首页> 外国专利> Authentication and entitlement for users of web based data management programs

Authentication and entitlement for users of web based data management programs

机译:基于Web的数据管理程序的用户的身份验证和权利

摘要

A double firewalled system is disclosed for protecting remote enterprise servers that provide communication services to telecommunication network customers from unauthorized third parties. A first router directs all connection requests to one or more secure web servers, which may utilize a load balancer to efficiently distribute the session connection load among a high number of authorized client users. On the network side of the web servers, a second router directs all connection requests to a dispatcher server, which routes application server calls to a proxy server for the application requested. A plurality of data security protocols are also employed. The protocols provide for an identification of the user, and an authentication of the user to ensure the user is who he/she claims to be and a determination of entitlements that the user may avail themselves of within the enterprise system. Session security is described, particularly as to the differences between a remote user's copper wire connection to a legacy system and a user's remote connection to the enterprise system over a "stateless" public Internet, where each session is a single transmission, rather than an interval of time between logon and logoff, as is customary in legacy systems.
机译:公开了一种双防火墙系统,用于保护向电信网络客户提供通信服务的远程企业服务器免受未经授权的第三方的攻击。第一路由器将所有连接请求定向到一个或多个安全的Web服务器,该服务器可以利用负载平衡器在大量授权的客户端用户之间有效地分配会话连接负载。在Web服务器的网络侧,第二个路由器将所有连接请求定向到调度程序服务器,后者将应用程序服务器调用路由到所请求的应用程序的代理服务器。还采用了多种数据安全协议。协议提供了用户的标识以及用户的身份验证,以确保用户是他/她声称的身份,并确定用户可以在企业系统中使用的权利。描述了会话安全性,特别是关于远程用户与遗留系统的铜线连接与用户通过“无状态”公共Internet到企业系统的远程连接之间的区别,其中每个会话都是一次传输,而不是一个间隔在登录和注销之间的时间间隔,这在旧系统中很常见。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号