CN106161438B - 为接口访问控制提供分层的安全防护的方法和设备 - Google Patents

为接口访问控制提供分层的安全防护的方法和设备 Download PDF

Info

Publication number
CN106161438B
CN106161438B CN201610495450.1A CN201610495450A CN106161438B CN 106161438 B CN106161438 B CN 106161438B CN 201610495450 A CN201610495450 A CN 201610495450A CN 106161438 B CN106161438 B CN 106161438B
Authority
CN
China
Prior art keywords
endpoint
resource
client application
access
server
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201610495450.1A
Other languages
English (en)
Chinese (zh)
Other versions
CN106161438A (zh
Inventor
李·艾伦·奈策尔
丹·霍尔沃·乌辛
罗伯特·肯特·胡巴
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Fisher Rosemount Systems Inc
Original Assignee
Fisher Rosemount Systems Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Fisher Rosemount Systems Inc filed Critical Fisher Rosemount Systems Inc
Publication of CN106161438A publication Critical patent/CN106161438A/zh
Application granted granted Critical
Publication of CN106161438B publication Critical patent/CN106161438B/zh
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/105Multiple levels of security
    • GPHYSICS
    • G05CONTROLLING; REGULATING
    • G05BCONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
    • G05B19/00Programme-control systems
    • G05B19/02Programme-control systems electric
    • G05B19/418Total factory control, i.e. centrally controlling a plurality of machines, e.g. direct or distributed numerical control [DNC], flexible manufacturing systems [FMS], integrated manufacturing systems [IMS] or computer integrated manufacturing [CIM]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/28Restricting access to network management systems or functions, e.g. using authorisation function to access network configuration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • Quality & Reliability (AREA)
  • Manufacturing & Machinery (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Automation & Control Theory (AREA)
  • Computer And Data Communications (AREA)
  • Storage Device Security (AREA)
  • Small-Scale Networks (AREA)
  • Mobile Radio Communication Systems (AREA)
CN201610495450.1A 2009-04-14 2010-04-14 为接口访问控制提供分层的安全防护的方法和设备 Active CN106161438B (zh)

Applications Claiming Priority (5)

Application Number Priority Date Filing Date Title
US16919909P 2009-04-14 2009-04-14
US61/169,199 2009-04-14
US12/637,439 US8887242B2 (en) 2009-04-14 2009-12-14 Methods and apparatus to provide layered security for interface access control
US12/637,439 2009-12-14
CN201010151782.0A CN101867566B (zh) 2009-04-14 2010-04-14 为接口访问控制提供分层的安全防护的方法和设备

Related Parent Applications (1)

Application Number Title Priority Date Filing Date
CN201010151782.0A Division CN101867566B (zh) 2009-04-14 2010-04-14 为接口访问控制提供分层的安全防护的方法和设备

Publications (2)

Publication Number Publication Date
CN106161438A CN106161438A (zh) 2016-11-23
CN106161438B true CN106161438B (zh) 2019-07-12

Family

ID=42235968

Family Applications (2)

Application Number Title Priority Date Filing Date
CN201010151782.0A Active CN101867566B (zh) 2009-04-14 2010-04-14 为接口访问控制提供分层的安全防护的方法和设备
CN201610495450.1A Active CN106161438B (zh) 2009-04-14 2010-04-14 为接口访问控制提供分层的安全防护的方法和设备

Family Applications Before (1)

Application Number Title Priority Date Filing Date
CN201010151782.0A Active CN101867566B (zh) 2009-04-14 2010-04-14 为接口访问控制提供分层的安全防护的方法和设备

Country Status (5)

Country Link
US (1) US8887242B2 (enExample)
EP (1) EP2242230B1 (enExample)
JP (2) JP5723105B2 (enExample)
CN (2) CN101867566B (enExample)
GB (1) GB2469557B (enExample)

Families Citing this family (49)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9654200B2 (en) 2005-07-18 2017-05-16 Mutualink, Inc. System and method for dynamic wireless aerial mesh network
US9871767B2 (en) * 2005-07-18 2018-01-16 Mutualink, Inc. Enabling ad hoc trusted connections among enclaved communication communities
US8887242B2 (en) 2009-04-14 2014-11-11 Fisher-Rosemount Systems, Inc. Methods and apparatus to provide layered security for interface access control
US20110239109A1 (en) * 2010-03-24 2011-09-29 Mark Nixon Methods and apparatus to display process data
US9122764B2 (en) 2010-03-24 2015-09-01 Fisher-Rosemount Systems, Inc. Methods and apparatus to access process data stored on a server
US8868732B2 (en) 2011-05-31 2014-10-21 General Electric Company Systems and methods for facilitating communication with foundation fieldbus linking devices
US8769072B2 (en) 2011-05-31 2014-07-01 General Electric Company Systems and methods for identifying foundation fieldbus linking devices
US8713166B2 (en) 2011-05-31 2014-04-29 General Electric Company Systems and methods for facilitating communication with foundation fieldbus linking devices
US9130853B2 (en) 2011-05-31 2015-09-08 General Electric Company Systems and methods for identifying foundation fieldbus linking devices
US8762528B2 (en) * 2011-05-31 2014-06-24 General Electric Company Systems and methods for write protecting foundation fieldbus linking devices
US8949350B2 (en) * 2011-08-26 2015-02-03 International Business Machines Corporation Tracking desktop application referrals to content distributed over a network
JP5687239B2 (ja) * 2012-05-15 2015-03-18 株式会社オプティム オペレータ認証機能を備えたオペレータ認証サーバ、オペレータシステム、オペレータ認証方法、及び、プログラム
US9613330B2 (en) * 2012-09-26 2017-04-04 EMC IP Holding Company LLC Identity and access management
US9558220B2 (en) 2013-03-04 2017-01-31 Fisher-Rosemount Systems, Inc. Big data in process control systems
US10678225B2 (en) 2013-03-04 2020-06-09 Fisher-Rosemount Systems, Inc. Data analytic services for distributed industrial performance monitoring
US10909137B2 (en) 2014-10-06 2021-02-02 Fisher-Rosemount Systems, Inc. Streaming data for analytics in process control systems
US9665088B2 (en) 2014-01-31 2017-05-30 Fisher-Rosemount Systems, Inc. Managing big data in process control systems
US10386827B2 (en) 2013-03-04 2019-08-20 Fisher-Rosemount Systems, Inc. Distributed industrial performance monitoring and analytics platform
US9397836B2 (en) * 2014-08-11 2016-07-19 Fisher-Rosemount Systems, Inc. Securing devices to process control systems
US10649449B2 (en) 2013-03-04 2020-05-12 Fisher-Rosemount Systems, Inc. Distributed industrial performance monitoring and analytics
US10866952B2 (en) 2013-03-04 2020-12-15 Fisher-Rosemount Systems, Inc. Source-independent queries in distributed industrial system
US10282676B2 (en) 2014-10-06 2019-05-07 Fisher-Rosemount Systems, Inc. Automatic signal processing-based learning in a process plant
US10649424B2 (en) 2013-03-04 2020-05-12 Fisher-Rosemount Systems, Inc. Distributed industrial performance monitoring and analytics
US10223327B2 (en) 2013-03-14 2019-03-05 Fisher-Rosemount Systems, Inc. Collecting and delivering data to a big data machine in a process control system
EP3200131B1 (en) 2013-03-15 2024-09-18 Fisher-Rosemount Systems, Inc. Data modeling studio
GB2513707B (en) * 2013-03-15 2020-07-22 Fisher Rosemount Systems Inc Method for initiating or resuming a mobile control session in a process plant
GB2513706B (en) * 2013-03-15 2020-09-23 Fisher Rosemount Systems Inc Method for initiating or resuming a mobile control session in a process plant
US9541905B2 (en) 2013-03-15 2017-01-10 Fisher-Rosemount Systems, Inc. Context sensitive mobile control in a process plant
US10599860B2 (en) * 2014-05-22 2020-03-24 Tata Consultancy Services Limited Accessing enterprise data
US10168691B2 (en) 2014-10-06 2019-01-01 Fisher-Rosemount Systems, Inc. Data pipeline for process control system analytics
JP2017538209A (ja) * 2014-11-14 2017-12-21 コンヴィーダ ワイヤレス, エルエルシー 許可ベースのリソースおよびサービス発見
WO2017007480A1 (en) * 2015-07-09 2017-01-12 Siemens Aktiengesellschaft Self-defending smart field device and architecture
EP3338408B1 (en) * 2015-11-05 2022-08-17 Hewlett-Packard Development Company, L.P. Local compute resources and access terms
US10503483B2 (en) 2016-02-12 2019-12-10 Fisher-Rosemount Systems, Inc. Rule builder in a process control network
US10540193B2 (en) * 2017-05-09 2020-01-21 Intel Corporation Software-defined microservices
CN110022310B (zh) * 2019-03-15 2021-09-14 北京星网锐捷网络技术有限公司 基于云计算开放网络操作系统的授权方法及装置
CN110827003B (zh) * 2019-11-11 2022-03-29 北京网聘咨询有限公司 基于虚拟化技术的服务器与招聘客户端的整合方法
US11601289B2 (en) * 2020-01-07 2023-03-07 Microsoft Technology Licensing, Llc Securely rotating a server certificate
CN112162491A (zh) * 2020-03-16 2021-01-01 陈力 智能家居权限控制方法及智能家居系统
US12314037B2 (en) 2021-06-16 2025-05-27 Fisher-Rosemount Systems, Inc Systems and methods for associating modules in a software defined control system for industrial process plants
US12242245B2 (en) 2021-06-16 2025-03-04 Fisher-Rosemount Systems, Inc. Discovery service in a software defined control system
US12321154B2 (en) 2021-06-16 2025-06-03 Fisher-Rosemount Systems, Inc. Systems and methods for associating modules in a software defined control system for industrial process plants
US12449789B2 (en) 2021-06-16 2025-10-21 Fisher-Rosemount Systems, Inc. Security services in a software defined control system
US12210329B2 (en) 2021-06-16 2025-01-28 Fisher-Rosemount Systems, Inc. Systems and methods for dynamically maintained redundancy and load balancing in software defined control systems for industrial process plants
US12417120B2 (en) 2021-06-16 2025-09-16 Fisher-Rosemount Systems, Inc. Systems and methods for dynamically maintained redundancy and load balancing in software defined control systems for industrial process plants
CN114726572A (zh) * 2022-02-28 2022-07-08 南京第壹时间信息科技有限公司 互联网设备的访问方法及系统
JP2025528325A (ja) 2022-07-18 2025-08-28 フィッシャー-ローズマウント システムズ,インコーポレイテッド プロセス制御又はオートメーションシステムアーキテクチャ
US12476973B2 (en) 2022-07-18 2025-11-18 Fisher-Rosemount Systems, Inc. Authentication/authorization framework for a process control or automation system
EP4606062A1 (en) * 2022-10-20 2025-08-27 Fisher-Rosemount Systems, Inc. Authentication/authorization framework for a process control or automation system

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2002008870A2 (en) * 2000-07-26 2002-01-31 David Dickenson Distributive access controller
US6715082B1 (en) * 1999-01-14 2004-03-30 Cisco Technology, Inc. Security server token caching
CN1505892A (zh) * 2000-11-03 2004-06-16 ���ܿ���ϵͳ���޹�˾ 利用安全通信信道的安全性来使非安全通信信道安全的系统和方法

Family Cites Families (29)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5764915A (en) 1996-03-08 1998-06-09 International Business Machines Corporation Object-oriented communication interface for network protocol access using the selected newly created protocol interface object and newly created protocol layer objects in the protocol stack
US5978850A (en) 1997-07-02 1999-11-02 National Instruments Corporation System and method for accessing parameters in a fieldbus network using a tag parameters interface
US7035850B2 (en) * 2000-03-22 2006-04-25 Hitachi, Ltd. Access control system
US6850979B1 (en) 2000-05-09 2005-02-01 Sun Microsystems, Inc. Message gates in a distributed computing environment
US8073967B2 (en) * 2002-04-15 2011-12-06 Fisher-Rosemount Systems, Inc. Web services-based communications for use with process control systems
JP2002366415A (ja) 2001-06-06 2002-12-20 Nippon Telegr & Teleph Corp <Ntt> リダイレクトシステムおよびリダイレクト装置
JP2003023676A (ja) 2001-07-10 2003-01-24 Hitachi Ltd 遠隔操作システム
US20030061515A1 (en) 2001-09-27 2003-03-27 Timothy Kindberg Capability-enabled uniform resource locator for secure web exporting and method of using same
JP2003140704A (ja) 2001-11-06 2003-05-16 Yamatake Sangyo Systems Co Ltd プロセス制御装置
JP4040886B2 (ja) * 2002-02-15 2008-01-30 三菱電機株式会社 コンテンツ管理システムおよびコンテンツ管理方法
JP3751584B2 (ja) * 2002-08-05 2006-03-01 株式会社デジタル 制御用表示装置、および、そのプログラムが記録された記録媒体、並びに、制御システム
JP2004127172A (ja) 2002-10-07 2004-04-22 Matsushita Electric Ind Co Ltd コンテンツ閲覧制限装置、コンテンツ閲覧制限方法およびコンテンツ閲覧制限プログラム
US7143288B2 (en) * 2002-10-16 2006-11-28 Vormetric, Inc. Secure file system server architecture and methods
US7237109B2 (en) 2003-01-28 2007-06-26 Fisher- Rosemount Systems, Inc. Integrated security in a process plant having a process control system and a safety system
US7502323B2 (en) * 2003-05-28 2009-03-10 Schneider Electric Industries Sas Access control system for automation equipment
US20050160161A1 (en) 2003-12-29 2005-07-21 Nokia, Inc. System and method for managing a proxy request over a secure network using inherited security attributes
JP2007536634A (ja) * 2004-05-04 2007-12-13 フィッシャー−ローズマウント・システムズ・インコーポレーテッド プロセス制御システムのためのサービス指向型アーキテクチャ
DE502005004396D1 (de) * 2005-04-22 2008-07-24 Trumpf Laser Gmbh & Co Kg Vorrichtung für sicheren Fernzugriff
US9871767B2 (en) * 2005-07-18 2018-01-16 Mutualink, Inc. Enabling ad hoc trusted connections among enclaved communication communities
US20070143827A1 (en) 2005-12-21 2007-06-21 Fiberlink Methods and systems for intelligently controlling access to computing resources
US8380979B2 (en) * 2005-12-22 2013-02-19 At&T Intellectual Property I, L.P. Methods, systems, and computer program products for invoking trust-controlled services via application programming interfaces (APIs) respectively associated therewith
US20070219908A1 (en) * 2006-03-02 2007-09-20 Yahoo! Inc. Providing syndicated media to authorized users
JP2007323340A (ja) 2006-05-31 2007-12-13 Toshiba Corp アカウントリンクシステム,アカウントリンク用コンピュータ,およびアカウントリンク方法
US8290949B2 (en) * 2006-07-24 2012-10-16 International Business Machines Corporation Resource name reconciliation in a configuration database
JP4935274B2 (ja) 2006-09-27 2012-05-23 大日本印刷株式会社 サーバ及びプログラム
US7950045B2 (en) * 2006-12-13 2011-05-24 Cellco Partnership Techniques for managing security in next generation communication networks
US8141143B2 (en) 2007-05-31 2012-03-20 Imera Systems, Inc. Method and system for providing remote access to resources in a secure data center over a network
US7996896B2 (en) * 2007-10-19 2011-08-09 Trend Micro Incorporated System for regulating host security configuration
US8887242B2 (en) 2009-04-14 2014-11-11 Fisher-Rosemount Systems, Inc. Methods and apparatus to provide layered security for interface access control

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6715082B1 (en) * 1999-01-14 2004-03-30 Cisco Technology, Inc. Security server token caching
WO2002008870A2 (en) * 2000-07-26 2002-01-31 David Dickenson Distributive access controller
CN1505892A (zh) * 2000-11-03 2004-06-16 ���ܿ���ϵͳ���޹�˾ 利用安全通信信道的安全性来使非安全通信信道安全的系统和方法

Also Published As

Publication number Publication date
CN101867566B (zh) 2016-08-03
GB2469557B (en) 2014-10-01
GB201005809D0 (en) 2010-05-26
JP5723105B2 (ja) 2015-05-27
EP2242230A3 (en) 2012-03-07
CN101867566A (zh) 2010-10-20
JP2015097091A (ja) 2015-05-21
JP5938088B2 (ja) 2016-06-22
US20100263025A1 (en) 2010-10-14
EP2242230B1 (en) 2017-02-22
US8887242B2 (en) 2014-11-11
EP2242230A2 (en) 2010-10-20
JP2010250825A (ja) 2010-11-04
GB2469557A (en) 2010-10-20
CN106161438A (zh) 2016-11-23

Similar Documents

Publication Publication Date Title
CN106161438B (zh) 为接口访问控制提供分层的安全防护的方法和设备
CN113010911B (zh) 一种数据访问控制方法、装置及计算机可读存储介质
JP7011709B2 (ja) 単一の産業ネットワーク上の多テナント・データアクセスを可能にすること
US7117529B1 (en) Identification and authentication management
US8510810B2 (en) Secure credential store
JP2006099777A (ja) レガシー・オートメーション・システムのための集中管理プロキシ・ベースのセキュリティ
AU5188499A (en) Access control using attributes contained within public key certificates
CN103401885B (zh) 网络文档权限控制方法、装置及系统
CN111274569A (zh) 统一登录认证的研发运维集成系统及其登录认证方法
US10963582B1 (en) Apparatus and method for enabling owner authorized monitored stewardship over protected data in computing devices
Mostéfaoui et al. A generic framework for context-based distributed authorizations
CN108449364A (zh) 一种分布式身份认证方法及云认证节点
KR100948873B1 (ko) 데이터베이스 보안을 위한 데이터베이스 보안관리장치와 그제어방법
Ahmed et al. A Method for Eliciting Security Requirements from the Business Process Models.
CN1822590A (zh) 保护轻量级目录访问协议的通信
Pereira et al. Secure, dynamic and distributed access control stack for database applications
Leila et al. A new framework of authentication over cloud computing
Del Vecchio et al. Evaluating Grid portal security
Abdurrahman et al. A Secure Digital Image Marketplace: Microservices and OWASP API Security Using Spring Boot
Marques et al. A component-based approach for integrating mobile agents into the existing web infrastructure
Oberoi et al. Benefits and Risks of Cloud Computing
Shen et al. Trust management for mobile agent system based on trusted computing platforms
Ezziyyani et al. Security techniques and specifications for the resources protection in mediation systems
Huang et al. Agentic AI Identity Security
HK40080377A (en) Processing method and device of sensitive information, storage medium and electronic equipment

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant