups and information sets. As mentioned, the engineer user group may be defined to include: hardware engineer user groups, physical engineer user groups, and Sales engineer user group. Similarly, engineering data information sets may be defined to include: hardware engineering data information sets, software engineering data information sets, and sales engineering data information sets. Within the hierarchy of user groups, access is granted by inheritance. Therefore, for access verification, a user belonging to one of the hardware engineer user groups will also automatically belong to the engineer user group. At the level of the information set, access is also obtained by inheritance. For access verification, information resources that belong to one of the hardware engineering data information sets will also automatically belong to the engineering data information set. Therefore, if there is an access decision that gives engineers access to engineering data, any user who is a member of one of the three user groups that make up the engineer may access: belonging to the constituent engineering data Any of the three information sets of any of the information sources. Using inheritance in the definition of the user group deduction information set will greatly reduce the number of access decisions 307 required in the access control database 301. For example, in the above example, a single access decision pillow allows all engineers to access all engineering data. Inheritance rights also make it possible to define all access decisions in terms of allowed access operations. Continuing the above example, if there is a "Salespeople" user group that does not belong to the "engineer", but there is an access decision that gives the user group access to sales engineering data: it becomes "sales" Users will be able to access sales engineering data, but not educational or hardware engineering data.
Of course, a user may belong to more than one user group, and an information resource may belong to more than one information set. There may also be different access decisions for various user groups to which a user belongs and various information sets to which an information resource belongs. When faced with multiple access decisions that apply to both the user and the information resource that the user is trying to access, the access filter 203 applies the decision in a restrictive, not permissive way:
If multiple decisions allow or deny a user group access to an information set, the decision to deny the access operation is dominant.
If a particular user is a member of a multi-user group and multiple decisions allow or deny access to the information set; the decision to deny access is dominant.
Which user group a user belongs to may change depending on the recognition mode used to identify the user. Therefore, if according to the recognition mode that the user has provided to the access filter 203 up to that time, no access decision is applicable to the user groups to which the user belongs; then the access filter 203 may obtain additional identification Information and decides whether the additional identifying information places the user in one of the user groups for which a decision about the resource is made. Accessing the device 203 may obtain additional identifying information if:
The user has installed User Identification Client Software (UIC) (a software that runs on a user's machine and provides identification information about the user to the access filter 203).
UIC is currently running on user machines.
The user has caused his UIC to pop up (POP-UP) for further identification (the user has a checkbox that enables this feature).
If all these requirements are true, the access filter 203 will force the user's UIC to pop up and request additional identification information. Store any identifying information provided by the user. After each new piece of user identification information, the access filter 203 performs the same evaluation process: until it is obtained that the user is placed in one of the user groups targeted for a decision to allow or deny access Until the user gives up their request, or pop up the UIC window.
Management Decisions 305
3 Management Decisions 305
Management decision 305 will implement the management of many objects in the access control system of VPN201. "Included in the objects are: user groups, information sets, access decisions, and available resources (available resources) ) 'That is "services, servers, access controllers, and the network hardware that makes up VPN201. Objects are managed by one or more administrative user groups. A member of the management user group who manages a given object may govern that object and its relationship to other objects and may make management decisions for that object. As will be explained in more detail later, the fact that a member of the management user group who manages an object may make management decisions about the object makes it possible for the member to delegate object management rights. As the police say, a member of the administrative user group that manages the "hardware engineer" user group may create an "one that grants" hardware engineer "management rights to the" hardware manager "user group Management decisions to delegate "hardware engineers" and management rights to "hardware engineering administrators". It should be noted that the right to manage information sets is separate from the right to make access decisions to information sets. The fact that a user group has the right to make access decisions about an information set does not give the user group the right to make management decisions about the information set; and vice versa. When an access E & t203 is first established, a single built-in security officer user group has: the administrative authority that governs all objects in VPN 201 and the decision 306 of decision makers.
With management decision inheritance
3. With inheritance of management decisions
Inheritance rights work with management decisions, the same way is: inheritance rights work with access decisions. Organize many user groups, information sets, and available resources referred to in management decisions into layers. "A user group within a user group is a subset of a given user group: The hierarchy of many user groups in a given user group goes down to the next level. The same is true for information sets. In the same way as for access decisions, inheritance is applied within the hierarchy. So In the user group level, the management user who controls one of the user groups will also control all the subsidiary including some user groups. "Similarly, regarding the information set level, One administrative user who governs an information set also governs all its affiliates, including one information set; and one administrative user who governs management decisions for an information set also governs access decisions for all included information sets .
There is also a natural hierarchy of available resources. As the police say, one level of the hierarchy is: "in a given location, many servers at that location form the next level down; and in a server, many services provided by the server The next level is formed. A group of administrative users with jurisdiction at any level of the available resource tree will also govern the lower levels used. As stated, management decisions confer jurisdiction over access filter 203 (many ) The administrator has the management right to: all servers under the website, all services running on those servers, and all resources supported by those services.
Delegate authority: Figure 25
3 delegated authority: Figure 25
In VPN201, it is easy to delegate permissions, because: members of the management user group of the management object may modify the object and make management decisions for it. For example, if an administrative user group manages an information set: it can divide the information set into two sub-sets and make some new management decisions that are given to each of the two other user groups. This group governs the management rights of one of the two subsets.
Figure 25 shows an augmented example of delegated authority. In Figure 25, user groups and other objects are represented by circles; decision makers' decisions are represented by squares; and decision relationships are represented by different types of arrows: solid arrows represent management decisions, and dotted arrows represent decision systems. Decisions, and dashed arrows represent access decisions. A part of the drawing labeled 2501 shows what happens when the access filter 203 is being built: built-in. The "security officer" group of users 2503 has administrative authority over all built-in objects 2505 and the decision maker decision 2507. Members of the "security officer" user group 2503 will use their administrative authority in order to: Gather, rearrange object levels, and establish decision maker decision 2507.
In the copy of Figure 25 marked 2508, it can be seen that: a result of the activity of the "security officer" user group 2503. A member of the "security officer" user group 2503 has been established:-"Project management" "Administrator user group 2509, an" engineer "user group 2511, and an" engineering data "information set 2513; and has been given" engineer administrator "jurisdiction over" engineer "and" engineering "data management rights. Members of the "security officer" have also established a decision maker decision 2507, which gives the "project manager" the right to make access decisions for "engineering data," as indicated by the dotted arrow 2510. A member of the "Engineering Administrator" has used this right to make an access decision to 'allow members of the Engineer 2511 to access the information in the' Engineering Materials' 2513, as indicated by the dashed arrow 2512. "So, the" security officer " The members have delegated the management engineer 2511, the engineering data 2513, and the management authority to access the engineering data to the engineering manager 2509.
Of course, the security officer 2503 still has administrative authority over the project administrator 2509; therefore, this authority can be used for further delegation of authority. An example is shown at 2517. One of the members of the "security officer" 2503 has divided "engineering administrators" into two sub-collections: "Engineering Personnel Administrators" (EPA) 251MQ "Engineering Data Administrators" (EDA) 2521. The members of these sub-collections are inherited from the project manager 2509 and have the management rights of "engineer" 2511 and "engineering materials" 2513. The members of EPA2519 and EDA2521 will use these management rights to manage the management authority of 11 engineers "2511 Entrusted to "Engineer Manager" 2519, and delegated management authority over "Engineering Materials" 2513 to "Engineering Materials Manager" 2521. Members of EPA 2519 and EDA 2521 have further used their rights to formulate storage for "Engineering Materials" 2513. Take a decision to change the access decision, so that: The access decision for "project data" is made by the "project manager" 2521, as shown by the dotted line arrow 2523, rather than the "project manager" 2509 , By which the function is entrusted to the "Project Data Manager" 2521.
Now, engineering administrators and members of engineering data administrators can use their jurisdiction to engineer, engineering data, and management rights for engineering data access decisions to refine access to engineering data. For example, a member of the "engineer manager" may subdivide "engineer" into: "software engineer" deducted "hardware engineer"; and a member of the "engineering data manager" may subdivide "engineering data" into : "" Hardware engineering data "and" software engineering data ". In doing so, a member of the" engineering data manager "may give the" software engineer "access to the" software engineering data "and give it to the" hardware engineer " The "access to" engineering data "access decision replaces the access decision to" engineer "access to" engineering data ".
In short, it can be said that many administrators who have jurisdiction over a user group are responsible for the membership defined correctly in the user group; they may delegate any part of this responsibility To other administrators. Similarly, many administrators who have jurisdiction over an information set are responsible for properly including information resources in the information set; they may delegate any part of this responsibility to other administrators. The latter's administrator must of course also be an administrator for an available resource, from which it is possible to obtain: the information being added to the information set. Administrators of available resources are responsible for overall network and security operations. As such, they may entrust their responsibilities. In the end, the decision maker administrator has the final jurisdiction that governs access to the information. They may independently make access decisions related to a particular set of information. In a sense, the decision maker decides the overall information sharing decision for the enterprise. The administrator for the user group, information set, and available resources then decides the construction details.
Access control using many access controllers 203 and database 301: Figure 4
2Access control using many access filters 203 and database 301: Figure 4
As shown in FIG. 2, the access filter 203 has a position in the VPN 201, and it is placed between the client computer from which the user is requesting access to the information resource and the server on which the information resource is stored "then, By interceding in the communication between a user and a service on the server that can provide the user with access to information resources, the access filter 203 is sufficient to control access to resources by the user. To provide users with access to information resources, a dialogue must be established between users and services. In the current context, the term "dialogue" is broadly defined to include some well-behaved connectionless communication protocols ( connectionlessprotocols) When the access filter 203 finds that the user is trying to start a conversation with a service, it determines whether the access operation should be allowed. This is done based on: the user's known identity; the information is being accessed Information resources; information sensitivity levels; and user identification methods, paths between users and services, and the level of trust in any encryption technology used.
Figure 4 shows how a conversation can involve more than one access filter 203. The dialog 402 shown in FIG. 4 relates to the five access filters 203 (1, 2) in the figure. The access filters 203 are all designed so that only one of the many access filters 203 is needed. An access filter makes decisions about whether to allow users to access information resources. The key to this feature of many access filters 203 is their ability to authenticate themselves to each other. SKIP was used to do this Each access filter 203 has: an X.509 certificate in the database that combines the key of the access filter 203 with the name of the access filter and is signed by the certificate authority of the VPN In 301, each access filter has: the name and IP address of all other access filters in VPN201: and, once a conversation encrypted with SKIP arrives, each access filter uses From the discussion in SKIP. The "SubjectName" of the certificate mentioned above determines whether the traffic using SKIP-encrypted traffic is coming from another access filter 203 in VPN201 .
If the conversation being received by the access device is not the target of the conversation (then -A, the access filter only performs the function of an IP router along one of the paths), the access device will only start from The target IP address verified in the database 301 is the IP address of some other access filter 203 in the VPN 201. If this is the case, the dialogue is allowed to pass without additional checks. When the request comes to the last access filter 203, the last access filter 203 decrypts the request using SKIP in order to confirm that the request is indeed checked by the first access filter 203, and then confirms that: the request It has not been modified during the transfer.
Therefore, in FIG. 4, the access filter 403 (1) uses a copy of its own access control database 301 to determine whether the user who initiated the conversation has accessed the information resource specified for the conversation. If the access filter 403 (1) is so determined; it will identify some of the output messages of the conversation and encrypt them if necessary to achieve an appropriate level of trust. Then, access filters such as 4032, ..., 5 will allow the conversation to continue. This is because the conversation came from the access server 403 (1) and has been encrypted with SKIP: they will neither use themselves A copy of the access control database 301 is used to decrypt the message and does not check the message. Then, the access filter 403 (decrypts the message and confirms that they are all encrypted and therefore are checked by the access filter B403 (i): and if the messages are intact, they are forwarded to Many of the messages in the conversation between the server 407 and the user system 401 containing the required resources are processed in the same way: if necessary, they are encrypted using the access filter 403 (5) " The access filters 403 (2, ..., 4) pass them based on the authentication performed by the access filter 403 (5); and the access filters 403 (1) to The message is passed to the system 401, and if necessary, the message is decrypted.
What this technique effectively performs is: opening and closing a tunnel 405 for the dialogue between the access filter 403 (1) and the access filter 403 (5); because of the tunnel, there is only the access closest to the client Filter 403 only needs to be executed: decryption, access check, and re-encryption. Moreover, tunnels are equally secure in many intranets and in the Internet 121. In a large VPN, the access rate 403 (1) is in the best position to check the access operation because it has access to the most detailed information about the user who initiated the conversation. The technology of access check performed at the first access filter 401 will further distribute access control responsibilities around the VPN, thus allowing the VPN to scale to any size.
End-to-end encryption: Figure 5
3 end-to-end encryption: Figure 5
The tunnel in Figure 4 only extends from the access filter 403 (1) to the access filter 403 (5); the message of the dialog is not between the system 401 used by the user and the access filter 403 (1). Encryption is not encrypted between the access filter 403 (5) and the server 407. In the case of extremely sensitive information, from the near-end access filter to the end of the path through the network, that is, between the system 403 (1) and the server 407, authentication and encryption may be required.
Figure 5 shows how to use some access filters 203 to achieve this. In addition to some access filters 203, it may be used with any client system 401 or 503, or any server system 407 using authentication and Encryption technology "When a client computer uses encryption technology, it uses SKIP to authenticate the conversation and uses a shared secret (shared secret) shared between the client computer and a selected access filter 203. The conversation is encrypted, and then the encrypted message is sent to the selected translation access filter 203; thereby effectively establishing a tunnel between the capacity client and the selected access filter 203, thereby making the selected translation access filter The first access filter 203 can be used for access verification. At the first access filter 203, the message is decrypted and the access verification is performed. Since SKIP enables the user's certificate to encrypt the encrypted message, For use, so the user s authenticated identity can be used for access verification. If the access operation is allowed; the message is encrypted again and sent to the access filter 403 (5) closest to the server 407, which Will If the database 301 contains a SKIP name and algorithm for server 407: if necessary, the access filter 403 (5) retrieves the certificate for server 407 and uses SKIP in order to If necessary, re-encrypt the conversation for server 407. In other cases, access server 403 (5) simply sends the message to server 407 in the clear. If it is server 407, the message is re-encrypted. , The server 407 will finally receive the encrypted message and decrypt it. Some of the access filters 203 that are in the middle of the first access filter 203 and the last access filter 203 just notice that the message comes from another An access filter and use SKIP to encrypt and pass the message, as described above. When the server 407 retrieves the information resource, it sends it to the access filter 403 (5) in clear or by using The key of the access filter 403 (5) is used to encrypt the message containing the resource. Then, the above-mentioned decryption and encryption processes are performed in pairs in reverse order: from the server 407 to the access filter 403 (uniform; Access filter 403 (filter 403 to an access homogenizer (1); and finally accessed from the filter 403 (1) to the original client system 401, it will be decrypted message.
The effect of this technique is to build a tunnel on the path between the client and the server, the tunnel extending from the access filter 203 on the path closest to the client to the storage on the path closest to the server Take the filter 203. If the client can encrypt and decrypt, the tunnel can extend from the access server closest to the client to the client; and if the servo Vvd can encrypt and decrypt, the tunnel can similarly go from the closest server. 'S accessor extends to the server. Once the first access filter 203 in the path has been reached and the conversation has been authenticated, no further encryption or decryption is required until the access pass closest to the server 203 has been reached. Moreover, the access control database 301 in each access filter 203 will contain all the necessary identifications and authentications for: the client, server, and many access filters 203 in the routing ( certification) information. One of the advantages of the end-to-end encryption technology described by A'1 is that instead of focusing on the many access filters used to connect the VPN to the Internet, it is better to distribute the encryption burden across the network to enhance scalability Sex.
FIG. 5 shows how the technology works with the conversation 501, which is initiated with the diffuser. The pillow is: the client 503 connects to the VPN via the Internet 121. The rover 503 is equipped with SKIP, just like the target server 407 on an intranet. When SKIP is configured in the diffuser, a certificate for the accessor 403 (3) is assigned to the diffuser, and a certificate for the roamer is assigned to the access filter 403 (3). When Man 503 sends a message that belongs to a conversation, it will address the message to server 407 and use it with the access filter 403 (sharing it. Send the key to encrypt the message, so, The message is tunneled to the access filter 403 (3) via the tunnel 505. There, the access filter 3403 (3) decrypts the conversation, performs an access check, and then uses the access filter 403 (The key is transmitted uniformly to re-encrypt the conversation. Many subsequent access filters 403 in the path allow the conversation to pass because: the conversation is authenticated by access filtering 403 (3) "then, at least A tunnel 507 is provided to the access filter 403 (5). If the target server 407 is equipped with SKIP, the access filter 403 (the child will extend the tunnel to the target server 407 as described above).
Adaptability encryption and authentication based on data sensitivity: Figures 6 and 7
3 Adaptability encryption and identification based on data sensitivity: Figures 6 and 7
In VPN, an important work in access control is: determine the minimum amount of security required for a conversation ". This is very important, first because: at least the minimum amount must be guaranteed; second because: Needing more security will waste resources. Many technologies used in the access filter 203 to determine the minimum are collectively referred to as SecureEncryptedNetworkDelivery (SEND). In SEND, access control The database 301 contains a data sensitivity level for each information resource. The data sensitivity level indicates the level of security associated with the information resource and is assigned to the information resource by a security administrator responsible for the resource. Many One exemplary set of levels is: TopSecret, Secret, Private, and Public.
The levels used to indicate data sensitivity are also used to indicate the level of trust required for access requests. As described above, access to naked work is allowed only if the trust level determined from the following trust levels is at least as large as the data sensitivity level of the information; the trust levels are: technology used to identify the user The trust level of the access level of the request through VPN201 or any encryption technology used to encrypt the message sent on the path. Aiming at: user identification method, path, and the trust level of the encryption algorithm are included in the access control database 301. Regarding the trust level of the path, the VPN is divided into network components, and each network component is a number of TPs. A collection of connections in a network, separated from other components by an access filter 203. Each network component has a name and a level of trust. The police say that an Internet component will have a "public" trust level, while an internal network component may have a "private" trust level. A given component's trust level may be based on its physical security, or Based on the use of cryptographic hardware in the component. Because each access filter 203 is added to the VPN, a description of its connection to the components of the VPN is added to the database 301. Included in this description are: the trust levels of many networks. Therefore, any access filter 203 can use a copy of its database 301 to determine the trust level of each component of the path; and between a client and a server, it will be carried by the path A conversation.
The user's trust level is determined from the way the access request identifies the user. In the access control database 301, each user group has one or more identification technology streets associated with it, and each identification technology has a minimum level of trust. Many basic technologies are:
Certificated by SKIP. Users are identified by their name in their X.509 certificate, which is used with the SKIP protocol to authenticate and encrypt traffic.
A certificate identifying the user's software by the user. The user is identified by the name in his X.509 certificate, which is transmitted to some affiliate access via a special Conclave user software module called the user identification client. Filter 203. This transmission is done securely using a password / response mechanism.
The WindowsDomainID (Windows Domain Identifier) of the II software is identified by the user. A user who is registered with Microsoft Windows Domain and has installed user identification client software automatically has his Windows identity, including group membership, and is passed to some auxiliary access filters 203. In the mechanism of the NetBIOS (Network Basic Input / Output System) protocol, network logon is done securely.
Authentication token. It is possible to use authentication tokens in the following two ways (Zhu Ru "; those tokens manufactured by Guidance's Kft2} company (SecurityDynamics Inc.) fu-rsheng company (AxentCorp.)" In a manner outside the frequency band: or in a Telnet (Long Range Communication Network faFTP (File Transfer Protocol) communication protocol, in a manner within the frequency band.
IP address and / or domain name. The IP address or fully qualified domain name of the user s computer.
In a preferred construction example of SEND, many identification technologies have a predetermined order from highest security to lowest security. The poem-tech streets just listed should be sorted, as they are in the list above: the most secure technologies are at the top of the list. Although the ordering of the identification technology is somewhat subjective, it reflects: the general security of the identification technology, and the rigor of the distribution and confirmation applied to the identity of the user. The administrator in VPN201 will then Ordered trust levels are related to ordered identification techniques. For example, if the administrator associates the "private" "reliability level" with the identification technology using authentication tokens, users who want to access a resource with one of the "private" sensitivity levels must identify themselves by : An identification token, or another identification technology that is higher in the order of identification technologies. The administrator of the access filter will likewise: the many password algorithms that will be available in the VPN, from the highest security to the lowest security. Sort the order; make the order trust level related to the order password algorithm; arrange the fJ order of many network paths used in VPN201; and make the order trust level related to the order network path. These relationships between the level of trust and the order of security are included in the access control database 301. Then, a SEND table is constructed with a level of trust and sensitivity related to the identification and encryption technology. Figure 6: A conceptual representation of such a SEND table.
The SEND table 601 has three columns: one column is 603 indicating the trust / sensitivity level, one column is 605 indicating the minimum encryption method, and one column is 607-, it details the encryption methods of column 605. For details, please refer to the book "" Application Code Street "by Bruce Schneier, written by Zhu Zhusheng. Printed by John Wiley & Sons Book Company Finishing, 1994 edition. Each J609 in the table associates the trust / sensitivity level with the minimum encryption level of the path connected to the access filter, the client, and the server and the minimum identification level of the user. By 609 (1), the "top secret" trust / sensitivity level is related to the 3DES encryption algorithm and the user certificate obtained via SKIP. Users who want to gain access to a resource with a sensitivity level of "Top Secret" must have an identification level certified by SKIP: and if the path does not have "Top Secret" trust level, 3DES encryption must be used The algorithm encrypts the conversation. On the other hand, as shown to 609 (4), a user who wishes to gain access to a resource with a sensitivity level of "" public "may be identified by any method, and therefore it is not necessary to encrypt the conversation.
When a new conversation is started, the first access filter 203 in the path used for the conversation continues as follows:
1. The access filter 203 determines the information resource being accessed; and looks up its sensitivity level in the database 301. According to the SEND table 601, the minimum authentication method for this sensitivity level will state: "Some identification mechanisms may be used by access filters to identify and authenticate users performing access operations.
The first access filter 203 then consults the consults database 301 to determine whether the user can access the resource according to the user group to which the user belongs and the information set to which the resource belongs.
The first step is to decide according to the access control database: Of the many identification methods used to identify users, these methods have a trust level that is sufficiently high for the sensitivity level of the resource.
Then, the first access filter 203 uses the identification information of the user to search the database 301 according to each identification method having a sufficiently high trust level, so as to determine: the user group to which the user belongs.
The first access filter 203 also searches the valve database 301 to determine which information set the resource belongs to.
Having determined the relevant user groups and information sets, the first access filter 203 searches the database 301 in order to indicate the location of some access decisions, the decision decision; whether it intends to allow or deny access to the conversation information . The user is allowed to access the operation if he is aware of at least one decision to allow the access operation and the decision not to deny the access operation; otherwise, the access operation is denied. The details of steps b, c & d are described below.
4. If the access operation is not denied, the first access filter 203 will then search the database 301 in order to determine some network components that constitute the route. The route is: from the client computer to the server that contains the information resources via the VPN. server.
Considering routing should be a series of up to three logical segments:
1. Segment (a), from client to first access filter 203. This segment may or may not be encrypted, depending on whether the client computer uses SKIP.
2. Segment (b), from the first access filter 203 to the access filter 203 closest to the servo a17} in the path; and.
3. Segment (c), the access filter RP203 from the server closest to the server; this segment may or may not be encrypted.
If segments (a) and (c) exist, each segment will consist of a single network component. If the client is on the first access filter, then segment (a) 9 does not exist; if the server is on the access filter closest to the server, then segment (.) Will not exist. If segment (b) exists, it will consist of one or more network components. If there is only one access filter E- between the client and the server, then segment (b) will not exist.
For each segment:
4. For segment (a), any encryption method must be performed by the client, if the trust level of segment (a) is not at least as strong as the sensitivity of the data of the resource; or, if the The level of trust in the encryption method is at least not as strong as the data sensitivity of the resource; access is denied.
5. In terms of segment (b), if the weakest trust level of any network component in the path is greater than or equal to the data sensitivity of the resource, the traffic is sent without encryption. This corresponds to the situation where the network is sufficiently secure to transmit data. In the example in the table above, an information resource with a "public" data sensitivity level may be transmitted on any network, as shown in column 609 (4). However, many access filters 203 will use SKIP to authenticate the conversation, thus allowing many subsequent access filters to pass the conversation without incurring: larger overheads of decryption, access check, and re-encryption. If the weakest trust level for the path is less than the data sensitivity of the resource, the SEND table is opened for the minimum encryption algorithm required for the sensitivity level, and the dialog is then encrypted using the algorithm. Encryption upgrades the security of the communication link, making it suitable for carrying the data of the given sensitivity, while allowing the user to access the resource.
6. As far as segment (c) is concerned, the path from the access filter 203 closest to the server to the server, the first access filter 203 is determined based on the information in the database 301, segmented (. ) And the trust level of any encryption method used in the segment (.). If the trust level of this segment of the path is less than the sensitivity level of the information resource, and in that case, if the trust level of the encryption method used in segment (C) is not at least as strong as the required level, the The required level is like the minimum level in the SEND table considering the sensitivity level of the information resource; the first access time 203 will deny the access operation.
The above method for determining the sensitivity and the trust level guarantees that the access filter 203 uses the encryption method only when it is necessary to reach the necessary trust level. While keeping the description of the network configuration in the database 301 simple and manageable, this method reduces the number of conversations to be encrypted. The result: With regard to management and efficiency in VPNs, there will be better scalability at scale.
Figure 7 provides an example of how the sensitivity level of the information resource, the trust level of the user identification method, and the trust level associated with the path between the client and the server affect the access to the information resource by the user. In FIG. 7, a user equipped with SKIP at the client end 703 initiates a conversation 701 in order to obtain one of the information resources 723 stored in the server 705 equipped with SKIP. Segment 723 discussed above (a) Appears at 707 in Figure 7; segment (b) appears at 709 (1, 2 ,, 4); segment (c) appears at 711. The information resource 723 has a sensitivity level of "confidential". The first access filter 203 encountered by this conversation is the access filter 203 (1). The access filter 203 (1) uses the copy of its access control database to determine the sensitivity level of the resource 723. Here, the user has used the SKIP certificate, and the SEND table 601 in the viewing database 301 displays the access filter 3203 (l); because this user identification method meets the requirements of information resources with "confidential" sensitivity level , So segment (a) at 707 has the required level of trust. For this reason, the first access filter continues to determine: in AVPN, the segment (b) and the position between the access filter 203 (l) and the server 705 at 709 (1, 2, 4) Trust level of ft (C) at 711 points. Segment 709 has some sub-segments "709 (1), 709 (2), 709 (3), 709 (4), and 709 (5); and the first access filter 203 (1) checks the data The trust level of each of the sub-segments in these molecular segments in library 301. Segment 709 (2) is Internet 121, so its trust level is: "Public", which is the lowest level in segment 709 The access filter 203 (1) then uses the access control database 301 to check the trust level of the segment 711. Its trust level is "confidential". Therefore, the segment (b) at 709 has only one Too low a trust level for the path that is accessing one of the "confidential" information resources 703. To deal with this, the access filter 203 (l) must encrypt the conversation in order to elevate it to The necessary level of trust. The first access filter 203 (1) queries the SEND table 601 to determine what encryption method is required, while 609 (2) indicates that the DES encryption method is sufficient. Therefore, the first access The filter 203 (l) uses the algorithm to encrypt the conversation, and then sends it
In FIG. 7, the segment 707 connecting the client 703 to the storage. Fetch filter 203 (1) has a trust level that is high enough for the sensitivity level of the resource, so the client 703 does not have to ask for it. encryption. When this is not the case, the access filter 203 (1) will only be assigned if the client computer 703 has used an encryption method that is sufficient for its trustworthy level of spiritual respect and enthusiasm to encrypt the request. Capacitor 703 poisoned fetch operation. For this reason, the intruder 503 in FIG. 5 must be equipped with SKIP. Since the trespasser 503 accesses via the Internet 121: access to the information of the filter 403 (3); many requests from the trespasser 503 may never have a higher trust level than "public" unless they are added Encryption; and in order to fully access the resources in VPN 201, the roamer 503 must use an encryption method, such as a method provided by SKIP, whose trust level is sufficient for the highest sensitivity level. In some embodiments of the access filter 203, the access filter may negotiate with the client to use the encryption in the request in a manner similar to that used in the preferred embodiment to negotiate the user identification mode technology.
Overview of the administrator interface for the access control database 301: Figures 8 to 123 Overview of the administrator interface for the access control database 301: Figures 8 to 12 Access decisions define storage based on user groups and information sets Fetch operations; therefore, before it is possible to define access decisions, the administrator must define user groups and information sets; how this is done is shown in Figure 8. Defining a user group involves steps 803 to 807: first define the user, then define the user group, and then assign the user to the appropriate user group. "Defining the information set involves steps 809 to 813: first define the resource , Then define the information set, and then assign resources to the information set. When this has been done for the user group involved in a decision, the access decision can be established, as at 815 As noted earlier, although the right to make access decisions for many user groups and information sets is determined by the decision maker's decision; it is used to define and determine the membership and The collection of information, and the right to make management decisions for them, are determined by management decisions.
As can be seen from the foregoing, user interfaces are often used to define the relationship between two entities or collections about them. The general form of the graphical user interface (GUI) for the access control database 301 corresponds to this task. The display diagram includes two windows, each of which contains a representation of some entities intended to be related to each other, and the relationship is defined by selecting the entity and where it is needed to define the relationship.
Define user groups: Figure 9
3Define user groups: Figure 9
FIG. 9 shows: a display diagram for populating and defining a user group. A view 903 in the display diagram 903 contains one of the currently defined user groups. A layered display diagram: a window 903 and those for displaying The file level windows in the Windows 95 trademarked operating system manufactured by Microsoft Corporation are similar. In the window 903, many user groups for which the management user using the display 901 has management rights are shown in black; other user groups are shown in gray. Above the two windows are two buttonbars. "911IR915 Buttonbars 911 are listed: Some of the available displays used to modify the access control database 301, while the buttonbar 915 is' 11T: Maybe in those Some operations performed on the display map, so the button labeled "user group" in the button strip 911 is highlighted, thus indicating: the display map 901 is a display map used to colonize and define the user group . Regarding the button band 915, when the window 903 is in an active state, one of the users having the right to manage a user group may modify the user group. The method is: select the user group in the window 903 and select Use the "delete" button in the button strip 915 to delete the user group: Or, use the "new" button to add and name the selected user group in the hierarchy The next new user group. When the management user clicks (clicks): "Apply" button 921, the access filter 203 will modify its copy of the access control database 301 to confirm what kind of bundle is on the display 901; And the modification information is transmitted to: a copy of all the access control database 301 in the VPN.
Window 909 displays the user. By identifying the users in the collection, one of the collections is indicated in the display. In this case, users are identified by the IP address, and they all appear in the display with the range of the IP address. The button 913 indicates: another type of identification method that can be displayed in the window 909. Just like using the window 903, when the window is currently in use, two buttons, "Add" and "Delete", can be used to add and delete users. To assign the (many) users specified by the user identification information to a user group, the use of the GUI can choose: a user group, as shown at 917, and a collection of identification information, As shown at 919; then use the "addtogroup" button in button Ia 913 to add the set of identification information to the user group, as shown by the following facts That's it: The range of selected IP addresses at 919 now appears in the hierarchy below the selected user group at 917. The effect of this operation is to "make many users become members of the" R & D "user group, and the user's dialogs have the source IP address of '1i shown at 917; and when the user clicks : When the "Apply" button is pressed, all copies of the access control database 301 are modified.
FIG. 10 shows a display diagram 1001 for defining an information set. Here, window 1003 contains a hierarchical list of information sets, and window 1005 contains a hierarchical list of available resources. It is developed in the same way as the user group's 'I1 table: a hierarchical set of information sets', and a hierarchical list of available user groups. In addition, the information set and available resources that the user who has the administrative authority to manage FIG. 1001 are shown in black; all other items on the list are shown in gray. In Windows 1001, the available resources are: the Internet and the two locations that make up VPN201. The '11 table of resources available in a more developed VPN 201 should indicate: the server at the location, the services in the server, and the items of information provided by the service. As the police say, if the service provides a directory tree, the information items contained in the directory tree should be indicated by a pathname; the path name will specify the root of the directory tree and will use the Match characters (wildcardcharacters) to indicate some files above the root of the directory tree. When a resource is strengthened. When it comes to a server, resources may be defined via window 1005. Thus, a resource has been defined, and a resource may be assigned to an information set in the same manner as a user identification information is assigned to a user group. Furthermore, clicking the "Apply" button causes the changes in the display 1001 to be propagated to all copies of the access control database 301.
Figure 11 shows "display diagram 1141 used to define a decision. Which type of decision is being defined is specified in the snap 1113; as indicated in that, display diagram 1101 is defining an access decision. All All decision display diagrams have the same general format: a window 1103, which contains a hierarchical display of one of the user groups: a window 1105, which contains a display that may define one of the object levels for which the decision is targeted; and a decision Definition window 1107, which contains some access decision definitions 1108fl. In the object level, the user who has the right to define the decision shown in Figure 1101 is shown in black; the others are shown in gray. Defines access decisions, so objects are information sets.
Each access decision definition has four parts:
An active checkbox 1117 indicates whether the access decision defined by the decision definition is active, ie, is being used to control access operations.
The access group is being defined for the user group 1119; the access decision is being defined for the information set 1123: and the access operation bit 1121, which indicates whether the access operation is allowed or denied to define the storage Make decisions.
The menu bar 1109 and the button bar 1115 allow decision makers to make decisions; those who do this can edit, add, delete, and activate or deactivate a selected decision definition 1108. The active checkbox 1117 of each decision definition 1108 allows the administrator to enable or disable the selection decision definition 1108; the access exploration field 1121 allows the administrator to choose to allow or deny the decision. The "Delete" button in the button strip 1115 allows the administrator to delete a selected decision; the "Add" button allows the administrator to make a new decision definition 1108; to do this, the administrator will choose: in the window One user group in 1103 and one information set in window 1105: Then click the "Add" button. A new access decision definition 1108 appears in display 1107; and, the administrator can edit the new access decision definition, as just described. To apply the change to the access control database 301 and propagate it to all access filters 203; the administrator will click on the "Apply" button 1125.
Figure 1101 also contains a policyevaluator tool that allows administrators to see how the current set of access decision definitions determines access operations for a given user group or resource set. Press: When the button has the "policyevaluation" button in 1113, and a user group is selected from the display 1103; the tool will display: the selected user group is blue: the decision definition allows User group access and all information sets shown in Figure 1105 are shown in green: the rest are shown in red; all decision definitions related to the decision as to which information set may be accessed by the user group are highlighted In the color set. If the administrator chooses to translate an information set, the same thing happens; then, the evaluator tool will display: the selected information set appears blue, and all user groups that can access the information set appear green , And the rest are red, which also highlights some relevant decision definitions. Users can also choose a decision. In that case, The selection decision is blue, and the user group information set affected by the decision is blue or red, as determined by the decision. The user can choose more than one; user group, information Set, or decision. In that case, the evaluator tool shows for each decision: the effect applied to all selected items, and the effects of those decisions. The evaluator tool can be clicked on the button band 1113 " The decision evaluation button is turned off and the color and highlights can be turned off by clicking the resetevaluation button in the button strip 1115 to target a new Prepared for decision evaluation.
FIG. 12 shows; FIG. 1201 is used to input information about an access filter 203 into the access control database 301. Window 1203 displays: a hierarchical list of access filters 203; when the window is active, the two buttons "Add" and "Delete" in button strip 1209 may be used to add or delete access filters. The window 1205 is used to input or display information about the access filter 203. The display image in window 1207 is determined by clicking one of the buttons in the button strip 1207; as shown by the button, the display image in window 1207 can be used in order to enter and view many access filters Information about network connections of the filter 203, enter and view information about the trust levels of those connections, scan the network for available servers and services, and create alerts for issues detected in the access filter 203 , Specifies the optional parameters for the software, and specifies the assignment 1} 1} sequence that is changed by the access control database 301. The highlighted function instruction of "alerts (-, tup)": the display 1205 shown in Fig. 12 is a display diagram for displaying and creating alert information.
User interface for inventing resources; Figures 18 and 24
3 User interface for inventing resources: Figures 18 and 24
VPN201 users have an interface to see what resources are available to them in VPN201. This is called the IntraMap (intra-image) world} u (IntraMap is the Internet's second force .... company (InternetDynamics, Incorporated) is a trademark) interface, at least to each user will be shown: belonging to the user may A resource of an information set that is accessed according to an access decision for the user set to which the user belongs. In other embodiments, IntraMap may also consider the sensitivity level of the resource and the trust level of the user's identification method.
IntraMapf is constructed by a small Java program (JavaTmapplet), which is executed on any World Wide Web (www) browser equipped with Java. "Using a web browser, users can scan the graphic display, In order to: Find and access resources available to users: Or, request access to resources that are not currently available to users. Access to resources by users is determined by many access decisions that apply to users and resources Figure 18 shows the display produced by the IntraMap interface 1801-IntraMap display 1801 The left side of the display shows the resource list 1803: while the right side of the display shows the "Find" field 1807, 44 Sort section 1809, the Services section 1811, and the Description field 1813. By clicking the "Help" button 1815, an on-line help program using IntraMap is available (on-linehelp is available).
Resource '11 table 1803 shows: For users who are using the IntraMap interface, the resources and information available in VPN 201. This} 'l table is hierarchical. The user can expand or collapse the "tree" branch by clicking on the "ten" and k "marks on the branch. Each entry in the '1l table will include 1804 The name of the resource. The color used to display the posted item indicates: what kind of access operation the user has. If the posted item 1804 is displayed in blue: the user has a free hyperlink for the resource. And may click the resource twice to display it. "If the resource is displayed in black, although it is also available to the user, there is no hypercommunication link available, so a separate application must be used to Retrieving resources, although the resources that are grayed out are not directly available for users, but if the user selects a resource, the IntraMap interface will open a dialog box "Especially the user will request access An operational email (e-mail) is sent to the administrator, who is responsible for the access decision of the information set to which the resource belongs. Then, the administrator may modify the access and / or management decision if necessary, The user can be given access operations. The administrator may further give the resource a "hidden" property. When the resource has this property, only if the user belongs to one of the information sets that the access resource belongs to use Group, the resource will appear in the IntraMap interface 1801. If the resource does not have a hidden feature, 1aI1 will always appear in the IntraMap interface 1801. In other cases, it will not appear "The resource may have an item than it is contained in it. The description in the entry 1804 of the detailed description. When the user selects the resource, the description is displayed in the description field 1813.
In addition to the resource list 1803, the IntraMap display chart 1841 will also show two specialized resource lists at 1805.
"What'sNew" 1806 shows: Recent information notices from other departments in the gold industry (postings) If the administrator has given the user access to the "Who's Latest" webpage, the user may send a new resource The URL (Common Resource Index) announcement is posted there.
"What's Hot" 1808 shows the most popular information resource of the gold industry based on how long the resource has been accessed.
The service type control table at 1811 allows the user to filter resources that are intended to be displayed in the resource '11 table 1803 according to the service type of the resource provided. In the service type control table 1811, each service type has a check box. If the box is checked, resources that include the service type and are associated with the service will appear in the resource list. "In other cases, resources associated with this service will not appear in the resource list.
The IntraMap interface allows users to sort the resource list 1803 by: information set, location, or service. To do this, the user chooses the way he wants to sort the resource table in the sort column 1809. The user may also specify the resource categories (categories used in the sort field), M order. The interface also has a search function. To perform a search function, the user enters a search string into the "Find" field 1807. Then according to the .ra order listed in the sorting field 1809, search for the resource list and resource description for the resources about the string. "The search function only finds all or part of wordmatches. Situation Not very sensitive, it shows that for the first time, Squid may use some function keys to navigate to other matches. Of course, if the user has not checked one of the service types in the service type field 1811, then the Many resources of the service type are not involved in the sort or search operation.
Figure 24 shows: One of the construction of the IntraMap interface * 12401 For users of VPN201, the IntraMap interface appears as a web page, which is provided by the report management program 209 being executed on the access filter 203 (c) in FIG. 2 A resource among resources. A user in VPN201; or even the general public (that is: someone who is a member of the Internet user group) may do so in the same way that he may be given access to any other resource, Given the access to the IntraMap interface, as will be apparent from the description below, the web page for IntraMap may be on any server in VPN201. The construction example 2401 includes: a component used by a user in the workstation 2403 to look at the IntraMap; a component in the access filter 203 (1) that is local to the workstation 2403; and A component in the access filter 203), which is an access filter on which the report manager 209 executes. Of course, the access filter 203 (.) May also perform a function like a local access filter. The local access filter 203 (1) is connected to the report access controller 203 (c) through VPN 201, and the workstation 2403 is connected to the local access filter 203 through the local area network (LAN) 213 (1).
As will be explained in more detail later, all access filters 203 have a layered architecture. The lowest level is an Internet packet information (IP) filter 2419, which only deals with the Internet. Road subcontracting information title only. The Subcontracting Information Filter 2419 reads the source and destination addresses in the Internet Subcontracting Information header and applies a set of rules to the subcontracting information "As determined by the rules, the IP filter does not accept them , And pick them up; that is, to further guide them in VPN 241. This rule will also determine: In the access filter 203, how to plan to guide a lot of accepted subcontracting information. The next level in the architecture is the service proxy server (Serviceproxies) 2427. The service representative server will wear the traffic for services such as the World Wide Web (Www) and perform access checks on the traffic. If the access filter 203 provides the service itself or performs Access check of one of the servers, then the IP filter 2419 sends the subcontracting information for the service to one of the services. The service proxy server 2427 The service proxy server uses the access control database 301 to execute the service Protocol-level access check "As stated, a service proxy server for a web service may check that a Whether the requesting user has access to the webpage. The next higher level is the service level 2425; if the relevant service proxy server allows a request and the access filter is also the server for that service, it is intended to process the request to the service at the service level 2425. In the case of a web page, the service should indicate the placement of the web page and return it to the requester. In IntraMap, two types of services are involved: Web (x Road) service and IntraMap service. In Figure 2401, the Web service appears as WebS2423. For the proxy server 3kWebP2421 of WebS2423; for many reasons that will become apparent in the 'IJt} a description below, the IntraMap service has only one proxy server: IntraMap2417 In addition, the access control database 301 includes IntraMap information 2422, which The optimized version of the information in the access control database 301 can be used as the basis for the IntraMap display.
The main difference about the construction example of IntraMap between access filter 203 (c) and access filter 203 (I) is that access filter 203 (c) includes a copy with IntraMap, l, Java program 2411 When downloading the web browser 2429 from the access filter 203 (I) ill workstation 2403, the little Java program 2411 will generate a request to the IntraMap server 2425, and then use the IntraMap server 2425 The result returned by the server 2425 generates the IntraMap display 1801.
Operation deduction: For users of workstation 2403, IntraMap may appear as a communication link for one of the web pages. Therefore, to use IntraMap, the use will start one of the communication links for IntraMap webpage 2410. The web browser 2429 in job 2403 will respond to initiating the communication link, just as it should respond to initiating any other communication link to the web page: it makes a request for the web page and sends the request Send to the server indicated in the communication link. In the case of the communication link for IntraMap, the web server 2423 in the access filter 203 (c) is fixed as the communication link, so the request will pass through the local access filter 203 (1) and VPN201. While going to the access filter 203 (c) is just like any other access operation for one of the resources in VPN 201, the local access filter 203 (I) performs the access column pair for the IntraMap webpage request. Since the request is for a web page, the web proxy server 2421 performs full access check. In most VPN201, the IntraMap webpage 2410 will be accessible to any user in VPN201. Therefore, the access control database 301 indicates that any user with a valid IP source address is May access IntraMap web page 2410.
When a request is received in the storage access filter 3203 (c), the IP filter 2419.AX will forward it to the network representative server 2421, which will sequentially forward the request to the J network server. 2423, it responds to the request by loading IntraMapd, Java program 2411-F to the web browser 2429 in the workstation 2403, among which: the IntraMap Java program 2411 starts to run in the web browser 2429. During execution, it will send a request to IntraMap information 24226'JIntraMap proxy server 2427. Like all Java programs, the IntraMap Java program 2411 sends the request to the server it is in. In this case, the squid is the access filter 203 (c). "However, as for the workstation 2403 Like any other access operation, the request will advance through the local access filter 203 (1). Voila, the IntraMap proxy server 2427 will check out the IntraMap that the request was addressed to in the access filter 203 (c) Proxy server 2427 instead of sending the request to access filter 203 (c); obtain IntraMap information 2422 from a local copy of the access control database 301 in the local access filter 203 (1); filter the information Makes it clear that it only accesses the resources that belong to the information set targeted by many user groups to which the user belongs to generate table 2431; and then returns it to IntraMapd, Java program 2411 via LAN213, which The program then uses bad, J table 243 to generate the IntraMap display map 1801. In generating the display map, the small Java program 2411 will apply any access filters specified in the request, and will also sort them as specified in the request. fl table. To table 24 31 not only indicates the available resources, but also contains the information needed to fetch the resources. Therefore, if the resource has a hyper communication link, the hyper communication link is included in the list; if it is a The user currently does not have access, but the user may request access to the targeted resource. The '1' table includes "the email address of the administrator of the resource.
Details of the access control database 301: Figures 13 to 17
3 Details of the access control database 301: Figures 13 to 17
In a preferred embodiment of the access filter 203, the access control database 301 is constructed at two levels: one level is used by a graphical user interface to manipulate the access control database 301; and the other One level is used in the actual access check. The first level is constructed using the Microsoft Jet trademark database system developed by Jianbi Zuo. The second level is constructed using some memory mapped files (MMF) compiled from the first level database. The following 11 discussions will describe first-level construction examples and explain how the information contained in them is used in access checks. In studying this discussion, you should remember that the actual access check is done using MMF, as will be described in detail later.
As is the case with most database systems, the Microsoft.let trademark database system has a diagram, which is a description of the logical structure of the database. 13 to 17 are display diagrams generated by the Microsoft Jet trademark database system for the diagram of the access control database 301. FIG. 13 shows a diagram 1301 for a portion of a database defining a plurality of user groups. The display diagram consists of two elements "in the database." Tables and other 11 "(classesoftables) representation of 1303, and" communication links "showing the relationship between the two tables that belong to certain categories of tables The notation of 1305. The notation of the category of the table shows: the name of the category at 1310; and the 'data field' to be included in every table belonging to that category at 1308. Examples of each table have An identifier (ID) specified by the database system. Other information in the table will change with the type of the table. By using the ID of the second table in the first table to create a kind of belonging to the table The communication link between the first table of the first category and the second table of the second category of the table, and vice versa. Therefore, the communication link 1305 shows that the "user group tree" category table 1307 And some tables in the "User Group" category table 1309. Some communication links have numbers at both ends of them. The number indicates the number of communication links the table may have at the end of the number. Thus, the communication link connecting the category table 1309 and the category table 1307 has a number 1 at the end of the category-specific table 1309, and a number at the end of the category-specific table 1307. ; Thus indicates that any number of IDs in the instances of category table 1309 may appear in one instance of category table 1307: however, only one ID in one instance of category table 1307 may appear in one of category table 1309 Instance.
User group table: Figure 13
3 user group table: Figure 13
The user group table 1301 includes a user group category table 1309 for each user group in the database 301. In the "user group" category table 1309, particularly interesting data includes: group house name , Which is the character-string name of the group; group description, which is the character string description of the group; and pre-defined information, which indicates whether the user who is a member of the group is : An administrator, that is, capable of making management decisions; a security officer, that is, capable of making decision makers' decisions; or a purely information user. The user group table 1301 will further organize many user groups into a hierarchical list-not only for inheritance rights, but also for the hierarchical display of user groups shown in window 903 in Fig. 9
Map, thus associating the user's identification method with the user group and the alert information with the user group. Organizing into a hierarchical list is done through some tables in the "User Group Tree" category table 1307. Each of the tables in the "User Group Tree" category table will include the "User Group" category table One table is linked to a parent user group (also a type of "user group"). For a specific "user group" table, multiple "user group tree" tables It may exist, depending on the number of places in which a particular user group appears.
As already mentioned, there are five different ways to identify users to an access filter 203 by IP address range, by a fully qualified Internet domain name, by The user identity in the Microsoft Windows trademarked operating system is identified by a brand, and by a certificate. Table classes for tables that identify users by certificate are displayed at 1321. Category tables for tables that identify users by IP address range are displayed at 1317; category tables for tables that identify users by IP domain are displayed at 1319; for tables identified by Microsoft Windows trademark Operating system IDs (identifiers) are shown at 1315 for those category tables; and those are for category tables that identify users by authentication tokens (labeled as smart cards in the figure). Is displayed at 1323. Finally, category tables 1325 are defined; some tables for alerting information related to user groups. One of the "user group" category tables 1309 may associate it with any number of tables for any way to identify users. As the case implies, there may be many different ways to identify an intended user at the same time.
In order to perform an access check, the access filter 203 must decide which user groups the user who is making the request belongs to. The request includes a user identification method, so the identification method is the starting point for the decision. Some tables in the user group table 1301 will allow access to the filter 203: determine which user groups the user belongs to according to the identification method, and determine some other uses that determine the user's belonging to them according to those user groups Hierarchical relationship of the group. Assuming the user is identified by an IP address, the access filter 203 looks for " IP address range definition "category table; in 1317), one or more tables are started to operate, this category table defines the" IP address range including the user's IP address. Each of these tables has a communication link to the "toIP address range" category table (in 1317), which makes the range defined in the "toIP address range definition" category table and a user group The group ID is related. As far as the user group corresponding to the IP address range is concerned, it can be used as a communication link to the "user group" category table 1309 in order. Each of the "user group" category tables 1309 has a communication link to the "user group tree" category table 1307, so that it can point to some user groups along some communication links "User group" category table, so some user groups specified by the IP address will inherit access rights. Thus, at the end of the process, the IP filter 203 has indicated the locations of all user groups, which are all related to determining whether the user is likely to access the resource. Furthermore, the IP filter 203 knows how to identify the user according to the request, and can decide, based on the request, what level should be assigned to the user identification method used in the request. The information in the user group table 1301 is added. Compile into MMF (memory mapping file). When the user initiates a conversation, the user will provide a user identification method to the first access filter 203 on the conversation path: the access filter 203 uses the The user identification method of the MMF in order to make a decision that is in effect of one of the decisions described above. The access filter 203 can then decide whether, for a given user identification method, it recognizes the right to access One user of the information; what user identification method it is; what level of trust it has; and which user groups the user belongs to. Therefore, the user group table 1301 contains an access decision All information required by the user portion of 1108.
List of Fan Yan Fan: Figure 14
3 information set table: Figure 14
FIG. 14 shows a chart 1401 for some tables that define an information set. These tables make many information sets (resource groups in Figure 14) related to the resources that make up them, and to the network location of the resources; and also organizes many information sets into: The hierarchical '11 table 'of the information set displayed at 1003. Each information set in the access control database 301 is represented by the "resource group" category table 1403. The resource group category is represented by table 1419 Some of the tables are organized into a hierarchy for inheritance and display purposes. The relationship between the information set and some of the resources that make it up in the grasp, and some of the pulls in the VPN that store them in it Created by some tables in the "resourcegroupelements" category table 1407. Any number of tables in the "resourcegroup elements" category table may be linked to "resource" elements One of the "Group Units" category tables is linked to many category tables: "SiteElements" 1411, "Services"! 1413, and any number of tables in "Resources" 1409. For database 301 Represented Each resource will have a "resource" category table. Included in this table are: the ID of the resource; its name; the ID for the service providing the resource; the ID for the sensitivity of the defined resource; the resource description: the resource administrator's Email address; and a hidden flag that indicates whether IntraMap should display resources to users who do not belong to some user groups who have access to the resources. The IntraMap interface will obtain the information it needs. Information about a resource from the Resources table for a resource.
Two types of tables: some of the "Website Units" and "Services" tables, and two types of tables: "Websites" 1415 and "Servers" 1417 are tables of categories that describe the location of information in a VPN 1421. There is a "website" category table for each physical location in the VPN: there is a "server" category table for each server in the VPN: and there is a "service" for every service in the VPN Category table. The communication links in some tables in the "Website Unit" category table will make many websites related to many servers; in the "server", the communication links in some tables in the category table will cause many servers to communicate with Many of the services they provide are related: and the communication links in some of the tables in the "Services" category table will make many services related to the many resources they host.
In determining what information set the requested resource belongs to, the access filter 203 starts with the information in the request. The request is contained in an IP subcontracting message, so it has "a header and a body in the header:-IP address, which specifies a location in the virtual private network 201, and A server at the location; a port number that describes a service about the server. In the ontology, there is a description of the resource in the form prescribed by the communication protocol. For example, if the request is For a web page, the resource description will be the URL of the resource. The access filter 203 uses the IP address to indicate the location of the "Bigang Station" category table, and uses the communication link in the table to indicate the "tl website unit" category Table 1411's location. This table associates the website with the server ID (identifier) of the Nuo server at the website; and, the access filter 203 uses the server ID to indicate the "server" category table for the servers of the website The position of some tables in 1417. It can then use the IP address to indicate the location of the "server" category table corresponding to the server specified in the request; and it can move from the "server" table to the "service" category table for the service Many tables have many communication links: in turn the port number from the request can be used to find the appropriate "service" table. Once it has discovered the appropriate "service" table, it will be able to). W points to a number of communication links to some of the tables in the "resource" category table 1409, and indicates the location of the "resource" table corresponding to the resource in the request. From there, there will be a communication link to the "resource group unit" category table 1407, which associates many resources with some resource group organization for the information set to which they belong. Many resource group identifiers sequentially specify some tables in the "resource group" category table 1403, and these tables have many communication links pointing to some tables in the "resource group tree" category table, so that they can The decision "indicates the level of the many resource groups to which the resource in the request belongs. Having completed those things, the access filter 203 has discovered that some resource groups related to deciding whether the request should be granted" The "resources" table also contains sensitivity levels for resources. Furthermore, the information in the information set table 1401 is edited into the MMF. When a request comes to the first access filter 203 in the path between the user and the server providing the resource, the first access filter 203 uses the MMF file in order to make a logical equivalent to] Only one of the described decisions was decided. Therefore, after viewing the MMF file containing the information from the user group table 1301 and the information set table 1401, the proxy server has decided: the trust level of the user identification method, the sensitivity level of the information resource, and some of the users' belonging User groups, and some information sets belonging to the information resource "Decision table: Figure 163 Decision table: Figure 16 Figure 16 shows: used in the access control database 301 to define some access decision tables; including in Among these decisions are: access decision, management decision, and decision maker decision: access decision makes the user group related to the resource group; management decision makes its members one of the administrators One of the following is related: 1. Another user group 2-A collection of resources 3-A resource 4. A location (website) in a VPN 5-An access filter 203 or another server 6. A service Decision makers make decisions that relate the administrator's user group to the information set.
Each decision will have a relationship between the "left side" and the "right side". The left side is always the "user group" category table 1309, while the right side depends on the type of decision. It may be: "resources" category table 1409, "resources" Group "category table 1403 represents the information set)," website "category table 1415," "service" category table 1413, "server" category table 1417 or "user group" category table 1309. Therefore, the decision tables 1601 are divided into three Large groups: tables 1603 on the left, tables 1605 on the decision, and tables 1609 on the right. The right to change a decision is a hierarchical group of members of a user group can change access decisions, say by management decisions for the group As determined, the group's "user group" table indicates "it is a type of one of many administrators. In order, those administrators may specify other management decisions related to their sub-domains.
Corresponding to three kinds of decisions, there are three categories in the decision tables 1605: belonging to the "Access Policies" category; Table 1611, "PoliciesAdminister" category 11A1613, and "Decision Maker Decision" (PoliciesPolicyMaker) Some tables of category table 1691. All of these category tables share many characteristics; they all include: the ID of the user group table on the left side of the decision, and the ID of the table indicating the items that are listed on the right side of the decision. An indication of whether the decision is predefined and cannot be deleted, and an indication of whether the decision is currently in use. The difference between category tables is: which may be on the right side of the decision, and thus is the communication link to many entities on the right side; in the case of access decisions and decision makers' decisions, the right entities are just information sets, Therefore, some tables in the two categories of "Access Decision" and "Decision Maker Decision" only contain many right-hand communication links to some tables in the "Resource Group" category table; and "Administrator Decision" Some tables in the category table may include alternatives to the following: "user group" category table, "resource group" category table, "website" category table, "server" category table, "service" category Tables, and many of the right-hand communication links in the "Resources" category table.
The right given to the user group specified in the user group on the right side of the management decision to govern the collection of many entities specified in the right side will vary, depending on the type of entity, as shown in the following table :<img file="TW448387B_D0001.tif" /><img file="TW448387B_D0002.tif" />
The following table describes the rights granted to administrative user groups when they appear on the left side of the decision maker's decision.
<img file="TW448387B_D0003.tif" />
As pointed out in the discussion of the information set table above, the proxy server that is performing the access check can use the "user group" table and the "information set" table to find: User groups, and the information set to which the information resource is being accessed; these tables can also be used to determine: the trust level of the user identification method, and the sensitivity level of the information resource "proxy server can then use" access "Decision" table to find: Is it possible for any user group to which the user belongs to access any information set to which the information resource belongs "if any such user group is found; then the user may access the information set, if If the requested trust level is as high as the sensitivity level of the information resource. To determine the level of trust requested, the proxy server must determine the level of trust of any encryption technology being used, and / or the level of trust of the path in VPN 201 being used for access operations. This information can be obtained in the access filter tables 1701 shown in FIG. 17 and described below. If the sensitivity level of the access decision or access request does not allow the fetch operation, the message is ignored and any dialog to which it belongs is discarded. When the request is a request made by a user who is a member of one of the management user groups of the access database 301, the access check process is essentially the same: only unfortunately: when the access operation is When allowed, it may lead to the revision of the database according to the rules announced above. This modification will then be propagated to all other access filters 203 in VPN 201.
Server table: Figure 17
3 server table: Figure 17
Figure 17 shows a chart of tables that are particularly important for the operation of many servers in a VPN. In a VPN, there are three types of servers:
Yangchun servers (Plainservors). These are: servers that have resources stored on them and access resources by running services.
Access filter 203.
Decision Manager server. These are: an access filter 301 that occupies an e-coordinate distribution database 301, and / or generates some reports on the operation and status of the VPN.
The access filter 203 may additionally perform a function like a Yangchun server.
There is a "server" category table 1417 for each server in the VPN. Information in the table for each server, including: server ID, name, domain in the operating system of the Windows NT trademark, and its Internet name , Whether it is an access filter 203 and incidentally a decision server, whether access information can be obtained only through the access filter 203, and whether it is within a VPN. If the server is an access filter 203, it will additionally have an identity provided by the access filter 203 to other entities in VPN 201 for authentication and encryption. In a preferred embodiment, the identification is: X.509 certificate for access filter used by SKIP. The X.509 certificate also includes a public key for the access controller 203. The public key may belong to one of many loyalty spaces (namespace); the namespace identifier (namespaceID, referred to as NSID) is an identifier for the namespace of the public key; and the master key identifier (mesterkeyID, referred to as MKID) is the public key identified in the namespace. Also included in the table is a communication link to the "Certificate Authority" category table 1711, which indicates the certificate authority that issued the certificate zX.509 for the access filter. Of course, with the access filter Different servers also have X.509 certificates; and, in that case, their "server" table will have the server's NSID and MKID.
Each Yangchun server in the VPN will have one or more services running on it. For example, a PTP (File Transfer Protocol) service will access files (resources) on the server according to the file transfer protocol in the TCPIIP protocol suite. Each of the "Servo I! .J1a9" tables 1417 for the Yangchun server has: many communication links to a group table that defines one of the services and resources available on the server. As shown at 1719, These tables include: "Service" category table 1413, which represents services; "resources", category table 1409, which represents resources available for use via services; and "service definition" category table 1715, which defines services.
For the rest of the tables in FIG. 17, there are shown some diagrams containing information used by the access filter 203. The category tables are displayed at 1705. Some tables will contain: all the information used by the access filter 203 to allocate the database 301ai or the decision management program used to generate the report: the category tables are displayed in Some tables at 1717 will contain information about many optional parameters for the software being executed by a given access filter 203; those tables whose category tables are shown at 1709 will include: about proxy servers and others Software module information, many access filters 203 will use this module to perform protocol-level access check in access filter 203; and some tables at 1707 will contain: Reliability and sensitivity definition information for identification methods and encryption types.
Some of the tables indicated by reference numeral 1708 will contain information about the VPN to which the access filter 203 belongs. The access filter 203 uses this information to route directed conversations; it is also used to determine the trust level of the path being used for a given conversation. The "Routingtable" category table 1721 will define: `` 1 shows some tables that point to many current routes to all networks that can access information from access filter 203. When those routes change, the table is automatically updated. The "AttachedNetwork" category table 1723 defines tables that indicate, for each access filter 203, the networks to which the access filter 203 is currently attached; in this category table, Some of the tables will contain many communication links to some of the tables in the "Network Definition" category table 1723, which in turn contains pointers to the "Trustdefinitions" category. A definition of a communication link, and the category table indicates the trusted children of the network. The last category table in this group is the "Point to Point Connection" category table 1713, which will define that the description can be passed through the VPN Tables connected between two access filters 203 for access information. There is a table for each combination of source and destination access filters 203, and a pointer to a type of access filter that specifies both source and destination One of the communication links is the trust level definition of the trust level of the path between the routers 203. The trust level in this table is based on the encryption technology used for the messages crossing the path.
As explained earlier, the "user group" table 1301 and the "information set" table 1401 provide the information required by the access filter 203 in order to decide whether the access decisions in the table 1601 allow access operations; In addition, it will provide: Lingering Zheng-level information about the resources being accessed. The access filter tables 1701 will additionally provide the information required to access the filter 203 in order to determine: the minimum level of trust for the path in the VPN being taken by the conversation, and the level of trust of some available encryption algorithms . Therefore, if the access device 203 decides that a given user who is trying to access a given resource belongs to a user group that has access to the information set to which the given resource belongs, and decides: The identification level of the identification method is not lower than the identification level required for the sensitivity level of the resource: the access controller 203 can further determine whether the path's trust level is high enough: and if the trust level is not high enough, the The fetch filter 203 can increase the trust level to a required amount by selecting an encryption algorithm having a required trust level and encrypting the conversation.
Available information sheet: Figure 15
3 Available Information Sheets: Figure 15
FIG. 15 shows a chart of tables 1501 for available information. This table is used by the access filter 203 to generate the available resource display diagram 1005 shown in FIG. 10. Some of the category tables shown at 1502 will make each RIS related to its services and related to the resources provided by the services. The category tables shown at 1504 organize many available resources into a hierarchy for the purpose of inheritance: and are also used to generate the hierarchical tables shown at 1005: and then by following the "Site" site unit With many communication links from the "list" to the "server" table, the access filter 203 can determine: the level of the website, server, service, and resource. In some category tables at 1503, a distribution tree of the access filter 203 is finally established. Said like to be more detailed later. As stated, when the access control database 301 is modified, the tree defined by those tables will determine: modify the order that is assigned to some access filters.
Modify the access control database 301: Figure 19 '
3 Xiu Mei access control database 301; Figure 19
As mentioned earlier, each access filter 203 will have an exact copy of a copy of the access control database 301 belonging to the master decision management program 205 in the access filter 203 (a) of FIG. 2 ( exactduplicate) Figure 19 shows how to modify that copy of the access control database 301 and how to distribute the modification information from the access filter B203 (a) to other access filters 203. Figure 19 shows: with master decision management Access filter 203 (a) of program 205 and another access filter 203 (i) where one of the workstations is using an administrator who is modifying the access control database 301 'which is needed to distribute and synchronize modification information Message 1909 is encrypted using SKIP and sent via VPN201 using a communication protocol called "private communications services" (PCs). Each access filter will have many access control databases 301 "Any copy of any access filter 203 has at least two copies: a live database (LDB) 1907, which is a database currently being used to perform access checks; and mirror data The database (mirror database for short, MDB) 1905, which is: a copy that can be switched into, intended to replace one of the live databases 1907. Therefore, the access filter 203 (a) has: -MDB1905 (a) lv-LDB1907 (a); and access filter 0} `; a203 (i) PIj has: MDB1905 (i) IRLDB1907 (i).
If an access filter 203 is being used by an administrator to repair the access control database 301, it will have at least one working database (WDB) 1903 incidentally. The work database is "is not a copy of a database that is being used to control access operations and can be repaired by an administrator. The administrator uses a workstation or PC that is connected to one of the access filters over the network (Personal computer). The workstation or PC displays the management graphical user interface described above, and the administrator uses the GUI (graphical user interface) to make many changes as enabled by some management decisions. Changes may affect any aspect of the information stored in the access control database 301. As indicated above, many of these changes are changes in access or management decisions, so administrators can use decision evaluation features to Observe the effect of change "When the administrator is satisfied with the change, he will click:" Apply "button; instead, many acetylene changes will be assigned to all access filters and included in each access filter. Live database.
The process of updating all live databases is called: database synchronization and distribution, and this process has three stages:
First, the repair information is sent from the access filter 203 (here, access filter 203 (1)) where they were generated to the access database 3203 (here, access filter) 203 (a)).
In that case, many changes were incorporated into the master database. The way to do this is to include many coups in the mirror database 1905 (a) and then the live database 1907 (a). The mirror database 1905 (a) is swapped and then the new mirror database 1905 (a) is changed.
Many changes are then assigned from the master decision manager to other access filters.
At each access filter 203, synchronization is done in the same way as with access filter 203 (a). The order p1, q according to which changes are made in the access filter 203 of VPN 201 is determined by the distribution tree 1511, and it is set up sequentially using the access device display 1201. An access filter 203 with a master decision manager 205 is always the root of the tree. According to a default method, the first access filter 203 installed in the VPN 201 has a master decision management program 205. When other access filters 203 are installed, they are added to the tree as children of the master decision manager.
The master decision management program sequentially distributes many changes to its children. When each child access filter 203 receives its allocation information, it then assigns it to its children. This means that a shallow allocation tree with many branches from the top level will complete an allocation cycle faster than a deep allocation tree with few branches from the top level. . Administrators with proper access to information can reconfigure the allocation tree to make allocations more efficient.
If two administrators have modified the same information segment (eg, access filter definition) in different job databases 1903, a synchronization conflict will occur. When this happens, the master decision management program 205 says that it will decide which modification information to include in the access control database 301.
Optimizing the access control database 301: Figures 21 and 23
3Optimize the access control database 301: Figures 21 and 23
Although the management graphical user interface (GUI) 1915 is suitable for continuous storage and use, the database 301 is not optimized for use in real-time access checking. It is said that as will be explained in more detail below, accessing the cache 203 will optimize the data in the database 301, which is required for run-time access verification, and then used to generate the IntraMap Display diagram. Every time a new copy of the database 301 is received in the access filter 203, it performs optimizations according to their optimized form. The database 301 is one of many memory mapped files (MMF) A collection in which access decision information is stored in a form that allows quick access. The reason why it is called MMF is as follows: although they are all generated as normal files, they are subsequently attached to the memory space of a program, and are all operated by some memory, not by file operations. Access is further optimized by using MMF files in order to generate some rules "using IP source and destination addresses and port numbers that are allowed or denied for access operations, use this rule to enforce low messages Hierarchical filtering operation.
Figure 21 shows an example of MMF file 2303. The MMF file in question is: DBCertificatesbyUserGroup (4 database "certificates" identified by the user group) file 2101, which maps the certificate matching criteria used to identify certificates belonging to many specific user groups To: For the records of many user groups specified in the certificate matching criteria, some identifiers in database 301 "thus, file 2101 allows to have a certificate that will identify the source of a message that has been encrypted using SKIP. An agent waits for R3 to quickly decide: the user groups to which the user identified by the certificate belongs. In a preferred embodiment, the certificate matching command is: (Organization), OU (Organizational Unit), & CA (Certificate Authority) in the X.509 certificate.
All MMF files 2303 have the same general form, with two main parts: the header part 2103, which contains the information on which it is being mapped, and the data part 2105, which contains the information to which it is being mapped. " Heading 2103 contains one of the many entries 2107 bad 11A. Each entry will contain: a value on which the mapping is based (in this case, the Certificate Matching Criterion (CMC) 2109); A pointer 2111 recorded in one of the data sections 2105, which contains the information being mapped to (in this case, for many user groups to which the user identified by CMC 2109 belongs, in List 2115 of one of the many identifiers 2113 in the database 301). Many of the entries in the title 2103 are sorted according to the information being mapped (here, CMC 2109), making it possible to use many tags A fast search algorithm is used to indicate the position of the entry 2107 corresponding to one of a set of established certificate matching criteria.
FIG. 23A, BaC provides: a complete list of a number of MMF files 2301 used in one construction example of the access filter 203. From the description of the contents of the files provided in the tables, the relationship between these files and some tables in the database 301 will be obvious. Each MMF file 2303 is represented by one of the entries in the table, which indicates the file name and its contents. Will be surprised by many files. Divided into the next group '1: 2311, 2313, 2319, 2321, 2323, and 2422. Some files of particular interest are: DBUsers (database "users") case 2307 and DBResources (database "resources") file 2309, both of which describe decisions; DBCertificatesByUserGroup (data identified by user groups Library "Certificate") file 2101, which is the MMF file shown in Figure 21 in detail: DBResourcelDbyServiceID (database "resource identifier" identified by IP name) file 2315, it will make the URL of the resource (common resource indicator ) Has a relationship with a resource ID (identifier): DBResourcesbyResource1D (a database 'resource' identified by a resource ID); file 2317, which associates a resource with a resource group; and DBTrustTable (database's trust level table ' ) File 2325, it will construct the SEND table 601.
Moreover, the following files are used to compile the rules: DBServerIDByNameFile (the database "server ID" identified by the IP name is the case) DBIPAndTypeByServerIDFile (the database "IP address and type" identified by the server ID) ) DBServicePortToProxyPortFile (database "service port to proxy server nv} Cnv port" file) DBAttachedNetworksByServerIDFile (database "affiliated network" file identified by server SID) DBRoutingTableFile (database "routing table" file) Database "routing table" file identified by server ID)
Many files in IntraMap information 2422 were finally filtered to generate bad lJ table 2431, and then use IntraMapd, Java program 2411 to download it to the client for use.
Details of the access filter 203: Figure 20
3 details of access filter 203: Figure 20
FIG. 20 is a block diagram of an architecture 2001 of an access filter 203. In the construction example shown in FIG. 20, all the access filter 203 components different from some NIC (network interface card) cards 2013 are constructed in software. The software in the construction example will be executed under the operating system of the Windows NT trademark manufactured by the main company. Software components fall into two broad categories: those components that execute as applications at the user level 2003 of the operating system, and those components that execute at the kernel level 2005 of the operating system. In general, in Programs executed at the core level perform: IP-level access checks, and encryption and authentication; those executed at the user level perform application-level access checks. Also included in the user-level component are: Manages the teaching body of the access control database 301 and software that generates MMFs and rules for IP-level access checks based on the access control database 301. The following discussion will begin with the core-level components and continue with the discussion and access Controls database-related user-level components, and then discusses protocol-level access check components.
Core-level components
3 core-level components
Network Interface Card (NIC) 2013: These are the ethernet token ringring cards installed in the access filter 203. Generally speaking, there are three types of network configured Luca. One is configured for the Internet, for a wide area network (WAN) 2011, or for an interface connected to a network of another access filter 203. The other is configured for the interface 2007 for all client computers; the third is configured for the interface 2009 for servers providing TCPIIP services. If it is not necessary to place an access filter 203 between many clients and servers, there may be only two types of NIC2013: one for WAN2011 and the other for LAN (Local Area Network). If no server exists at the location of the access filter 203, or if all local client computers have access to all local information resources, it is acceptable; it is not necessary to place the access filter in between .
J Real Gap Software (SHIM) 2017, during the installation, a J Real Gap (shire) comparison module was inserted between the two levels (NDIS and TDIS levels) of the Windows NT operating system. This will cause all traffic for a specific communication protocol to pass through SHIM2017. In the construction example, all traffic for the TCPIIP communication protocol will pass through SHIM2017, and non-TCPIIP communication traffic will go directly from the NIC to some appropriate other core modules group. SHIN2017 will invoke the SKIP module when necessary to handle the traffic of the TCPIIP communication protocol.
SKIP module 2021 sends all IP = Broadway traffic via SKIP2021. If the input subcontracting information is not of SKIP type, that is: SKIP does not need to perform 3aL authentication and decryption services; SKIP module 2021 will pass it Similarly to IP filter module 2019, if you do not plan to encrypt the output subcontracting information, SKIP module 2021 will send it directly to the appropriate NIC2013 for transmission. Although there is SKIP type subcontracting information , But the authenticator 2024 in the SKIP module 2021 can be used to identify a conversation; the encryptor / decryptor 2022 can be used to encrypt and decrypt information at a conversation level. Maybe Utilization: Any number of other access filters 203, some servers using SKIP, and some clients using SKIP to complete authentication and encryption / decryption. The authentication and encryption algorithms are based on the SEND parameter, and output subcontracting information , Set by the IP filter module 2019; or, it is specified in the input subcontracting information.
The SKIP module 2021 maintains sufficient status information for every other website it talks with, so that it can maintain high-speed operation for most SKIP-type subcontracting information. Subcontracting information is sometimes "parked" and additional processing (shared secret and temporarykey calculations) is performed. The "skipd" module 2037 in user space 2003 performs this additional processing.
IP filter 2019; IP filters operate according to a set of rules, which are; a rule compiler for one component of the database service 2029, based on access decisions in the access control database 301. Some basic functions of IP filters are used to:
1. Pass traffic to TCP / IP push.
2. Blocking traffic-Traffic for a specific IP address is explicitly discarded and is based on many special rules for emergency situations.
3. Discarding the traffic will discard any traffic that does not match any rules and is not explicitly allowed by any decision.
4, the agent handles the traffic-instead of delivering the traffic to the indicated target, it routes it to a proxy server application on the current machine.
5. Perform network address conversion-change the internal IP address that may be illegal to a valid IP address.
6. As soon as a new conversation is established that cannot be strictly determined by the rules for access control operations, the decision is passed to Pr iPf (discussed below). In general, this is for conversations that may be tolerated by decisions or by the aforementioned VPN tunneling operation characteristics.
IP Adapter 2019 performs these functions based on the following information:
Rules generated by a rule compiler;
Source and destination IP addresses and port numbers;
Encryption or non-encryption of input subcontracting information; and required encryption and authentication of output subcontracting information.
Components related to database 301
3 components related to database 301
Shared Directory 2028 = What access filter 203 VPN201 uses will maintain a single access control database 301 that resides in it. All versions of the database 301 in a given access filter 203 are maintained in a shared directory 2028. The shared directory 2028 also contains log files for each access filter 4-3203.
Private Connect Service (PCs) module 2025 "PCs module 2025 provides 'in the VPN 201, access filter-to-access filter' communication. All such communications will have their own IP port number via PCs-PCs, and their messages will be encrypted. Some specific functions implemented through PCs messages are:
Allocation tree management; allocation and synchronization of database 301; retrieval and allocation of routing table 1721; Windows domain. Retrieval of user information; network scanning; retrieval of registered content; and transmission of files used by reports and other subsystems.
ISDB management program 2027: The ISDB management program 207 manages the database 301. Other PCs are the only interfaces for the copies of the database 301 in each access filter 203. It contains software for reading and writing all tables in the copies of the database 301.
Database service and rule compiler 2029; database service module 2029 will generate many MMF files 2301. Every time it receives a new copy of a database 301 in the access filter 203, it does so. It uses the functions provided by the ISDB management program 2027 to read the live database 1907 (1) for a given access filter 203 (I) and generates many MMF2301 database service modules. One of the components is a rule compiler , It will generate some rules for use in the IP filter module 2019 according to some of the many MMF2301 related to MMF. The rule specifies what access operations are allowed or denied: IP source, destination, and port number. The rule compiler exists, acting as a DLL and an application that simply calls the routines in the DLL "In normal operation, whenever in the access filter 203 (1), from the master decision manager 205 When the modified database 301 is received, the routines in the DLL are called by the database service module 2029. The application is used in some special modes during the installation and bootstrapping process.
Memory Map File (MMF) 2301 "As already explained, MMF 2301 is a data file generated by the database service module 2029 and is used by many other modules in the access filter 203. Design files To make the next J operation as efficient as possible:
From user identification methods to (many) user groups; from information resources to (many) information sets; to find decisions related to many user groups; and to find decisions related to many information sets.
Qualification related components
3 Identification-related components
Evaluator 2036 The evaluation program 2036 is a collection of many DLLs used by each of the plurality of proxy servers 2031. The evaluation program 2036 provides the following functions to many proxy servers:
Prompting users for additional "in-band" or "out-of-band" identification information;
Obtain "out-of-band" authentication information from the Authentication ToolService (ATS):
Obtain a certificate associated with the current user from SKIPd; read a lot of MMF2301 and decide: whether the access decision allows the user to access the resource; and if the access operation is allowed under other circumstances, construct a path-specific Trust / sensitivity level calculations, including determining whether access operations may be allowed via paths, -ka if so; what encryption and authentication methods are required, and which access filter is closest to the server. These functions are performed by a component of an evaluation program 2036 called a VPN management program.
Authentication tool program service / user identification customer software (ATSIUIC) 2039 deduction 2041: ATS2039 is a server in a client-server application that collects and authenticates user information. ATS2039 runs on the computer, and There are other components on which the access filter 203 is executing. The client part is -UIC2041, which will be executed on a Windows-based client. ATS2039 and UIC2041 are mechanisms, and the access filter 203 uses this mechanism to obtain "out-of-band" authentication information. ATS2039} aUIC2041 communicates through a conversation separate from the conversation being authenticated. ATS2039 will collect and quickly access the authentication information it has obtained from many UIC clients, and then provide this information to the evaluation program 2046. The fast-access information from the client computers includes:
w; ndowsID: identification certificate; and identification order ID.
SKIPd2037:
Most SKIP'd functions support SKIP module 2021. Those functions include:
Exchange certificate information with other communication partners. This is done by using the Certificate Discovery Protocol (CDP). Computation of Diffie-Hellman shared secret method. This shared secret method is the key to SKIP operations. This calculation can take a considerable amount of time and store it to disk in an encrypted form. Calculate the transport key used to encrypt the conversation. These keys will last for a period of time or amount of data. In addition, SKIPd will provide certificate matching criteria to (among many) evaluation programs for use in user identification methods.
Proxy server 2031
3 proxy server 2031
As described above, the proxy server is software in the access filter 203 that fetches traffic for a specific communication protocol. What the proxy server "knows" about the protocol is that it is taking information and is able to obtain the information it needs to identify the resource being accessed and / or authenticate the user from the messages being exchanged during the conversation . As the IP filter redirects some messages using an established protocol from its standard port to its non-standard port, all proxy servers except SMTP will receive: For their communication protocols, the Messages on some ports. The proxy server provides the information it has obtained from the conversation to the evaluation program 2036 in order to determine whether the user has access to the information resources. If the user has access, the access filter 203 will forward the input message To the server to which they are addressed, and the message is further processed in the server by a service for that protocol. In the following description, each communication protocol used in a preferred embodiment will be discussed; of course, other embodiments may include proxy servers for other communication protocols.
Pr; Pf (IP router proxy server): Most network traffic will occur on a few communication protocols, and in the access filter 203 there will be many proxy servers for the protocol. However, even where there is no proxy server, an access decision must be made. In some cases, decisions may be made by IP Filter 2019 at the core level; when it does not make decisions, IP Filter 2019 says to provide traffic to Pr iPf, it will get whatever it can from the traffic Obtain information related to user identification methods and information resources, and then pass this information to the evaluation program 2036 to determine whether access operations should be granted. Pr iPf is not actually a proxy server, because it only makes an access decision for IP filter 2019, so it does not pass any traffic to the standard communication protocol software.
FTP (File Transfer Protocol): The FTP proxy server handles TCP / IP packet information for the file transfer protocol. One of the current embodiments of VPN201
In addition, the access control is only implemented to the account (login) level; in other embodiments, the access operation may be controlled to the file access level. During the FTP registration part of the protocol, the proxy server determines the server and account being accessed, and provides this information to the evaluation program 2036 in order to determine whether the user belongs to a user group , Many members of the group may have access to the information set corresponding to the account. The proxy server uses tokens that interact with users in the FTP communication protocol to further process "in-band" authentication information.
FTP is actually a very complex communication protocol involving active and passive modes (used in web browsers and some automated FTP client software). In addition, FTP data transfer Two dynamic deterministic TCP (Transmission Control Communication Protocol) dialogues. This requires a special interface between the FTP proxy server and the IP filter 2019, so that the FTP proxy server can instruct the IP filter 2019: it should allow the first Second dialogue.
HTTP (Super Text Transfer Protocol): For the public domain CERN (Danlisheng Hongzi Institute of Physics) construction example of HTTP, the 'HTTP proxy server' is constructed according to the source code and includes all other Quick access (cachinglogic). The proxy server uses an evaluation program 2036 to check each access operation pointing to a URL. No'. "In-band" authentication information is performed using HTTP.
Telnet (Remote Communication Network): Due to the non-standardized nature of Telnet registration, Telnet resources are controlled only to the server level "only to provide additional" in-band "authentication information will the Telnet proxy server be used. It is many The simplest of real proxy servers.
NNTP "NetworkNewsTransferProtocol (NNTP) is used to control both newsfeed and news reading operations. During the newsfeed operation, the NNTP proxy server looks at unencoded messages. These messages are already Binary messages that are converted into ASCIItext for transmission are often disbanded into multi-part messages in order to keep them to a reasonable size. The NNTP proxy server quickly accesses all parts of a binary message. For each such message, if the message is the last part of a multipart message, the entire multipart message is combined Then, the anti-virus module 2033 will check the messages against many viruses, as described in more detail below. During the news reading operation, the access operation is protected to the new group level. As in other proxy servers, the evaluation program 2036 is used to determine whether the current user may access the newsgroup
Real Audio Communication: The Real Audio Communication Agent server allows the client to access the Real Audio Communication Server, which is only protected at the server level. Real audio communication protocols use a standard TCP socket connection to establish a conversation, but then use a switch back to the UP channel. Just like for FTP, the real audio communication proxy server has an interface for the IP filter 2019, which allows it to indicate to the IP filter 2019 that "the switch back to the UP channel is allowed.
The SMTP simple mail transfer protocol (SimpleMailTransferProtocol for short) is different from other proxy servers; many rules of the IP filter's proxy server are not used to redirect traffic to the SMTP proxy server. In fact, other proxy servers will "listen" on a non-standard port; the SMTP proxy server will listen on the standard port (25), and then it will perform its own communication connection with the standard SMTP server. The access decision in the database 301 must explicitly allow this access operation.
IntraMap: When the user specifies that it is for IntraMap-zURL, the report management program 209 will download the IntraMap + Java program, and the downloaded small Java program will try to execute one of the access filters 203 with the report management program 209 The communication connection of a socket. The IP filtering 2019 of the local access filter 203 (1) will intercept the information of the attempted communication connection and provide it to the ntraMap proxy server on the local access filter 103 (l). By looking for answers in a partial copy of the database 301 and returning the answers to the Java program, the proxy server will respond to queries from the Java program. As all responses are being filtered to reflect user access rights. The IntraMap proxy server is not a real proxy server because the entire communication connection is always fully serviced by the instance of the IntraMap proxy server that cuts the communication connection.
Anti-virus module 2033
3 anti-virus module 2033
In a preferred embodiment, the anti-virus module 2033 is a plurality of DLLs provided by Trend Micro Devices, Inc., located in Cupertino, CA., California. One collection. In other embodiments, anti-virus modules from other sources may be used. The anti-virus module 2033 will check all information entering the VPN 201 for viruses. In order to provide users with feedback functions on data transfer, prevent the user's software program from timing out, transfer the data to the client computer and copy it at the same time into a virus check In the temporary file. However, the last part of the information was not sent to the client computer until after the virus check was completed. The last part of the temporary file will check the temporary file for many viruses. If no virus is detected, the bell portion of the data is sent to the client. If a virus is detected, the data transfer is suspended. In this embodiment, the user is notified that the transmission is invalid, and if the administrator has stated so, it may send a kind of alert information to the administrator.
Launch (launck), login, alert and report module 2027:
Some components of this module will perform the following functions to initiate an initial sequence of control startup work; when VPN 201 is established, the initial IA sequence will occur on an access filter 203. Register a DLL alert that provides a standardized login interface. A standalone program that looks at all NT logins, looking for the alert conditions contained in the database 301. Use the GUI to specify the methods used to deliver alert information for defining alert information.
The first report transfers a subset of many registrations to a special report registration, condenses it into a database, and then forwards it to the report management program 209 later.
Management Graphical User Interface 1915:
The GUI (Graphical User Interface) may be executed on the access filter 203 or any computer attached to the access filter 203 and having a 32-bit Windows trademark operating system. Whether the GUI is executed on the access filter 203 or the accessory system, it will use the ISDB management program 2027 to read or write one of the work control database 1301 in the access control database 301 via the GUI 1915 to the access The control database 301 makes all necessary modifications to the "application in the GUI" operation, and sends it to PCS2025 as a signal, which will respond to the signal by initiating the aforementioned allocation and synchronization operations.
Detailed example of the operation of the access filter 203; Figures 5 and 22
3 Detailed example of the operation of the access filter 203: Figures 5 and 22
In the following description, the end-to-end encryption example of FIG. 5 will be explained in detail. In this example, its PC is equipped with one of the SKIP intruders 503 is accessing: within a website on VPN 201, a server 407 equipped with SKIP. When intruder 503 is established to access VPN 201, it is so established by using an access filter 403 (3) of a special encryption type. Here, it will be assumed that the type of encryption being used by the intruder 503 has a "confidential" trust level: and it is assumed that the user wants to access a web page on the server 407, which is "confidential" Sensitivity. Because the web page being accessed is, the man 503 is using the HTTP communication protocol for its conversation with the HTTP service on the server 407. "Because of the roamer 503, many accesses in VPN 201 The filter 203, and the server 407 are all equipped with SKIP, so they are all equipped with their own public and private keys. At a minimum, the Drifter 503 also has a certificate and public key for the access filter 403 (3), which will direct messages directed to the servers inside VPN201 to the access filter 403 (3); access The filter 403 (3) has a certificate and a public key for the roamer 503 (or obtain them using a certificate discovery communication protocol); all access filters 203 in the VPN 201 have or can obtain: each other's public key, And public keys for many servers equipped with SKIP in VPN201. In addition, each access filter 203 in VPN 201 will know: all other access filters 203 in VPN 201 and the IP addresses of many servers.
All messages that are sent and received as part of the HTTP conversation between the Drifter 503 and the server 407 are authenticated by SKIP. "Figure 22 shows the format used by such a SKIP message 2201 "SKIP messages are produced by SKIP software on a system that is said to be the source of SKIP messages. The SKIP message 2201 shown here is from the man 503. Its main components are:
Outer IP header 2203: Outer IP header 2203 is used to deliver SKIP messages to the access filter 403 (3). Included in the IP header 2203 are the source IP address 2209 for the Drifter 503 and the target IP address 2206 for the access filter 403 (3). When the Drifter 503 is established to access VPN 201, The destination address 2206 used by the advancer 503 is said to be set up to specify the access filter 403 (3). The source IP address 2209 may be dynamically assigned to the roamer 503 by the Internet service provider; the rover 503 is used to connect to the Internet 121. The gFIP header 2203 also contains a message type and another 1l (messagetype, MT) field of 220 $, which will state that the message is a SKIP message.
SKIP header 2205: SKIP header 2205 contains the information needed to decrypt the SKIP message 2201 when the SKIP message is received. The SKIP header 2205 contains at least: a certificate for the target, that is, a target NSID (name space identifier) 2215 and a target MKID (master key identifier) 2213 for the certificate of the access filter 403 (3); And the certificate for the source, the pillow is the source NSID2219 and the source MKID2217a of the rover 503 certificate. In addition, the SKIP header 2205 contains: the algorithm for authenticating messages (MACALG2226) and the algorithm for encrypting messages (CRYPTALG2225 ) 'And an encrypted transport key (Kp2223) used to decrypt the message and an identifier 2224 for the algorithm used to decrypt the transport key.
Authentication header 2211: The authentication header 2211 contains a message authentication code (MAC for short) 222-it is calculated based on the MAC algorithm identified in field 2226; and it is used by the access filter 403 (3) To verify: the message arrived without intervention.
Encrypted Payload 2227 Encrypted Payload 2227 contains known encrypted messages that trespasser 503 is sending to server 407, which includes: IP header 2331 for the message, and encrypted message 2229-IP header 2331 It has: an rP address for the server 407, and a call number for the HTTP protocol service. The encrypted payload-}} '1-rGGGI can be decrypted by using the transfer key Kp2223s with the decryption algorithm specified by CRYPTALG (Cryptographic Algorithm Identifier) 2225.
Process SKIP message 2201
3 Processing SKIP Message 2201
SKIP message 2201 arrives at Internet interface 2011 at access filter 403 (3). Message processing starts at the SHIM level in the core level 2005. SHIM2017 will send all incoming traffic to 511SKIP2021, and it will perceive according to the MT field 220 $ in sequence: the message is a kind of SKIP. To decrypt and authenticate the message, SKIP needs to decrypt the transmission key Kp2223, and what it has to do is: it will provide SNSID2219, SMKID2217, DNSID2215, and DMKID2213 to SKIPd2037, and SKIPd will use these IDs to quickly access and store the certificate from SKIPd2037 A cache (cache) is retrieved against the rover 503. The certificate of the access filter 403 {3), if the certificate is not there, SKIPd2037 uses the CDP communication protocol to extract the certificate. Then, use the information button access filter 403 (the private key of the blade together in the certificate; in order to generate a shared secret value, and then use this value to decrypt the transmission key Kp2223, and then generate two internal keys: Akp and Ekp-SKIP will safely store the shared secret value for use with future messages, because the calculation of this value takes a considerable amount of time. Second, calculate the MAC for the entire received message and use Akp with MAC2221 & MACALG2226 In order to verify that the entire SKIP message 2201 has not been intervened. If this is the case, the internal key Ekp is used to decrypt the encrypted payload 2227 in order to recover the original message from the diffuser 503. The decrypted payload 2227 is then provided to IP filter 2019, it will apply some of its rules to: source IP address, destination IP address, and port number of IP header 2231. If there is no rule to deny access operation, then IP filter 2019 follows another rule And redirect unencrypted messages along with SNSID2219 and SMKID2217 to the port for HTTP proxy server. IP Filter 2019 uses MMF2301 DBServicePortToProxyPort file to find the port being talked about.
Processing of messages continues at the application level in the user level 2003 of the operating system. The HTTP proxy server can grasp: the IP address of the server, the port number of the service, the URL for the web page, the certificate of the user who belongs to Man 503, and the encryption method used to encrypt the message. It uses the evaluation program 2036 to determine the following based on MMF2301:
Many user groups to which the user represented by the certificate belongs; many information sets to which the web page belongs;
Whether there is an access decision will allow at least one user group in many user groups to access at least one information set in many information sets; and whether the trust level of the message is at least equal to the sensitivity level of the web page.
Starting from the first of these tasks, the evaluation program 2036 will receive the NSID and MKID for the certificate and use the certificate matching criteria of the certificate with the DBCertificatesByUserGroup file to obtain the "many user groups of the user who is sending the message The identifier of the group.
The evaluation program 2036 determines the information set by adopting: the IP address of the server, the port number of the service, and the URL of the web page; and uses: DBServerIDByIP (identify the other 11 databases by IP addresses) Server ID ") IP address of the file to determine the server that contains the webpage. The port number of the file with DBServiceIDByPort (identified by the port number to the other 11 database" Service ID ") determines the server to provide services. Server service, and the URL of the file with the DBResourceIDbyName (database "resource ID" identified by IP name) to get the identifier for the information set to which the web page belongs. With the ability to grasp: for user groups and information sets, the identifiers in database 301, the evaluation program 2036 uses the DBResources file to determine whether an access decision will allow any user group to which the user belongs to store Get any info set that the page belongs to. In doing so, it may only consider groups of users whose membership is determined using a recognition pattern whose trust level is sufficient for the sensitivity level of the resource. "DBResources files The set identifier maps to: There will be some PJ tables for one of the many user groups for which the access decision for this resource set is targeted. For each user group, the DBResources file will further indicate whether the decision allows or Access denied. Evaluator 2036 uses the DBResources file to determine sequentially for each information set to which the page belongs: there will be some of the many user groups for which the access decision about the information set is f. Does the J table include one user group among a plurality of user groups to which the user belongs. If there is an access decision denied access operation for any user group, the evaluator instructs the HTTP proxy server: the access operation is denied; if no access decision is made for any user group, the access operation is denied And at least one decision allows the access operation, the evaluator indicates to the HTTP proxy server: the access operation is allowed; if there is no access decision of any kind for any user group, the evaluator will decide: There will be a certificate or token-based group of users with an admissible decision on a resource. If this is the case, and a uIC (user identification customer comparison) is being performed on the requesting client computer: then the UIC is requested to request additional identification information from the user. If additional identification information comes back, the above process is repeated. In other cases, the evaluator instructs the HTTP proxy server that the access operation was denied.
Of course, if the access request does not have a trust level equal to the sensitivity level of the webpage, the evaluation program 2036 will also deny the access operation. The evaluation program 2036 obtains the sensitivity level of the webpage from the case of DBResoureesByResoureeID, obtains the trust level of the user identification method from the DBTrustAuthentications (database "Trust Level Authentication") file, and obtains the trust level from DBTrustEncryPtioos (database "Trusted Encryption") Obtain the trust level of the encryption method in the file. Since SK Kun has used a method of "confidential" to encrypt the message, the trust level of the path through the network has nothing to do with this example. It is necessary to decide whether the trust level for the user identification and encryption method is sufficient for the sensitivity level of the web page; the evaluation program 2036 will use DBTrustT which effectively constructs the SEND table 601. bl. file. If the trust level is sufficient, the evaluation program 2036 instructs the proxy server that the access operation is allowed.
Once the proxy server has confirmed that it intends to allow access to the information resources contained in the message; the proxy server will initiate a new dialogue for the actual service: HTTP service on server 407. The proxy server 2031 sends a special message to the IP filter 2019, telling it: allow a specific conversation to pass; this is because 'In other cases, this conversation may be blocked by some rules, or sent to Proxy server. The message for IP filter 2019 also includes information about the encryption method required for the new conversation. In this example, the information is: for the last access filter 403 (5), the conversation should be encrypted; and it should be used Suitable for data sensitivity level Shen is a confidential encryption method. When IP Filter 2019 encounters a new conversation, it will find that because the conversation matches the criteria set by the proxy server 2031, it will pass the conversation to the SKIP module. Because encryption is necessary for this conversation, the message will be re-encrypted. Except for the following items, the SKIP module 2021 generates a SKIP message 2201 in the same manner as described above:
The outer IP header 2203 for the message states that: the access filter 403 (3) is used as the source of the message, and the access filter 403 (5) is used as the destination of the message;
The SKIP header 2205 has: SNSID2219 and SMKID2217 for the access filter 403 (3); and DNSID2215} tDMKID2213 for the access filter 403 (5); and other values in the header 2205 are: The source and destination are now those values required for access filter 403 (3) and access filter 403 (uniform facts;
The encrypted payload 2227 is the same as before (except that it has been encrypted using a different key; and MAC2221 is generated for the entire new message 2201 if necessary.
While the proxy server is relaying messages, it is also looking at the types of ad hoc transmissions that may contain viruses. When it encounters a virus, it applies antivirus software 2033 to these files. If the file contains a virus, the proxy server fails to deliver the complete file so that the virus is not harmful. If the access control database 301 instructs this, the proxy server will send a warning message when the anti-virus software 2033 detects a virus.
When the SKIP message 2201 is received at the access filter 403 (5), litAlf is passed to the SKIP module 2021, where it is decrypted as described previously. Regarding the access filter 403 (3), through the same mechanism as described above, the IP filter 2019 on the spoon realized that the message is assigned to the HTTP application protocol, so it will The message is directed to the HTTP proxy server 2031. The proxy server will accept the message: it will then deduct the SKIP header 2205 from the external IP header 2203 and it will be able to obtain information about the originator of the message (access filter 3403 (3)) and send 911- 0Evaluate program 2036 in order to determine whether the conversation being encouraged by this message should be allowed to continue. "Evaluate program 2036 will review the source IP address of the message and other identifying information; and by detecting the DBServerIDByIP file in the MMF file To determine the source IP address in: the identifier in the database 301 for the access filter 403 (3); use the identifier to indicate the location of the certificate of the access filter 403 (3); and To: The certificate information matches the retrieved certificate, which is related to the message of the access filter a403 (3) being processed. "The access filter 403 (3) of the source of the message is therefore considered to be in VPN201. one The filter 403 is taken, so the evaluation program 2036 responds that the conversation should be allowed, because it is a message that is already allowed by another accessor 403 in the same VPN 201, and this decision will allow the message Switch back to the HTTP proxy server 2031. The evaluator 2036 will instruct the access filter 403 (the HTTP proxy server 2031 on the child: for the same reason, any request from the same conversation is allowed. When the HTTP request is During processing, the proxy server establishes an output communication connection with the HTTP service on the server 407 in the same manner as the output session is established on the access filter 403 (3).
When starting the communication connection with the server 407, the evaluation program 2036 will find the server 3407.zIP address in the DBServerIDByIP file of the MMF file in order to determine: For the server 407, the identifier in the database 301: use This identifier indicates the location of the server table; it then uses the certificate identification and DBCertificates (Database '"Certificate") file from this table to find the certificate for server 407. It then uses the access filter 403 (3 ) Key and the public key (obtained from the certificate) for the server 407 to construct a SKIP conversation, as described earlier. The actual message is encrypted. The authentication, the SKIP header 2205 is added, and the external IP is added. Header 2203, thus directing the message to server 407.
When the message reaches the server 407, the SKIP pillow in the server 407 will: check the authentication information about the message, decipher it, and then forward the decrypted message to the HTTP service; the service will perform access: Web pages requested by messages in the payload. Having obtained a web page, the HTTP service will generate a return message with an IP header specifying the roamer 503 as the target. Then, this switch-back message is encapsulated in a SKIP message 2201, which was described earlier by the woman. This SKIP message is directed to the access filter 403 (5), and the information contained in the outer title 2203 and the SKIP title 2205 is necessary for the information between those entities.
When the reply message touches the access filter 403 (5), the SKIP module 2021 pillow there will identify and decrypt it, and send it to the IP filter 2019. The message was found to match an existing conversation, so no evaluation was necessary; it was therefore forwarded directly to the HTTP proxy server 2031. In that case, it is treated as an HTTP protocol reply message to check the validity, and then it is retransmitted back to the originator of the access filter 403 (3) z.HTTP conversation. Since it is understood that the initiator of this conversation may be another access filter 403 in VPN 201, the checking operation of the anti-virus module 2033 will not be performed, just as it is known that the access filter will perform the checking operation when necessary. Uses many SKIP parameters necessary for the message exchange between the access filter 403 (3) and the access filter 403 (5). Through the SKIP module 2021, the retransmission of the reply message is processed again, and it is Enforce the second secret, ru u mentioned above.
When this answer message came to the access filter 403 (3), exactly the same thing happened, that is, the message passed through the SKIP module 2021 and the IP adapter 2019 to the '1 HTTP proxy server 2031. In that case, check it as an HTTP communication protocol reply message to check the validity; possibly through the anti-virus module 2033 (if the content type of the message is guaranteed to it); and then re-transmit it back to the person who is said to be invader Initiator of HTTP session 503. For a message 503 being sent from the access filter 403 (3) to the diffuser, use Ru. The SKIP parameters announced above, through the SKIP module 2021, process the transmission of the reply message again, and then the woman. Encrypt it as described above, and then receive the reply message at Drifter 503; where: use SKIP to authenticate and decrypt the message, provide the message to the user s browser, and display it for the user.
General rules of many technologies used in access filter 203
Many techniques used in the access filter 203 have been generalized in two ways:
Separating decision evaluation and decision execution, it will allow entities other than access filters to execute decisions; and the decision database now allows not only definitions: users, user groups, resources, and resource groups; but also definitions : Many new user identification types, which may define many new action types for decision-making, and many new resource types.
The discussion below will first describe how it is possible to separate decision evaluation and decision execution, and then describe how the many types that can be used to define decisions can be expanded.
Separate decision evaluation and decision execution: Figures 20, 26, & 27 Figure 26 is a block diagram of a decision execution system 2601, where decision evaluation and decision execution have been separated. In system 2601, the notion of decision has been generalized, not only including: access decision, management decision, and decision making decision; but also: any action that a user may perform on an information resource. For example, a decision might state that a particular user group might print out some file systems 2601 that belong to a particular information set with five main components:
Requesting entity 2603, which will request an action to be performed on an information resource, and it may be any entity that can belong to a user group; decision executor 2609, which can control the effectiveness of the requested action; many resources 2611 (0 ,. .., n) It may be: any information that can be accessed or controlled by the decision implementer 2609; a decision server 2617, which decides: whether the action is allowed; and a decision database 2619, which contains many decisions, a decision server The device 2617 decides whether the action is allowed based on the decision.
The requesting entity 2603, the decision executor 2609, and the decision server 2617 can each be located anywhere. The only requirement is that there is a message transmission medium between the requesting entity 2603 and the decision executor 2609 and between the decision executor 2609 and the decision server 2617. The media between the requesting entity 2603 and the decision executor 2609 allows the requesting entity 2603 to send a message 2605 requesting an action to be performed on a resource R2611 (i) to the decision executor 2619 and to receive a message from the decision executor 2609 Action response message 2607, which indicates: whether to take action, and if such a result. The media between the decision executor 2609 and the decision server 2617 allows the decision executor 2609 to send a decision request 2613 to the decision server 2617, thus requesting the instruction from the decision server 2617; in the decision server database 2619 Whether many of the decisions allow a given requesting entity to take a given action relative to a given resource; and request the decision server 2617 to respond to the decision request 2613 with a decision response 2615, which indicates whether the many decisions will allow Actions in decision requests. It should be further noted that the actions controlled by the decision implementer 2609 do not even need to be performed by a component of the computer system. "Many decisions in the decision database may be controlled by library patrons to access the books. The action specified in the decision may be a library web page with a book extracted from the bookshelf.
The format of the decision request message 2613 and the decision response message 2615 are defined by a decision communication protocol. "An example of some standard decision communication protocols that are currently being developed is: Common Open Decision System (COPS). This system Xu is available online: Squid as described on June 21, 1999, the URL is: http: //www.ietf.or only / internet-drafts / draft-ietf-rap-cops-06.txt 'and in Remote Authentication Dialing in User Service (RemoteAuthenticationDialInUserService, RADIUS for short; Reference: x Internet Standard No. RFC2138).
The decision server 2617 obtains the information needed to generate a decision response 2615 and then provides the response to the decision executor 2609. The decision server 2617 includes a decision server database 2619 containing a number of decisions. The decision includes: one or more decisions for a requesting entity 2603 that has requested the decision executor 2609 to perform an action on a resource 82611 (i). The server 32617 will query the decision server database 2619 to point out some relevant decisions, and then apply them to the decision request 2613. Doing this may require the decision server 2617 to access from any Other decision-related information is obtained in the location 2623. An example of such a process is: the technique described in the discussion of the access filter 203; by this technique, the access filter 203 obtains additional information about the user Identification information. If the information obtained by the decision server 2617 from the decision server database 2619 and other resources indicates that action is allowed, the decision server 2617 sends a decision response 2615 instructed by this, and the decision executor 2609 executes Deduct the action indicated at 2610, and return the result to the requesting entity 2603 via action response 2607; if determined 2615 in response to instructions: Action not allowed, then the implementation of decision 2609 sends an indication of the action was not permitted to act in response to 2607.
An important advantage of separating the decision implementer 2609 from the decision server 2617 is that it is possible to construct the decision implementer 2609 at many different levels in the system. It is understood that the system includes a system composed of many devices connected to the network. . The decision server 2617 may contain decisions for any decision executor; therefore, actions that may be governed by that decision are no longer limited to actions taken at one or more levels of the system.
FIG. 27 shows a system 2701 having a plurality of components, and the components are connected through a network including a public network 2702 and an internal network 103. At the highest level, the system 2701 has: one or more policy decision points 2723, which determine whether a decision allows an action; and one or more decision execution points 2721, where many of the decisions are made by decisions Execute. The decision-making decision point will include a decision server 2617; and the decision execution point will include a decision enabling device, which is: a device capable of performing a function like the decision implementer 2609. The communication between the decision-making decision point and the decision-execution point is through the decision message 2725, which includes "decision request 2613 and decision response 2615." When an entity 2603 requests to use resource 82611 to perform an action, the action will be performed by a device controlled by decision execution point 2721. Decision execution point 2721 will exchange decision message 2725 with decision decision point 2723. In order to decide "whether the action is allowed: if so, the decision execution point 2721 will cause the action to be executed.
Among the many decision-enabling devices included in the system 2701 are: decision-enabling router 2713, which executes decisions at the level of routing guidance traffic in the physical network; decision-enabling subsidiary device 2719, which executes at Decisions at the level of a device attached to the network of system 2701. An example is a printer, which can check the decision server 2617 to determine whether to accept a print request from an entity 2603. The decision-enabling application 2717 is executed at the application level. Decision.
Each decision-enabling device processes decisions in the same way as described for the decision-executor 2609: when the decision-enabling device receives it, it must decide whether the action request complies with the When an action request 2703 for many access decisions is made, it sends a decision message 2725 to the decision server 2617; and when it receives a decision message, it responds, allowing or rejecting as indicated by the decision message Action.
Continue to discuss in more detail the level at which the decision enabling devices of FIG. 27 operate. The decision enabling router 2.713 may maintain a table of allowed sources and destinations for the many subcontracting information it routes; when routing 32713 When initialized, these tables are created based on the information provided by the decision server 2617; from then on, when the router 2713 receives a subcontracting message with a source or destination not in its table, it will A decision message 2725 is sent to a decision server 2617 indicating the source or target, and the decision server 2617 responds to the message by indicating whether the source or target is intended to be included in some tables. Of course, when a decision is made When the server database 2619 changes, some tables of the router 2713 may also be updated by the information sent by the decision server 2617 to the router 2713. As can be seen from the foregoing, the router 2713 will The 203 construction example 2001 performs the decision check at the level of the IP filter 2019.
The decision enabling accessory 2719 is a device such as a printer attached to a network. The device is capable of responding to a request made by an entity to use it with a decision message sent by the decision server 2617, and can proceed based on the information it receives from the decision server 2617. This decision-enabling accessory device 2719 would allow the jurisdictional details of these devices to be governed; the granularity of control is more elaborate than the access check at the level of access filtering 3203 may allow.
Finally, the decision-enabling application 2717 would allow decision execution at a level higher than the access filter 203 may allow "as long as the decision server database 2619 contains many resources that are being accessed by the application For decision-making information, the decision-enabling application 2717 can exchange decision information 2725 with the decision server 2617, so that it can decide whether to allow or deny the action being requested by the user of the decision-enabling application 2717. Decision-making An example of a capable application 2717 is: an application that builds an Internet service such as FTP, HTTP, or SMTP. This is the level handled by many proxy servers 2031 in Figure 20. Because services may now be all It is decision-enabled, so a proxy server is no longer necessary; instead, it can only pass the Internet communication protocol to the system where the service exists, and the service will provide the access operation requested by the communication protocol. As shown in Figure 27, the service can then personally exchange decision messages 2725 with the decision server 2617 in order to decide that the requested access operation is No should be especially promised.
Another example of a decision enabling application 2717 is: a document processing program. In this case, the decision server database 2619 may contain decisions that specify a collection of users who have the authority to modify a collection of files. When the user uses the program to select a document for editing, the document processing program can exchange the decision message 2725 with the decision server 2617 and if the decision response instruction from the decision server 2617 indicates that the user may not modify the document ; The document handler may instruct the user and refuse to allow the user to modify the document.
As can be seen from the foregoing, the separation of decision evaluation from decision execution and the extensible nature of decision definition actually collectively allow: any operation a program can perform on a resource becomes the subject of a decision; thus, making access Control systems are like those shown in Figure 27: Not only are they scalable and easy to manage, they are also easily adapted to any current or future device or program.
It should be noted here that in the access filter 203, the decision evaluation and decision execution are logically separated, even if both are included in the same device. When reviewing view 20 according to FIG. 26, it is obvious that "GUI 1915; startup, login, alert and report module 2027; database shared directory 2028: ISDB management program 2027: PCS 2025; and MMF 2301 will build a decision server 2617; and The remaining components are constructed as decision implementers 2609 that operate at the IP filter and Internet protocol level.
General Principles of Decision "Figure 28
In the access filter 203, an administrator who appropriately accesses information; can define new users and user groups, can define new resources and information sets, and can add services and servers. Administrators cannot define actions that are different from accessing information. Also, the methods anyone can use to define new user groups are fixed, and resources are limited by the source of the information. In the generalized decision server of the preferred embodiment, these restrictions have been lifted. It is now up to the administrator to define: new actions, new methods for defining user groups, and resources that are not information sets are possible. Of course, the right to make these definitions is itself determined by the decisions in the decision server database 2619, as explained with regard to the management decisions and decision maker decisions in the access filter 203. In most systems, the definition: many types of entities, types of resources, and types of operations should be limited to only those who belong to the "security officer" user group.
These new possibilities are illustrated in a generalized decision syntax 2801 for the decision statement shown in FIG. 28. The generalized decision syntax 2801 describes how to present a decision to an administrator in a window targeted at a possible manipulation decision. In Figure 28, items in italics are part of many decision statements that may be defined by the administrator of the decision server 2617, who has the right to access the decision server database 2619. Items in parentheses are groups of words that make the items in italics relevant to defining a decision. Police + Q said,
EmployeesareallowedtoAccesstheHRWebSite (Employees are allowed to access HR website information) Among them: Employees is a user group, Access is an action, r7nHRWebSite (HR website), J is an information set; This decision statement allows any user belonging to the "employees" user group to access any resource belonging to the "HR Website" information set.
Continue to discuss the generalized decision syntax 2801 in more detail. Entity represents a group of users whose members are: one of many technologies used in the access filter 203; or a decision server 2617 is defined by a technology defined by the administrator. The only requirement for the entity is that it must be recognizable by the decision executor 2609.
Action means; it may be just an action like the access operation in the access filter 203, or an action defined by the administrator of the decision server 2617. The only requirement for action is "to enable the decision executor 2609 to perform an action on a resource. Resource represents a set of information. However, in a generalized decision server, a set of information may be such as a printer or One of the many devices of the file server. The only requirement for the resource is to enable the decision executor 2609 to perform actions on the resource.
TimeIntervals 2809 allows administrators to define a temporal restriction on decisions that are being specified using the generalized decision syntax 2801 when decisions are being evaluated to determine whether a given user has access to a given When resources are available, a time-interval decision is considered only if the evaluation time is within the interval. For example:
EmployeesareallowedtoAccesstheHRWebSitefrom 9 am to 5 pm weekdays (employees are allowed to access HR website information weekdays: from 9 am to 5 pm) It will limit the time for employees to access the HR website to normal business hours. In a preferred embodiment, the time interval may be defined as follows:
The range of the beginning and end of each working day; the range of the beginning and end of the working day; restrictions on weekly working days and holidays; the option to include specific working days of the week and / or the dates listed as holidays Or 44 except for; weekly work week restrictions: allow weekly, every x weeks from the reference date (where x is a number from 2 to 12), or within each applicable month The weekly table is regulated; the monthly table applies every year.
ActionAttribute (s) 2811 are some administrator-defined definitions that are likely to implement the method used by the decision statement. Furthermore, the only requirement is that the decision implementer 2609 is capable of performing the action as stated in the attribute of the action. Police girl. Say;
MarketingisallowedtoprinttotheMarketingPrinterwithtype = color (marketers are allowed to come to India using a marketer with a color marketer of Print '1) This decision contains the action attribute type = color Users in the Marketing user group use the resources of a marketer's printer to perform color printing.
Many additional examples of mobile attributes are: the type of service required for the network communication connection: the type of route or media that is intended to be used; the billing rate that is intended to apply; the maximum number of this transaction; the maximum time allowed to complete the transaction.
Can use time interval and action attributes, as well as with the entire decision statement, as indicated by the syntax [with; when] (with every time) *] io, an item that sets a time limit on the type of service The decision looks like this: (EveryoneisallowedtoaccesstheWorldWideWebwithbandw; dth = 90% whenweekends (everyone is allowed to access World Wide Web information with bandwidth = 90% every weekend) This decision allows users in "everyone" Entities in the group say access to World Wide Web information with bandwidth = 90% every weekend. When the time interval has been applied to the mobile attribute, although a request to perform an action is made within the time interval applied to the mobile attribute In order to execute the actions set out in decision-making as they are set out in the attribute of the action.
Construction example of generalized decision: Figures 29 and 30
Figure 29 shows the decision database 2901. The decision database 2901 is a modification of the decision database 301; in order to adapt to the generalized decision defined by the grammar 2801, and operates in an environment where decision evaluation and decision execution have been separated. Thus, in FIG. 29, the decision query 2939 is from the decision server 2 and not the access filter 203, and thus includes; a specifier of the action to be performed, and a source of information or the action to be performed by the action. Specification of other resources targeted. In addition to returning the result of the decision query 2941 to the decision server 2617, in addition to an indication of whether the action is allowed, the result now also includes the attribute value associated with the action. Many of the units in FIG. 3 that remain unchanged in function in FIG. 29 have the reference numbers they have in FIG. 3. It is said that from the access decision 3) 07, the first additional item of information is the access type definition 2929, which will define: many additional action categories, and it is possible to define the decision in the access decision 307 for it. Second, there will be attribute information 2927, which will define attributes that may be attached to many entities involved in carrying out a decision. Included in the attribute information 2937 are the following various types of information:
Attribute designation 2937, which will indicate what is intended to be used with the attribute; user group, information set, website, or service; attribute tag 2941, which will be defined; in the user interface] is well known Many attribute names; and attribute characteristics 2939, which actually define '; how attributes affect many user groups specified by it, and so on.
Schedule information 2925 will be defined. A time interval that may be attached to a decision or attribute. In the schedule information 2925, the schedule rule 2931 actually defines the time interval; and the holiday table 2933 is a holiday table used in the schedule rule. Resource type 2935 will define: the type of resource for which the decision may be defined, and user ID type 2937 will define: the type of identification method required for the entity for which the decision may be defined.
In a preferred embodiment, the database 2901 is constructed using a company well known: Microsoft. Access Database. Access is a relational database, that is: the information in the database is stored in some tables. A utility in the access software will provide: the images of some tables and their relationship to each other Figures 13 to 17 and 30 in this application are derived from those images. In Figure 30, some of the tables appearing in Figures 13 to 17 have the reference numbers they have in those figures; some new tables have reference numbers that start with 113011. Tables 3001 in FIG. 30 show how some tables used to define time intervals and attributes can be integrated into the decision database 2901. More generally, they show how a decision can be governed by adding additional units, and how many new unit types can be defined for the decision.
Detailed construction example of time interval
Starting from time intervals, these time intervals are defined in the time interval table 3025. The table includes: a schedule definition table 3023, which will define names that may appear in Timelnterval (s) 2 $ 09 in the generalized decision syntax 2 $ 01; and a schedule rule table 3025, which will define The names in the "Schedule Definition" table 3023 have associated scheduling rules. More than one schedule rule may be associated with a given name. ScheduleDeflD (Schedule Definition ID) makes each schedule rule defined in Table 3025 related to the schedule using the rules in Table 3023 " ItDayMask (Workday Masking-PIEndDate (End Date). Many fields will define the schedule. The "Description" field describes the rules and their purpose.
As mentioned below, time intervals may be defined for the entire decision and for attributes in the decision. Thus, each decision defined in the "Access Decision" table 1611 now includes a ScheduleDeflD field. Each such column will contain: a ScheduleDeflD identifier defined in one of the tables 3023 for a time interval intended to be applied to a decision. Therefore, when the decision server 2617 is deciding whether a decision is applicable to an action request, by: in the entries in the table 1611 for decision, the ScheduleDeflD field for the time interval; it can indicate the application to The location of the time interval for a decision. Similarly, the "attribute designation" table 3007 will associate attributes with: user groups, resource sets, websites, or services; the table includes: a ScheduleDefID column for any time interval applicable to that particular attribute designation Bit. Finally, the mechanism used to define the time interval is also used in a preferred embodiment for scheduling alert information; therefore, many of the entries in Table 3023 can also be changed from "AlertSchedules" Arrangement) The position is indicated in Table 3021.
Example of detailed construction of attributes
Some tables that will be used to define a number of attributes and relate them to what may be applied: user groups, resource groups, websites, and services are shown in the attribute table 3003 in FIG. 30. A given attribute is defined by three types of tables: the "attribute tag" table 3005, the "attribute" table 3011, and the entries in the "attribute specific" table 3009. An "attribute tag" table 3005 will define: tags for attributes in ActionAttribute (s) within the decision definition syntax 2801. Each such tag will have a posting item, which includes: the tag itself, the description of the attribute, the precedence of the tag, and the type of the attribute. The priority of the tags defines which attributes will be applied when more than one attribute is connected to the decision evaluation. When a designation has a higher priority than another designation, the designation with a lower priority is ignored. Each attribute tag posting is identified by an "AttributeLabelID".
Each posting in the "Attributes" table 3011 contains the current definition of the attribute. The definition may have one or more "attribute tag ID" fields used to identify entries in the "attribute tag" table 3005. The tag defined by the entry in the "attribute tag" table 3005 indicates the attribute defined by the entry in the "attribute" table 3011. The current meaning of attributes is defined by some fields in Table 3011. Includes: description of the attribute, its type, the ID of the server to which it applies, and the device type of the server. Three fields: "AttributeFeatureID", "valuel", and "Value2" are fields of particular interest. There must be at least one "AttributeFeatureID" field in that wrap. This field will identify one of the entries in the "Attribute Characteristics" table 3009, and the table will define the types and ranges of the many values used in the attribute. "Value1" IL, "Value2" will define: the current range of a single value (Valuel), or the current range of two values (both Value1 and Value2); this value is selected from the attributes in Table 3009. The types and ranges of many values defined.
As will be apparent from the foregoing, the "attribute characteristics" table 3009 can be used to define many new attribute types. Each entry in the table 3009 includes an "attribute characteristic ID" identifier and some fields to indicate the location of the entry:
Category: The category to which the attribute belongs, another name (such as: service quality checkout rate, or the maximum number of transactions): feature ID: a number that uniquely defines the feature within its category; name: the user uses it to Understand the name of the feature; Description: A description of the feature; Value type: A definition of the type of many values that define the attribute (such as saying: whether a single value or a pair of values is required, and the type of data): An indication of order in which a number of characteristics are applied to the evaluation attributes in accordance with the order: numerical precedence; an indication of whether the highest or lowest value in the range is intended to be selected; and restriction: an indication of a restriction on the value.
To define new attribute categories, the administrator who is allowed to do so by the decision server 2617's decision simply defines the characteristics for the new category in the "Attribute Characteristics" table 3009, and then begins to define the attributes that use those characteristics. One feature may be: Anything that is meaningful to the decision executor 2609 that is about to make decisions. It should be noted here that "some of the above-mentioned general techniques that may be used to define many new attribute types are used in decision materials. Library 2901 elsewhere to define many; new actions, new methods to identify users, and new resource types.
Once an attribute has been defined by the information in three tables: 3005, 3011 & 3009, it will be related to the asset to which an attribute may be applied. Call this entity; the subject of the attribute. The "Attribute Assignment" table 3007 sets out these relationships. Each entry in table 3007 will associate the attribute stated in its "AttributeLabelID" with a single subject; moreover, it may associate the attribute with a user group, and the Members of the user group may perform an action involving the subject. If the posted item does not specify a user group, the attribute is applied to any use of the subject; in other cases, the attribute is only applied when the user group is specified to use the subject. The subject may be; a user group, a resource set, a website, or a service; an image with many fields. The values for "User Group ID", "Resource Group ID", "Site ID", and "Server ID" are specified. Other fields in table 3007 indicate whether the attribute is active (ie; intended to be currently applied), when the application should start, when it expires, and whether the attribute involves a time interval. The "ScheduleDefID" for the time interval "Value. The "priority" field indicates; among the many attributes assigned to a given entity, the priority that the attribute will have.
In deciding which attributes to use in making a decision, the decision server 2617 proceeds as follows; when the decision evaluation is completed, it targets any user group, resource group, website, or service that is relevant to the decision evaluation. A plurality of communication links are searched for the attribute designation information in the table 3007. If the entity performing the action belongs to one of the user groups targeted by the attribute application, it will follow the Shido communication link specified by the attribute in the table 3007, and it will come to the attribute tags in the table 3005, and sequentially The attributes in table 3011 finally come to the attribute characteristics in table 3009. Each of these linked tables (except table 3011) contains priority information, which is used to determine: For those attributes that are found along all communication links, there are "some" in table 3011 Attributes will actually be applied to decision evaluation.
These priorities are considered individually for each category of attributes, as defined by the attribute characteristics in Table 3009. Within each category, consider first: the priority in the attribute assignments in table 3007. Although all assignments that share the same priority will be considered, only those assignments with the highest priority value will be considered further. Secondly, consider: For the remaining linked attributes, the tag priority in the attribute tag in table 3005. Although all tags that share the same tag priority will be considered, only those with the highest priority value will be considered further. Secondly, consider: for the linked attributes of its bell, the features in the entry in the "attribute features" table 3009 take precedence. Only those attributes that share the highest feature priority will be retained. Finally, for each attribute in table 3011, the attribute is hammered to the same entry in the "attribute characteristics" table 3009; the numerical priority in the "attribute characteristics" table 3009 is prioritized by indicating the intention to choose The highest or lowest value is used to decide which attribute from Table 3011 to use.
At this time, for many related attribute and feature posting items in Table 3009, at most one attribute defined in Table 3011 will remain intact, and the values and characteristics in these posting items will be reversed for use in Evaluate decisions. In some cases, the request may indicate what attribute values are required; and if they do not match those stated in the decision, the request may be rejected: in other cases, many attribute values are provided to the decision Implement 2609 for use in performing operations.
The optimization of the attribute table 3003 and the time interval table 3025 enables decision servoing in a preferred embodiment as described in the above discussion of the access filter 203 and illustrated in Figures 21 and 23 The processor 2617 optimizes the decision database 2901 by generating a plurality of MMF files 2303 therefrom. In the preferred embodiment, two new MMF files have been added to optimize the information in table 30034a3025. Two new MMF files:
DBProperties (Database "Properties") file: Contains all "Properties"-properties and schedules that can be applied to other objects. This index is indexed by the "characteristic TD" in those other objects.
DBPropertiesMetaData (Database 'Properties Metadata',) file: All properties have a name. This file is indexed by the property type name (for each property name contained in the DBProperties file, it is included in the index Has a post): and maps some names to a list of many feature ZDs, so that they are quickly detected in the DBProperties file.
User interface for time intervals: Figures 31 to 33 Figures 31 to 33 show: In a preferred embodiment, the window used in the graphical user interface is used to: see what time interval (or time course) is Schedule) has been defined, defining a rule for a time interval and using a time interval to be associated with a decision. Starting from Figure 31, the figure shows: a window used to display the defined schedule 3102P subwindow 3103 will display all the defined schedules according to the name bad "; and the subwindow 3106 will be based on the name List all defined rules. The displayed information is from: "Schedule Definition" Table 3023, "Schedule Regulation," Table 3025.
To see what kind of rule the schedule name indicates, the user will choose the name in the sub-window 3103, as shown at 3105, where "non-working time" has been selected. This schedule has two composition rules: one for each weekday, displayed at 3107; one for Saturday, Sunday, and holidays, displayed at 3109. When choosing the name of the schedule, it belongs to it (many; rules will be highlighted in Shigu 3106. Conversely, when selecting a rule, the name of the schedule for many schedules using the rule will be highlighted. Displayed at 3111 in sub-window 3106: Rules for business hours: while displayed in sub-window 3103: some other schedule names.
To generate a new schedule, when the sub-window 3103 is in the active state, click the "Add" button and enter the name of the new schedule; then select the new schedule and add some rules that belong to it Highlighted in the sub-window 3102. To change some rules assigned to a schedule, first select the schedule name, and then select a different rule for that name in subwindow 3106. To generate a new rule for an existing schedule, first select the name of the schedule and click the "Add" button. A new rule may be created at that time, female. Described below. When in the sub-window 3106, you can also click the "Add" button to generate a new rule, and then make the new rule related to a schedule name, as described above. By dragging a rule to a schedule name and discarding it on the schedule name, a rule can also be related to a schedule name.
The window used to generate a new rule is shown at 3201 in Figure 32. This is the window used to modify an existing rule or generate a new rule. To modify an existing rule, double-click it. Entering information in the window will allow the user to: define the time interval being applied to the decision or attribute based on the validity of the scheduled time (3203), define the weekly working day (320) in which the selected time is valid Young, defines the work week in which the schedule is valid (3207), and defines a part of the year in which the schedule is valid (3209). As shown in the figure, the window 3201 defines the schedule shown in Figure 31 at 3111 The schedule is indicated by "business hours". The information displayed in window 3201 comes from the "scheduling rules" table 3025, and many modifications made using window 3201 are applied to the table.
Figure 33 shows the window used to add time intervals to the definition of a decision. Windows 3301 restricts access to the "Community" information set by many users belonging to the "Corporate" user group to the schedule of "business hours" indicated at 3303. When the user clicks on the box 3303 , The entire list of many defined schedules will be displayed, so the user may choose one or add a new name. When the user clicks the "define" button 3305, it will display the Window 3201. If a new name is being added, the user will fill out the window 3201 for the new schedule if necessary. According to Figure 301, one of the schedules shown in Figure 33 will be used. A "SCheduleDefID" field is filled in: the identifier for the entry in the "Schedule Definition" table 3023; and Table 3023 includes the schedule name in its "Name" field. If the schedule name is new, a new entry is added to table 3023 for the new name. If a rule is added or modified, the "Schedule for Schedule" table 3025 will also be modified.
User interface for attributes: Figures 34 to 37 are similar for user interface definitions and assignments for attributes. Figure 34 shows: a window 3401 listing many currently defined attributes of the quality of service (QOS) type. These attributes determine how much bandwidth is available for an access operation that is being performed according to a given decision. . At 3401, '11 shows some attribute tags or names. Here, four types of QOS attributes are defined: three types indicate the amount of bandwidth ("high", low 'one ("highest priority") indicates priority if there is a conflict. All of these attributes have one. The priority order is as shown at 3405. Many bandwidth attributes are all defined by the "bandwidth" feature, which is displayed at 3407. The "value" for each attribute is defined at 3409. Only " Only the highest priority will have a value of 2. As stated in Windows 3401, the Q0SM wide attribute: "High" will receive 5120000. The maximum bandwidth, "Medium" will receive the maximum frequency of 64000 Wide, and "low" will receive a maximum bandwidth of 32000. Regarding "highest priority", the priority stated in the attribute must be in the two values specified in "value 1" and "value 2" The information in window 3401 is of course from the three tables 3005, 3011, and 3009.
Figure 35 shows "window 3501 used to assign a QOS attribute to a user group, collection, website, or service. In sub-window 3503, it shows" What has happened to all user groups (3507)? Assign "Q", "High", and "Low" three QOS bandwidth attributes (3509) to the World Wide Web Service, File Transfer Service, and Remote Access Service (3511) and how to set the "High" 11QOS priority attributes are assigned to "Finance", the user group subject. Many different assignments reflect the fact that bandwidth is an attribute of a communication service, and priority is an attribute of one of the users of the communication service Therefore, within the bandwidth available for network services, many members of the "Pei Cai Wu" user group have high priority. As shown by this example, more than one mobile attribute may be applied to A decision "If the theme-specific attributes can be generated by selecting some user groups from the two sub-windows 3513 and 3515, respectively, the attribute designation will be facilitated. The selections made in this window will of course be applied to the "attribute designation" table 3007. Windows 3503 can be further used in the same general way as window 3102 touches many windows used to define attribute marks and characteristics.
Figure 36 shows a window 3601 "for reading, repairing, or generating" attribute tags ", one of the entries in Table 3011. Here, the entry being read is for" Qos bandwidth attribute "in" ". At 3603, the values of the "tag", "description", and "tag priority" fields of the posted items are displayed. Administrators with appropriate access rights can of course change the values of these fields through window 3601. At 3605, display: for the attributes associated with the tag, the information from the entry in the "attributes" table 3011. The current value of "value 1" in the entry and the name of the feature are displayed there The feature name is of course from the "attribute feature" table 3009 for the attribute. Furthermore, these values may be edited via window 3601. Button 3607 is used to view a window that will display: in the "attribute feature" table 3009 Features the full content of the published items.
FIG. 37 shows that the window "window 3701 is used to define many new attributes for a given attribute category and many new attribute categories. Of course, the window will operate according to the value of one of the entries in the" Attribute Characteristics table 3009. Block 3703 is a list of one of many attribute categories; a new category may be defined by adding to the list. Box 3705 is the name of the current feature; a posting item is uniquely identified between them (category and name), and the category and name correspond to the "category" and "name" of many postings in Table 3009 Fields. In this case, the posting item is for the Q priority attribute "{Priorityattribute)." Description "box 3707 will contain the value of" Description "in the posting item being viewed. 3709 indicates what type of value the characteristic has. Here is a pair of values, female. Indicated in Figure 34. At 3711, the current set values of the two fields "Characteristic Priority" and "Value Priority" are displayed; while at 3713, any restriction information appears.
in conclusion
3 conclusions
The previous description has been for those who are familiar with the skills related to the description "the best model for constructing a universal decision server, which is currently many developers of the universal decision server Well-known. The two basic characteristics of the universal decision server described above are: the separation of decision evaluation from decision execution, and the scalability of the many types of actions that can be made for decisions. About the evaluation of decisions and decisions Separation of implementation, many decision execution components may be located at different levels in the system to which the decision is applied; and many decision evaluation components may be located far from the positions of many decision components.
Although the techniques used to separate decision evaluation from decision execution, as well as techniques that can perform many types of actions to make decisions scalable, may be applied to any mechanism used to define them; however, when the technology is used in terms of some actions and They are particularly useful when a collection of entities is used to define a decision in some decision execution systems. In these systems, it is also possible that the types of entities that can perform actions and the types of entities to which actions are performed are extensible.
Other features of the decision execution system disclosed herein that would increase the usefulness of the system are: action attributes, which define the manner in which an action is intended to be performed by one of the decision authorizations and the time interval; the time interval will define: The time when a decision is valid or when an attribute is applied to an action. A graphical user interface provides easy definitions and manipulations of many decisions and their components.
As will be immediately apparent to those skilled in the arts, many of the techniques described here may be applied to any kind of decision-making system; and even in a manner described here The techniques that are most useful in decision execution systems that define decisions may also be constructed in many different ways. For example, different graphical user interfaces may be used, different database systems may be used to construct decisions; and within a given database system, many different table arrangements may be used. Therefore, the many principles disclosed here are infinite. Other embodiments are possible; and, for this reason, in all aspects, it is intended to treat "reports" as a model "without limitation; The breadth of the present invention disclosed here does not come from "statements," but from the scope of a patent application, as explained using the full range of coverage covered by patent law.
Figure 1 is an overview of many technologies used to control access to information via the Internet;
Figure 2 is an overview of a VPN (Virtual Private Network) using one of the many access filters incorporated in the technology disclosed herein;
FIG. 3 is a general cable of an access control database used in an access filter; FIG.
Figure 4 shows access check and tunneling operations in a VPN using one of the many access filters incorporating the technology disclosed herein;
Figure 5 shows the information in a VPN accessed by a "roamer";
Figure 6 is a table used in defining the relationship between sensitivity and trust levels and many authentication and encryption technologies;
Figure 7 is an example of applying SEND (Secure Encrypted Network Delivery) technology;
Figure 8 is a flowchart of a decision-making process;
FIG. 9 shows a display diagram for defining a user group;
FIG. 10 shows a display diagram for defining an information set;
FIG. 11 shows a display diagram for defining an access decision;
FIG. 12 shows a display diagram for defining an access filter 203;
13A and 13B are each a part of a schema defining an access control database 301 for a user group;
FIG. 14 is a diagram of one part of an access control database 301 defining an information set;
FIG. 15 is a diagram of one part of the access control database 301 defining the sites in the VPN and the servers, services, and resources at each site;
16A and 16B are diagrams each forming a part of an access control database 301 defining a decision;
17A, B, and C are diagrams each forming a part of the access control database 301 of the server;
Figure 18 shows the display used in the IntraMap interface.
Figure 19 shows how changes are made to the access control database 301;
FIG. 20 is a detailed block diagram of one of the architectures of the access filter 203;
FIG. 21 is a schematic diagram of a structure of an MMF (Memory Map File) file 2303; FIG.
FIG. 22 is a schematic diagram of a message sent using a SKIP (Simple Key Management for Internet Protocol) protocol;
23A, B, and C are a table of MMF files used in a preferred embodiment;
FIG. 24 is a schematic diagram of a construction example of the IntraMap interface; FIG.
25 is a diagram illustrating one of delegations in the VPN 201;
Figure 26 is a block diagram of an action control system that has separated decision checking and decision execution;
FIG. 27 is a block diagram of an action control system with various policy-enabled devices; FIG.
Figure 28 shows a syntax for defining generalized decisions;
FIG. 29 shows the total cable of the decision database 2901 in a preferred embodiment;
FIG. 30 shows an example of constructing many attributes and time intervals in the decision database 2901;
FIG. 31 shows a window listing all defined schedules;
FIG. 32 shows a window for defining a scheduling rule used in a preferred embodiment; FIG.
FIG. 33 shows a window used to apply a time interval to a decision in a preferred embodiment; FIG.
FIG. 34 shows a window for displaying attributes used in a preferred embodiment; FIG.
Figure 35 shows a window used to assign attributes to a subject in a preferred embodiment;
FIG. 36 shows a window for displaying and modifying an attribute definition in a preferred embodiment; and
FIG. 37 shows a window for displaying and modifying a feature definition in a preferred embodiment.
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| TWI493367B | Cited by | Taiwan Province of China | Examiner |
| US7561530B2 | Cited by | United States of America | Applicant |
55 members in 11 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 60091130 | United States of America | – | |
| 9113098 | United States of America | P | |
| 19980091130P | – | – | – |
| US19980091130P | – | – | – |
Members55
| Document | Office | Kind | |
|---|---|---|---|
| WO9840992A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU6452798A | Australia | A | |
| WO9840992A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO9941405A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2758899A | Australia | A | |
| EP0966822A2 | European Patent Office (EPO) | A2 | |
| WO0000879A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU4838699A | Australia | A | |
| WO0000879A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US6105027A | United States of America | A | |
| EP1054996A1 | European Patent Office (EPO) | A1 | |
| AU5755300A | Australia | A | |
| US6178505B1 | United States of America | B1 | |
| AU733109B2 | Australia | B2 | |
| EP1105809A2 | European Patent Office (EPO) | A2 | |
| TW448387BThis record | Taiwan Province of China | B | |
| US6277626B1 | United States of America | B1 | |
| TW464812B | Taiwan Province of China | B | |
| US2001055798A1 | United States of America | A1 | |
| US6408336B1 | United States of America | B1 | |
| JP2003517266A | Japan | A | |
| AU762061B2 | Australia | B2 | |
| US6638758B2 | United States of America | B2 | |
| EP1054996B1 | European Patent Office (EPO) | B1 | |
| AT258604T | Austria | T | |
| ATE258604T1 | Austria | T1 | |
| DE69914458D1 | Germany | D1 | |
| DK1054996T3 | Denmark | T3 | |
| PT1054996E | Portugal | E | |
| US6785728B1 | United States of America | B1 | |
| ES2216495T3 | Spain | T3 | |
| DE69914458T2 | Germany | T2 | |
| EP1105809A4 | European Patent Office (EPO) | A4 | |
| US7272625B1 | United States of America | B1 | |
| US2008028436A1 | United States of America | A1 | |
| US2008172366A1 | United States of America | A1 | |
| US7580919B1 | United States of America | B1 | |
| US7821926B2 | United States of America | B2 | |
| US7912856B2 | United States of America | B2 | |
| US2011072135A1 | United States of America | A1 | |
| US2011231443A1 | United States of America | A1 | |
| US8136143B2 | United States of America | B2 | |
| US2012198232A1 | United States of America | A1 | |
| US2013346751A1 | United States of America | A1 | |
| US2014047232A1 | United States of America | A1 | |
| US2014059645A1 | United States of America | A1 | |
| US2014059646A1 | United States of America | A1 | |
| US8914410B2 | United States of America | B2 | |
| US8935311B2 | United States of America | B2 | |
| US9154489B2 | United States of America | B2 | |
| US9276920B2 | United States of America | B2 | |
| US9331992B2 | United States of America | B2 | |
| US9438577B2 | United States of America | B2 | |
| US2017118221A1 | United States of America | A1 | |
| USRE46439E | United States of America | E |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A | |
| Issue of patent certificate for granted invention patentGrantedGD4A | GD4A |
Numbers
- Publication
- 448387
- Publication, DOCDB
- 448387
- Publication, EPODOC
- TW448387B
- Application
- 88110985
- Application, DOCDB
- 88110985
- Application, EPODOC
- TW19990110985
Titles5
- English
- Generalized policy server
- Chinese
- 一般化決策伺服器
- English
- "GENERALIZED POLICY SERVER"
- Unlabeled
- 一般化決策伺服器
- Unlabeled
- Generalized decision server
Classification
- CPC, 1
- G06F21/6236
- IPC, 1
- H04L29 06