CN102215597A - Access policy management method and device - Google Patents

Access policy management method and device Download PDF

Info

Publication number
CN102215597A
CN102215597A CN2011101420976A CN201110142097A CN102215597A CN 102215597 A CN102215597 A CN 102215597A CN 2011101420976 A CN2011101420976 A CN 2011101420976A CN 201110142097 A CN201110142097 A CN 201110142097A CN 102215597 A CN102215597 A CN 102215597A
Authority
CN
China
Prior art keywords
access
accessed
information
equipment
strategy
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN2011101420976A
Other languages
Chinese (zh)
Other versions
CN102215597B (en
Inventor
黄婉清
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
New H3C Technologies Co Ltd
Original Assignee
Hangzhou H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou H3C Technologies Co Ltd filed Critical Hangzhou H3C Technologies Co Ltd
Priority to CN201110142097.6A priority Critical patent/CN102215597B/en
Publication of CN102215597A publication Critical patent/CN102215597A/en
Application granted granted Critical
Publication of CN102215597B publication Critical patent/CN102215597B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

The invention discloses access policy management method and device. By using the technical scheme provided by the invention, in access policies corresponding to an access condition satisfied by a device to be accessed, the access policy with top priority is selected to be applied to the device to be accessed, so that the optimal access policy combined with various dimensional authorities is automatically selected by combining various combinable dimensional conditions, and the selection of the access policy of the device to be accessed is realized. The access policy selection of the device to be accessed is more flexible, a better matched access policy is selected for the device to be accessed, and the automatic management of access policies is realized.

Description

A kind of access strategy management method and equipment
Technical field
The present invention relates to communication technical field, particularly a kind of access strategy management method and equipment.
Background technology
Network insertion control technology scheme is made up of Security Policy Server, aaa server, access device and the software that accesses terminal etc.At first carry out authentication when accessing terminal access network, and according to the access rules information of configuration, to the user authorize, function such as binding.Control it by access device and can only visit a limited network area (being called " isolated area "), carry out safety certification then, access terminal and meet safety requirements and just remove it and isolate restriction when Security Policy Server detects this, allow other Internet resources of terminal access.
As shown in Figure 1, be the typical networking schematic diagram of a network insertion control technology scheme of the prior art.
Prior art is carried out the setting of different access network authorities (equipment side inserts control of authority, as ACL, VLAN etc.) according to zone, different on-position (different access devices and different client ip address).
In realizing process of the present invention, the inventor finds that there is following problem at least in prior art:
For inserting, prior art is just carried out the differentiation of access conditions at the on-position regional perspective, and for authorizing, prior art has just limited the access network authority of equipment side.
Summary of the invention
The invention provides a kind of access strategy management method and equipment, solve the problem that access device carries out the flexible management of access strategy of how treating.
For achieving the above object, one aspect of the present invention provides a kind of access strategy management method, specifically may further comprise the steps:
Access management product receives the access request that equipment to be accessed sends, and carries the pairing information of described equipment to be accessed in the described access request;
The access conditions that described access management product is satisfied according to the described equipment to be accessed of the pairing information inquiry of described equipment to be accessed;
Determine described equipment to be accessed when described access management product and satisfy at least one access conditions, and described at least one access conditions correspondence during a plurality of access strategy, described access management product is determined described equipment to be accessed is used the highest access strategy of priority or access strategy combination according to the pairing precedence information of described a plurality of access strategies.
Preferably, described access conditions specifically comprises one of following information or multinomial:
The on-position area information;
User side information;
Equipment side information;
Turn-on time information.
Preferably, described on-position area information specifically comprises the identification information of the on-position area relative access device under the described equipment to be accessed and/or the pairing IP address information of described equipment to be accessed;
Described user side information specifically comprises the mac address information of described equipment to be accessed and/or the pairing wireless SSID information of described equipment to be accessed;
Described equipment side information specifically comprises the type information of the on-position area relative access device under the described equipment to be accessed;
Described turn-on time, information comprised that specifically described equipment to be accessed sends the temporal information of described access request.
Preferably, described access strategy comprises one of following information or multinomial at least:
The authorization message of equipment side;
The authorization message of server side;
The function restriction of described equipment to be accessed;
Default security strategy function restriction.
Preferably, the authorization message of described equipment side specifically comprises the authorization message of VLAN, and/or default ACL information;
The authorization message of described server side specifically comprises the attribute information that described access management product is bound;
The function restriction of described equipment to be accessed specifically comprises the network access restrictions strategy to the equipment of the pairing type of described equipment to be accessed.
Preferably, described access control equipment is specially:
Aaa authentication server, and/or Security Policy Server.
Preferably, described access management product is determined described equipment to be accessed is used the highest access strategy of priority or access strategy combination according to the pairing precedence information of described a plurality of access strategies, specifically comprises:
When existing at least two pairing precedence informations of access strategy identical, described access management product is determined described equipment to be accessed is used the access strategy combination that described at least two access strategies are formed.
On the other hand, the present invention also provides a kind of access management product, specifically comprises:
Receiver module is used to receive the access request that equipment to be accessed sends, and carries the pairing information of described equipment to be accessed in the described access request;
Enquiry module is used for the access conditions that is satisfied according to the received described equipment to be accessed of the pairing information inquiry of equipment described to be accessed of described receiver module;
Determination module, be used for determining that when described enquiry module described equipment to be accessed satisfies at least one access conditions, and described at least one access conditions correspondence during a plurality of access strategy, according to the pairing precedence information of described a plurality of access strategies, determine described equipment to be accessed is used the highest access strategy of priority or access strategy combination.
Preferably, described access management product is specially:
Aaa authentication server, and/or Security Policy Server.
Preferably, described determination module specifically is used for:
When described enquiry module inquires the pairing precedence information of at least two access strategies of existence when identical, determine described equipment to be accessed is used the access strategy combination that described at least two access strategies are formed.
Compared with prior art, the present invention has the following advantages:
By using technical scheme of the present invention, in the pairing access strategy of the access conditions that equipment to be accessed satisfied, select the highest access strategy of priority to be applied in this equipment to be accessed, thereby, automatically select to have made up the optimum access strategy of various dimension mandates in conjunction with the condition of combinable various dimensions, selection with the access strategy of realizing equipment to be accessed, make the access strategy of equipment to be accessed select more flexible, for the access strategy that choice of equipment to be accessed is mated more, realize the automatic management of access strategy.
Description of drawings
Fig. 1 is the typical networking schematic diagram of a network insertion control technology scheme of the prior art;
Fig. 2 is the schematic flow sheet of a kind of access strategy management method proposed by the invention;
Fig. 3 is the schematic flow sheet of access strategy management method under a kind of concrete application scenarios proposed by the invention;
The on-position area configurations schematic diagram of Fig. 4 for being proposed in the embodiment of the invention;
Fig. 5 is the configuration schematic diagram of the service Back ground Information that proposed in the embodiment of the invention;
Fig. 6 is the configuration schematic diagram of the access strategy that proposed in the embodiment of the invention;
Fig. 7 is the structural representation of a kind of access management product proposed by the invention.
Embodiment
As stated in the Background Art, access strategy Managed Solution of the prior art exists more single to the management and the application scheme of access strategy, can't realize the defective of the access strategy management of various dimensions.
In order to overcome such problem, the present invention proposes a kind of access conditions, the scheme of the automatic management of the access strategy of realization various dimensions in conjunction with various dimensions.
As shown in Figure 2, be the schematic flow sheet of a kind of access strategy management method proposed by the invention, this method specifically may further comprise the steps:
Step S201, access management product receive the access request that equipment to be accessed sends, and carry the pairing information of described equipment to be accessed in the described access request.
The equipment to be accessed here specifically refers to insert the equipment that inserts of asking by sending, and concrete device type can't influence protection scope of the present invention.
The access conditions that step S202, described access management product are satisfied according to the described equipment to be accessed of the pairing information inquiry of described equipment to be accessed.
Wherein, in concrete application scenarios, access conditions specifically comprises one of following information or multinomial:
(1) on-position area information specifically comprises the identification information of the on-position area relative access device under the described equipment to be accessed and/or the pairing IP address information of described equipment to be accessed.
(2) user side information specifically comprises the mac address information of described equipment to be accessed and/or the pairing wireless SSID information of described equipment to be accessed.
(3) equipment side information specifically comprises the type information of the on-position area relative access device under the described equipment to be accessed.
(4) turn-on time information, comprise that specifically described equipment to be accessed sends the temporal information of described access request.
In concrete application scenarios; concrete access conditions can adopt the combination of above-mentioned any or multiple condition; concrete employ or which are planted the access conditions content change that access conditions brought; and the concrete form of the above-mentioned information that is adopted; can adjust according to actual needs, such variation does not influence protection scope of the present invention.
Step S203, determine described equipment to be accessed when described access management product and satisfy at least one access conditions, and described at least one access conditions correspondence during a plurality of access strategy, described access management product is determined described equipment to be accessed is used the highest access strategy of priority or access strategy combination according to the pairing precedence information of described a plurality of access strategies.
Wherein, in concrete application scenarios, access strategy comprises one of following information or multinomial at least:
(1) authorization message of equipment side specifically comprises the authorization message of VLAN, and/or default ACL information.
(2) authorization message of server side specifically comprises the attribute information that described access management product is bound.
(3) function of equipment to be accessed restriction specifically comprises the network access restrictions strategy to the equipment of the pairing type of described equipment to be accessed.
(4) default security strategy function limits.
In concrete application scenarios; concrete access strategy can adopt the combination of above-mentioned any or multiple condition; the content change of concrete employ or which kind access strategy that access strategy brought or access strategy combination; and the concrete form of the above-mentioned strategy that is adopted; can adjust according to actual needs, such variation does not influence protection scope of the present invention.
Need further be pointed out that, the concrete manifestation form of above-mentioned access control equipment can for:
Which kind of form aaa authentication server, and/or Security Policy Server specifically take to adjust according to actual needs.
In the actual application of step S203, when existing at least two pairing precedence informations of access strategy identical, described access management product is determined described equipment to be accessed is used the access strategy combination that described at least two access strategies are formed.
Compared with prior art, the present invention has the following advantages:
By using technical scheme of the present invention, in the pairing access strategy of the access conditions that equipment to be accessed satisfied, select the highest access strategy of priority to be applied in this equipment to be accessed, thereby, automatically select to have made up the optimum access strategy of various dimension mandates in conjunction with the condition of combinable various dimensions, selection with the access strategy of realizing equipment to be accessed, make the access strategy of equipment to be accessed select more flexible, for the access strategy that choice of equipment to be accessed is mated more, realize the automatic management of access strategy.
In order further to set forth technological thought of the present invention, existing in conjunction with concrete application scenarios, technical scheme of the present invention is described.
The present invention proposes the access strategy management method of various dimensions, automatically the access strategy (access strategy also is the combination of various dimension authorization messages) of selecting client to use in conjunction with various dimension conditions, when having a plurality of access strategy that satisfies condition, filter out optimum access strategy by the priority setting.
Wherein, select the concrete processing mode of the operating process of access strategy to be exemplified below automatically in conjunction with various dimension conditions:
Can pass through zone, on-position (different access devices, different client ip address etc.), the user profile of user side (different client mac address, different wireless SSID etc.), device-dependent message (as different device types etc.), and the different time (different insert period) wait and select access strategy automatically.
The access strategy of the combination of wherein each kind of dimension authorization message can comprise equipment strategy mandate, server authorizes and according to mandate of client functionality etc.
Further, technical scheme proposed by the invention can also be expanded access conditions:
Access conditions can be the combination of various dimension conditions, such as zone, on-position (different access devices, different client ip address etc.), user side information (different client mac address, different wireless SSID etc.), equipment side information (as different access device type etc.) and time angle (different access periods) or the like.
On the other hand, technical scheme proposed by the invention is also expanded access strategy:
The authorization message that access strategy slave unit side is different (VLAN, ACL etc.), to the mandate (binding different attribute etc.) of server side and client functionality restriction (anti-Intranet outreach etc.) and different security strategy function restriction etc.
According to above-mentioned technical thought, in concrete enforcement scene, aaa authentication server and Security Policy Server can be searched needs use access strategy (equipment side mandate, server authorizes and client functionality restriction) according to various dimension conditions (zone, on-position, user side information and time angle) and priority, and client is used this access strategy.
In order to realize above-mentioned technical scheme, need in network system, to carry out in advance the configuration of the access strategy of corresponding various dimensions, corresponding layoutprocedure specifically comprises as shown in Figure 3:
Step S301, division zone, on-position are divided into different zones, on-position to access device.
In the present embodiment, corresponding on-position area configurations schematic diagram as shown in Figure 4.
Step S302, division insert the IP group of addresses, insert MAC Address group and wireless SSID group of addresses.
Step S303, different access period of division.
For example every day 8:30~17:00 and every day 17:00~24:00.
Step S304, the different access rules of division.
Access rules comprises different authorization message (as VLAN, ACL etc.), different authentication binding information, different client configuration information (anti-Intranet outreach etc.).
Step S305, the different security strategy of division.
Comprise different isolation ACL and security acl, functions such as terminal security software, controlled software group.
Step S306, configuration service Back ground Information, and be the different different access strategies of access conditions combining and configuring, access strategy comprises access rules, different security strategy and priority.
Accordingly, as shown in Figure 5, be the configuration schematic diagram of the service Back ground Information that proposed in the embodiment of the invention, as shown in Figure 6, be the configuration schematic diagram of the access strategy that proposed in the embodiment of the invention.
After the layoutprocedure of having finished above-mentioned access strategy, if access management product receives the access request that an equipment sends, then according to inserting the access conditions that entrained this equipment of information inquiry is satisfied in the request, and select the access strategy of limit priority therein, this equipment is used, corresponding processing procedure does not repeat them here with reference to the explanation of aforesaid step S201 to the step S203.
By above-mentioned setting, in the process for the service of access user applies, this user just can use different access strategies different conditions (research and development are distinguished and distinguished with clothes).And for identical zone, different clients or different periods or different wireless SSID etc. insert, and also can use different access strategies.
Compared with prior art, the present invention has the following advantages:
By using technical scheme of the present invention, in the pairing access strategy of the access conditions that equipment to be accessed satisfied, select the highest access strategy of priority to be applied in this equipment to be accessed, thereby, automatically select to have made up the optimum access strategy of various dimension mandates in conjunction with the condition of combinable various dimensions, selection with the access strategy of realizing equipment to be accessed, make the access strategy of equipment to be accessed select more flexible, for the access strategy that choice of equipment to be accessed is mated more, realize the automatic management of access strategy.
In order to realize technical scheme of the present invention, the invention allows for a kind of access management product, its structural representation specifically comprises as shown in Figure 7:
Receiver module 71 is used to receive the access request that equipment to be accessed sends, and carries the pairing information of described equipment to be accessed in the described access request;
Enquiry module 72 is used for the access conditions that is satisfied according to the described receiver module 71 received described equipment to be accessed of the pairing information inquiry of equipment described to be accessed;
Determination module 73, be used for determining that when described enquiry module 72 described equipment to be accessed satisfies at least one access conditions, and described at least one access conditions correspondence during a plurality of access strategy, according to the pairing precedence information of described a plurality of access strategies, determine described equipment to be accessed is used the highest access strategy of priority or access strategy combination.
Concrete, this access management product is specially the aaa authentication server, and/or Security Policy Server.
Further, described determination module 73 specifically is used for:
When described enquiry module 72 inquires the pairing precedence information of at least two access strategies of existence when identical, determine described equipment to be accessed is used the access strategy combination that described at least two access strategies are formed.
Compared with prior art, the present invention has the following advantages:
By using technical scheme of the present invention, in the pairing access strategy of the access conditions that equipment to be accessed satisfied, select the highest access strategy of priority to be applied in this equipment to be accessed, thereby, automatically select to have made up the optimum access strategy of various dimension mandates in conjunction with the condition of combinable various dimensions, selection with the access strategy of realizing equipment to be accessed, make the access strategy of equipment to be accessed select more flexible, for the access strategy that choice of equipment to be accessed is mated more, realize the automatic management of access strategy.
Through the above description of the embodiments, those skilled in the art can be well understood to the present invention and can realize by hardware, also can realize by the mode that software adds necessary general hardware platform.Based on such understanding, technical scheme of the present invention can embody with the form of software product, it (can be CD-ROM that this software product can be stored in a non-volatile memory medium, USB flash disk, portable hard drive etc.) in, comprise some instructions with so that computer equipment (can be personal computer, server, the perhaps network equipment etc.) each implements the described method of scene to carry out the present invention.
It will be appreciated by those skilled in the art that accompanying drawing is a preferred schematic diagram of implementing scene, module in the accompanying drawing or flow process might not be that enforcement the present invention is necessary.
It will be appreciated by those skilled in the art that the module in the device of implementing in the scene can be distributed in the device of implementing scene according to implementing scene description, also can carry out respective change and be arranged in the one or more devices that are different from this enforcement scene.The module of above-mentioned enforcement scene can be merged into a module, also can further split into a plurality of submodules.
The invention described above sequence number is not represented the quality of implementing scene just to description.
More than disclosed only be several concrete enforcement scene of the present invention, still, the present invention is not limited thereto, any those skilled in the art can think variation all should fall into protection scope of the present invention.

Claims (10)

1. an access strategy management method is characterized in that, specifically may further comprise the steps:
Access management product receives the access request that equipment to be accessed sends, and carries the pairing information of described equipment to be accessed in the described access request;
The access conditions that described access management product is satisfied according to the described equipment to be accessed of the pairing information inquiry of described equipment to be accessed;
Determine described equipment to be accessed when described access management product and satisfy at least one access conditions, and described at least one access conditions correspondence during a plurality of access strategy, described access management product is determined described equipment to be accessed is used the highest access strategy of priority or access strategy combination according to the pairing precedence information of described a plurality of access strategies.
2. the method for claim 1 is characterized in that, described access conditions specifically comprises one of following information or multinomial:
The on-position area information;
User side information;
Equipment side information;
Turn-on time information.
3. method as claimed in claim 2 is characterized in that,
Described on-position area information specifically comprises the identification information of the on-position area relative access device under the described equipment to be accessed and/or the pairing IP address information of described equipment to be accessed;
Described user side information specifically comprises the mac address information of described equipment to be accessed and/or the pairing wireless SSID information of described equipment to be accessed;
Described equipment side information specifically comprises the type information of the on-position area relative access device under the described equipment to be accessed;
Described turn-on time, information comprised that specifically described equipment to be accessed sends the temporal information of described access request.
4. the method for claim 1 is characterized in that, described access strategy comprises one of following information or multinomial at least:
The authorization message of equipment side;
The authorization message of server side;
The function restriction of described equipment to be accessed;
Default security strategy function restriction.
5. method as claimed in claim 4 is characterized in that,
The authorization message of described equipment side specifically comprises the authorization message of VLAN, and/or default ACL information;
The authorization message of described server side specifically comprises the attribute information that described access management product is bound;
The function restriction of described equipment to be accessed specifically comprises the network access restrictions strategy to the equipment of the pairing type of described equipment to be accessed.
6. the method for claim 1 is characterized in that, described access control equipment is specially:
Aaa authentication server, and/or Security Policy Server.
7. the method for claim 1 is characterized in that, described access management product is determined described equipment to be accessed is used the highest access strategy of priority or access strategy combination according to the pairing precedence information of described a plurality of access strategies, specifically comprises:
When existing at least two pairing precedence informations of access strategy identical, described access management product is determined described equipment to be accessed is used the access strategy combination that described at least two access strategies are formed.
8. an access management product is characterized in that, specifically comprises:
Receiver module is used to receive the access request that equipment to be accessed sends, and carries the pairing information of described equipment to be accessed in the described access request;
Enquiry module is used for the access conditions that is satisfied according to the received described equipment to be accessed of the pairing information inquiry of equipment described to be accessed of described receiver module;
Determination module, be used for determining that when described enquiry module described equipment to be accessed satisfies at least one access conditions, and described at least one access conditions correspondence during a plurality of access strategy, according to the pairing precedence information of described a plurality of access strategies, determine described equipment to be accessed is used the highest access strategy of priority or access strategy combination.
9. access management product as claimed in claim 8 is characterized in that, is specially:
Aaa authentication server, and/or Security Policy Server.
10. access management product as claimed in claim 8 is characterized in that, described determination module specifically is used for:
When described enquiry module inquires the pairing precedence information of at least two access strategies of existence when identical, determine described equipment to be accessed is used the access strategy combination that described at least two access strategies are formed.
CN201110142097.6A 2011-05-30 2011-05-30 A kind of access strategy management method and equipment Active CN102215597B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201110142097.6A CN102215597B (en) 2011-05-30 2011-05-30 A kind of access strategy management method and equipment

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201110142097.6A CN102215597B (en) 2011-05-30 2011-05-30 A kind of access strategy management method and equipment

Publications (2)

Publication Number Publication Date
CN102215597A true CN102215597A (en) 2011-10-12
CN102215597B CN102215597B (en) 2016-01-20

Family

ID=44746656

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201110142097.6A Active CN102215597B (en) 2011-05-30 2011-05-30 A kind of access strategy management method and equipment

Country Status (1)

Country Link
CN (1) CN102215597B (en)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2014135102A1 (en) * 2013-10-25 2014-09-12 中兴通讯股份有限公司 Wlan user management method, device and system
WO2014206152A1 (en) * 2013-06-27 2014-12-31 中兴通讯股份有限公司 Network safety monitoring method and system
CN104468552A (en) * 2014-11-28 2015-03-25 迈普通信技术股份有限公司 Access control method and device
CN104661262A (en) * 2013-11-19 2015-05-27 友讯科技股份有限公司 Wireless base station with multiple service setting identification codes and operation method
CN114189469A (en) * 2021-12-09 2022-03-15 重庆紫光华山智安科技有限公司 Public cloud multi-node device access routing method and system

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101155055A (en) * 2006-09-28 2008-04-02 华为技术有限公司 User management method and system for next-generation network
CN101335984A (en) * 2007-06-25 2008-12-31 华为技术有限公司 Household miniature base station access control method and system

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101155055A (en) * 2006-09-28 2008-04-02 华为技术有限公司 User management method and system for next-generation network
CN101335984A (en) * 2007-06-25 2008-12-31 华为技术有限公司 Household miniature base station access control method and system

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2014206152A1 (en) * 2013-06-27 2014-12-31 中兴通讯股份有限公司 Network safety monitoring method and system
WO2014135102A1 (en) * 2013-10-25 2014-09-12 中兴通讯股份有限公司 Wlan user management method, device and system
CN104581977A (en) * 2013-10-25 2015-04-29 中兴通讯股份有限公司 WLAN user management method, device and system
CN104581977B (en) * 2013-10-25 2019-01-15 中兴通讯股份有限公司 WLAN user management method, apparatus and system
CN104661262A (en) * 2013-11-19 2015-05-27 友讯科技股份有限公司 Wireless base station with multiple service setting identification codes and operation method
CN104661262B (en) * 2013-11-19 2018-07-03 友讯科技股份有限公司 Wireless base station with multiple service setting identification codes and operation method
CN104468552A (en) * 2014-11-28 2015-03-25 迈普通信技术股份有限公司 Access control method and device
CN104468552B (en) * 2014-11-28 2018-10-19 迈普通信技术股份有限公司 A kind of connection control method and device
CN114189469A (en) * 2021-12-09 2022-03-15 重庆紫光华山智安科技有限公司 Public cloud multi-node device access routing method and system

Also Published As

Publication number Publication date
CN102215597B (en) 2016-01-20

Similar Documents

Publication Publication Date Title
US20220078192A1 (en) Dynamic passcodes in association with a wireless access point
EP3651500B1 (en) Managing mobile device applications in a wireless network
EP2574090B1 (en) Managing mobile device applications
EP2574091B1 (en) Managing mobile device applications on a mobile device
KR101618041B1 (en) Method, module and ue for network access control
CN108337677B (en) Network authentication method and device
US9161225B2 (en) Authentication procedures for managing mobile device applications
CN101610156B (en) Dual protocol stack user authentication method, device and system
EP2658207B1 (en) Authorization method and terminal device
CN103746983A (en) Access authentication method and authentication server
US9369492B1 (en) Out-of band network security management
CN101990211B (en) Method for network access, device and system
CN104104516A (en) Portal authentication method and device
CN102215597A (en) Access policy management method and device
CN101651697A (en) Method and equipment for managing network access authority
US20190215690A1 (en) Processing Method for Terminal Access to 3GPP Network and Apparatus
WO2016165505A1 (en) Connection control method and apparatus
WO2017008580A1 (en) Method and device for wireless station to access local area network
CN112804679B (en) Network slice connection method and device, storage medium and electronic device
CN105744597A (en) Terminal and wireless connection method
WO2017219748A1 (en) Method and device for access permission determination and page access
CN101616414A (en) Method, system and server that terminal is authenticated
CN110933019B (en) Method for network policy management of foreground applications
CN105681352A (en) Wi-Fi access security control method and system
CN106572077A (en) Portal authentication method and device

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CP03 Change of name, title or address

Address after: 310052 Binjiang District Changhe Road, Zhejiang, China, No. 466, No.

Patentee after: Xinhua three Technology Co., Ltd.

Address before: 310053 Hangzhou hi tech Industrial Development Zone, Zhejiang province science and Technology Industrial Park, No. 310 and No. six road, HUAWEI, Hangzhou production base

Patentee before: Huasan Communication Technology Co., Ltd.

CP03 Change of name, title or address