发明名称 Method for providing user authentication/authorization and distributed firewall utilizing same
摘要 The distributed firewall performs user authentication at a first level to establish a user security context for traffic from that user, and an authority context provides authorization for subsequent traffic. This authority context may be based on an underlying policy for particular types of traffic, access to particular applications, etc. Additionally, the system includes the ability to allow a user/process/application to define its own access control. The linking of the user security context from the traffic to the application is accomplished by enabling IPSec on a socket and forcing the socket to be bound in exclusive mode. The most common policy definitions may be included by default. Extensions of the Internet key exchange protocol (IKE) to provide the desired user authentication plus application/purpose are also provided. The architecture includes pluggable authorization module(s) that are called after IKE has successfully authenticated the peer, but before the connection is allowed to complete.
申请公布号 US2003084331(A1) 申请公布日期 2003.05.01
申请号 US20010014747 申请日期 2001.10.26
申请人 MICROSOFT CORPORATION 发明人 DIXON WILLIAM H.;PALL GURDEEP S.;PALEKAR ASHWIN;ABOBA BERNARD D.;SWANDER BRIAN D.
分类号 H04L29/06;(IPC1-7):H04L9/00 主分类号 H04L29/06
代理机构 代理人
主权项
地址