首页> 外国专利> A access control system for security audit and control of server remote access session using encryption communication protocol

A access control system for security audit and control of server remote access session using encryption communication protocol

机译:一种使用加密通信协议对服务器远程访问会话进行安全审核和控制的访问控制系统

摘要

The present invention relates to an access control system for a security audit and control for a server remote access session based on an encryption communication protocol which controls corresponding access in accordance with a security policy when a user uses an encryption communication protocol (SSH, SFTP) to remotely access a server and perform a job for security management of the server in which the main information of an institution is loaded, and loads a job history for a subsequent audit. The access control system for a security audit and control for a server remote access session based on an encryption communication protocol comprises: a server handler to receive a hooked message of a communication application, perform key distribution with the communication application, and decrypt the hooked message of the communication application when the message of the communication application is hooked by a network hooking driver installed in a user terminal; a security policy inspection unit to determine whether to permit server access of the communication application, and analyze a decrypted message in accordance with a security policy to determine whether to permit the corresponding message; and a client handler to perform key distribution with the server when server access of the communication application is permitted, and encrypt the corresponding message with a key of an access control system to transmit an encrypted message when the corresponding message of the communication application is permitted. By the access control system, when using an encryption communication protocol (SSH, SFTP) to access a remote server, encrypted communication information is decrypted to perform security inspection and relay communication to control remote access, which cannot be executed in a parameter form, to improve convenience and strengthen security.
机译:本发明涉及用于基于加密通信协议的服务器审计和控制的远程访问会话的访问控制系统,该加密通信协议在用户使用加密通信协议(SSH,SFTP)时根据安全策略控制相应的访问。远程访问服务器并执行对服务器的安全性管理的工作,其中已加载了机构的主要信息,并为以后的审核加载了工作历史。基于加密通信协议的安全审计和服务器远程访问会话控制访问控制系统,包括:服务器处理器,用于接收通信应用程序的挂接消息,与通信应用程序进行密钥分发,并对挂接的消息进行解密当通过安装在用户终端中的网络挂钩驱动程序挂钩通信应用程序的消息时,通信应用程序的状态;安全策略检查单元确定是否允许服务器访问该通信应用,并根据安全策略分析解密后的消息,以确定是否允许相应的消息;客户端处理程序,当允许通信应用程序的服务器访问时,与服务器一起执行密钥分发;当允许通信应用程序的相应消息时,使用访问控制系统的密钥对相应消息进行加密,以发送加密消息。通过访问控制系统,当使用加密通信协议(SSH,SFTP)访问远程服务器时,加密的通信信息被解密以执行安全检查和中继通信以控制不能以参数形式执行的远程访问。提高便利性并加强安全性。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号