首页> 外国专利> System providing internet access management with router-based policy enforcement

System providing internet access management with router-based policy enforcement

机译:提供基于路由器策略实施的互联网访问管理的系统

摘要

A computing environment with methods for monitoring access to an open network such as the Internet, is described. The system includes one or more client computers, each operating applications (e.g., Netscape Navigator or Microsoft Internet Explorer) requiring access to an open network, such as a WAN or the Internet, and a router or other equipment that serves a routing function (e.g., a cable modem) for the client computers. A centralized security enforcement module on the router maintains access rules for the client computers and verifies the existence and proper operation of a client-based security module on each client computer. The router-side security module periodically sends out a router challenge via Internet broadcast to the local computers on the network. If the client-side security module is installed and properly operating, the client-side security module responds to the router challenge. The responses received by the router-side security module are maintained in a table. Each time the router receives a request from a client computer to connect to the Internet, the router-side security module reviews the table and analyzes whether or not the computer requesting a connection to the Internet properly responded to the most recent router challenge. If it determines that the computer has properly responded to the router challenge, then it permits the computer to connect to the Internet. If a computer has not properly responded or if a computer has not answered the router challenge, then the computer is not allowed to connect to the Internet as requested.
机译:描述了一种具有用于监视对诸如因特网之类的开放网络的访问的方法的计算环境。该系统包括一个或多个客户端计算机,每个操作应用程序(例如Netscape Navigator或Microsoft Internet Explorer)需要访问开放式网络(例如WAN或Internet),以及路由器或提供路由功能的其他设备(例如(电缆调制解调器))。路由器上的集中式安全实施模块维护客户端计算机的访问规则,并验证每台客户端计算机上基于客户端的安全模块的存在和正确运行。路由器端安全模块定期通过Internet广播向网络上的本地计算机发出路由器质询。如果客户端安全模块已安装且正常运行,则客户端安全模块将响应路由器质询。路由器端安全模块收到的响应保存在一个表中。路由器每次收到来自客户端计算机的连接到Internet的请求时,路由器端安全模块都会检查该表并分析请求连接到Internet的计算机是否正确响应了最新的路由器挑战。如果确定计算机已正确响应路由器询问,则它允许计算机连接到Internet。如果计算机没有正确响应,或者计算机没有回答路由器询问,则不允许计算机按要求连接到Internet。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号