CN108390874A - 网络结构中基于证书的访问控制模型及访问方法 - Google Patents
网络结构中基于证书的访问控制模型及访问方法 Download PDFInfo
- Publication number
- CN108390874A CN108390874A CN201810145458.4A CN201810145458A CN108390874A CN 108390874 A CN108390874 A CN 108390874A CN 201810145458 A CN201810145458 A CN 201810145458A CN 108390874 A CN108390874 A CN 108390874A
- Authority
- CN
- China
- Prior art keywords
- certificate
- node
- starting point
- access
- authority
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000000034 method Methods 0.000 title claims abstract description 32
- 238000013475 authorization Methods 0.000 claims abstract description 39
- 230000000977 initiatory effect Effects 0.000 claims abstract description 4
- 230000008569 process Effects 0.000 claims description 17
- FGUUSXIOTUKUDN-IBGZPJMESA-N C1(=CC=CC=C1)N1C2=C(NC([C@H](C1)NC=1OC(=NN=1)C1=CC=CC=C1)=O)C=CC=C2 Chemical compound C1(=CC=CC=C1)N1C2=C(NC([C@H](C1)NC=1OC(=NN=1)C1=CC=CC=C1)=O)C=CC=C2 FGUUSXIOTUKUDN-IBGZPJMESA-N 0.000 claims description 3
- 230000005540 biological transmission Effects 0.000 abstract description 5
- 230000000694 effects Effects 0.000 abstract description 4
- 230000033228 biological regulation Effects 0.000 abstract description 3
- 230000000644 propagated effect Effects 0.000 abstract description 2
- 230000006872 improvement Effects 0.000 description 6
- 238000005516 engineering process Methods 0.000 description 5
- 230000008901 benefit Effects 0.000 description 4
- 238000013461 design Methods 0.000 description 4
- 238000011161 development Methods 0.000 description 4
- 238000011160 research Methods 0.000 description 4
- 238000012795 verification Methods 0.000 description 4
- 238000007689 inspection Methods 0.000 description 3
- 238000000926 separation method Methods 0.000 description 3
- 238000004458 analytical method Methods 0.000 description 2
- 230000008859 change Effects 0.000 description 2
- 238000004891 communication Methods 0.000 description 2
- 238000010276 construction Methods 0.000 description 2
- 238000010586 diagram Methods 0.000 description 2
- 238000009826 distribution Methods 0.000 description 2
- 230000002452 interceptive effect Effects 0.000 description 2
- 230000001902 propagating effect Effects 0.000 description 2
- 230000007115 recruitment Effects 0.000 description 2
- 238000004088 simulation Methods 0.000 description 2
- 230000003068 static effect Effects 0.000 description 2
- 101100006982 Mus musculus Ppcdc gene Proteins 0.000 description 1
- 238000013459 approach Methods 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 230000015572 biosynthetic process Effects 0.000 description 1
- 238000010835 comparative analysis Methods 0.000 description 1
- 238000011217 control strategy Methods 0.000 description 1
- 230000008878 coupling Effects 0.000 description 1
- 238000010168 coupling process Methods 0.000 description 1
- 238000005859 coupling reaction Methods 0.000 description 1
- 230000007812 deficiency Effects 0.000 description 1
- 239000006185 dispersion Substances 0.000 description 1
- 235000013399 edible fruits Nutrition 0.000 description 1
- 230000001815 facial effect Effects 0.000 description 1
- 230000005484 gravity Effects 0.000 description 1
- 230000006698 induction Effects 0.000 description 1
- 230000003993 interaction Effects 0.000 description 1
- 238000004519 manufacturing process Methods 0.000 description 1
- 238000005259 measurement Methods 0.000 description 1
- 239000000203 mixture Substances 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 230000006855 networking Effects 0.000 description 1
- 238000005457 optimization Methods 0.000 description 1
- XEBWQGVWTUSTLN-UHFFFAOYSA-M phenylmercury acetate Chemical compound CC(=O)O[Hg]C1=CC=CC=C1 XEBWQGVWTUSTLN-UHFFFAOYSA-M 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
- 239000000047 product Substances 0.000 description 1
- 238000010845 search algorithm Methods 0.000 description 1
- 239000004575 stone Substances 0.000 description 1
- 239000013589 supplement Substances 0.000 description 1
- 230000000007 visual effect Effects 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/12—Discovery or management of network topologies
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/14—Network analysis or design
- H04L41/145—Network analysis or design involving simulating, designing, planning or modelling of a network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/101—Access control lists [ACL]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
- H04L9/3268—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Storage Device Security (AREA)
Abstract
Description
节点 | L | R | E |
A | - | C/D∈FriendListA | C/D∈FriendListA |
B | - | C/D∈FriendListB | C/D∈FriendListB |
I | A | - | A |
r1 | I,A,B | - | I∧A∧B |
节点 | L | R | E |
A | - | D∈FriendListA | D∈FriendListA |
B | - | D∈FriendListB | D∈FriendListB |
C | - | D∈FriendListC | D∈FriendListC |
I | A | - | A |
r1 | I,A,B | - | I∧A∧B |
r2 | r1,B,C | - | r1∧B∧C |
r3 | r2,A,C | - | r2∧A∧C |
r4 | A,C | - | A∧C |
Claims (6)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810145458.4A CN108390874B (zh) | 2018-02-12 | 2018-02-12 | 网络结构中基于证书的访问控制系统及访问方法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810145458.4A CN108390874B (zh) | 2018-02-12 | 2018-02-12 | 网络结构中基于证书的访问控制系统及访问方法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN108390874A true CN108390874A (zh) | 2018-08-10 |
CN108390874B CN108390874B (zh) | 2020-08-07 |
Family
ID=63069428
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201810145458.4A Active CN108390874B (zh) | 2018-02-12 | 2018-02-12 | 网络结构中基于证书的访问控制系统及访问方法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN108390874B (zh) |
Cited By (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109657111A (zh) * | 2018-12-20 | 2019-04-19 | 北京天融信网络安全技术有限公司 | 一种连通图的处理方法及装置 |
CN110611591A (zh) * | 2019-09-18 | 2019-12-24 | 重庆特斯联智慧科技股份有限公司 | 一种网络拓扑建立方法及装置 |
CN112333173A (zh) * | 2020-03-11 | 2021-02-05 | 合肥达朴汇联科技有限公司 | 基于数据提供方的数据传送方法、系统、设备及存储介质 |
CN117336101A (zh) * | 2023-11-29 | 2024-01-02 | 南京中孚信息技术有限公司 | 一种细粒度网络接入控制方法、系统、设备及介质 |
CN117792778A (zh) * | 2023-12-29 | 2024-03-29 | 北京观翌信息技术有限公司 | 一种互联互通系统、以及数据传输方法 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20080289036A1 (en) * | 2007-05-19 | 2008-11-20 | Madhusudanan Kandasamy | Time-based control of user access in a data processing system incorporating a role-based access control model |
CN101321064A (zh) * | 2008-07-17 | 2008-12-10 | 上海众恒信息产业有限公司 | 一种基于数字证书技术的信息系统的访问控制方法及装置 |
CN101997876A (zh) * | 2010-11-05 | 2011-03-30 | 重庆大学 | 基于属性的访问控制模型及其跨域访问方法 |
US20170163684A1 (en) * | 2015-12-08 | 2017-06-08 | Sap Se | Electronic access controls |
-
2018
- 2018-02-12 CN CN201810145458.4A patent/CN108390874B/zh active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20080289036A1 (en) * | 2007-05-19 | 2008-11-20 | Madhusudanan Kandasamy | Time-based control of user access in a data processing system incorporating a role-based access control model |
CN101321064A (zh) * | 2008-07-17 | 2008-12-10 | 上海众恒信息产业有限公司 | 一种基于数字证书技术的信息系统的访问控制方法及装置 |
CN101997876A (zh) * | 2010-11-05 | 2011-03-30 | 重庆大学 | 基于属性的访问控制模型及其跨域访问方法 |
US20170163684A1 (en) * | 2015-12-08 | 2017-06-08 | Sap Se | Electronic access controls |
Non-Patent Citations (3)
Title |
---|
ARINDAM KHALED 等: "A Token-Based Access Control System for RDF Data in the Clouds", 《2010 IEEE SECOND INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE》 * |
刘恒强: "基于属性证书的访问控制模型研究", 《中国优秀硕士学位论文全文数据库 信息科技辑》 * |
苏雪 等: "基于证书的服务组合动态访问控制策略", 《计算机应用与软件》 * |
Cited By (9)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109657111A (zh) * | 2018-12-20 | 2019-04-19 | 北京天融信网络安全技术有限公司 | 一种连通图的处理方法及装置 |
CN109657111B (zh) * | 2018-12-20 | 2023-03-14 | 北京天融信网络安全技术有限公司 | 一种连通图的处理方法及装置 |
CN110611591A (zh) * | 2019-09-18 | 2019-12-24 | 重庆特斯联智慧科技股份有限公司 | 一种网络拓扑建立方法及装置 |
CN110611591B (zh) * | 2019-09-18 | 2022-09-09 | 重庆特斯联智慧科技股份有限公司 | 一种网络拓扑建立方法及装置 |
CN112333173A (zh) * | 2020-03-11 | 2021-02-05 | 合肥达朴汇联科技有限公司 | 基于数据提供方的数据传送方法、系统、设备及存储介质 |
CN117336101A (zh) * | 2023-11-29 | 2024-01-02 | 南京中孚信息技术有限公司 | 一种细粒度网络接入控制方法、系统、设备及介质 |
CN117336101B (zh) * | 2023-11-29 | 2024-02-23 | 南京中孚信息技术有限公司 | 一种细粒度网络接入控制方法、系统、设备及介质 |
CN117792778A (zh) * | 2023-12-29 | 2024-03-29 | 北京观翌信息技术有限公司 | 一种互联互通系统、以及数据传输方法 |
CN117792778B (zh) * | 2023-12-29 | 2024-07-19 | 北京观翌信息技术有限公司 | 一种互联互通系统、以及数据传输方法 |
Also Published As
Publication number | Publication date |
---|---|
CN108390874B (zh) | 2020-08-07 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN108390874A (zh) | 网络结构中基于证书的访问控制模型及访问方法 | |
He et al. | Rethinking access control and authentication for the home internet of things ({{{{{IoT}}}}}) | |
CN104144158B (zh) | 用于基于策略的自动同意的方法和装置 | |
CN110050474A (zh) | 用于物联网网络中的复合对象的子对象的类型命名和区块链 | |
US9390243B2 (en) | Dynamic trust score for evaluating ongoing online relationships | |
Muir et al. | An exploratory study into the negotiation of cyber-security within the family home | |
Maratea et al. | Deviant identity in online contexts: New directives in the study of a classic concept | |
Ebner et al. | Fairness, trust and security in online dispute resolution | |
CN107911282B (zh) | 一种面向社交网络实现第三方应用植入的网络系统 | |
US8887248B2 (en) | JUBISM: judgement based information sharing with monitoring | |
KR20120087238A (ko) | 자원공유를 위한 소셜 네트워크 시스템, 이의 구축 및 유지방법 | |
Alexopoulos et al. | Towards secure distributed trust management on a global scale: An analytical approach for applying distributed ledgers for authorization in the IoT | |
Kaposi | The culture and politics of Internet use among young people in Kuwait. | |
Kohl | The net and the nation state: Multidisciplinary perspectives on internet governance | |
Zhao et al. | Zero trust access authorization and control of network boundary based on cloud sea big data fuzzy clustering | |
Santaniello et al. | Electronic regimes: Democracy and geopolitical strategies in digital networks | |
Kneuer et al. | Conceptualizing Authoritarian Gravity Centers: Sources and Addressees, Mechanisms and Motives of Authoritarian Pressure and Attraction 1 | |
Bailey et al. | Interoperability of social media: an appraisal of the regulatory and technical ecosystem | |
Liu et al. | The combination of pairwise and group interactions promotes consensus in opinion dynamics | |
Ziyi | International Law Protection of Cross‐Border Transmission of Personal Information Based on Cloud Computing and Big Data | |
Wang et al. | Public and Private Blockchain Infusion: A Novel Approach to Federated Learning | |
Pal et al. | Security, Privacy and Trust for the Metaverse of Things | |
Musiani | When social links are network links: The dawn of peer-to-peer social networks and its implications for privacy | |
Zhang et al. | GT‐Bidding: Group Trust Model of P2P Network Based on Bidding | |
Li et al. | Towards building a firm metaverse security base |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20231103 Address after: Room 10408, 4th Floor, Building B, Xi'an National Digital Publishing Base, No. 996 Tianguqi Road, High tech Zone, Xi'an City, Shaanxi Province, 710000 Patentee after: Shaanxi Fenghuo Yunji Information Technology Co.,Ltd. Address before: 101200 room 205-211526, No. 40, Fuqian West Street, Pinggu town, Pinggu District, Beijing (cluster registration) Patentee before: BEIJING YONGBO TECHNOLOGY CO.,LTD. Effective date of registration: 20231103 Address after: 101200 room 205-211526, No. 40, Fuqian West Street, Pinggu town, Pinggu District, Beijing (cluster registration) Patentee after: BEIJING YONGBO TECHNOLOGY CO.,LTD. Address before: 100124 No. 100 Chaoyang District Ping Tian Park, Beijing Patentee before: Beijing University of Technology |
|
PE01 | Entry into force of the registration of the contract for pledge of patent right | ||
PE01 | Entry into force of the registration of the contract for pledge of patent right |
Denomination of invention: Certificate based access control system and access methods in network architecture Effective date of registration: 20231229 Granted publication date: 20200807 Pledgee: Xi'an innovation financing Company limited by guarantee Pledgor: Shaanxi Fenghuo Yunji Information Technology Co.,Ltd. Registration number: Y2023980075523 |