CN1240201C - A network management interface information access control system and control method thereof - Google Patents

A network management interface information access control system and control method thereof Download PDF

Info

Publication number
CN1240201C
CN1240201C CN 02148707 CN02148707A CN1240201C CN 1240201 C CN1240201 C CN 1240201C CN 02148707 CN02148707 CN 02148707 CN 02148707 A CN02148707 A CN 02148707A CN 1240201 C CN1240201 C CN 1240201C
Authority
CN
China
Prior art keywords
management system
network
information
interface
processing device
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Lifetime
Application number
CN 02148707
Other languages
Chinese (zh)
Other versions
CN1501627A (en
Inventor
李冶文
王烨
徐海东
魏丽红
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Mobile Communications Group Co Ltd
Original Assignee
China Mobile Communications Group Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Mobile Communications Group Co Ltd filed Critical China Mobile Communications Group Co Ltd
Priority to CN 02148707 priority Critical patent/CN1240201C/en
Publication of CN1501627A publication Critical patent/CN1501627A/en
Application granted granted Critical
Publication of CN1240201C publication Critical patent/CN1240201C/en
Anticipated expiration legal-status Critical
Expired - Lifetime legal-status Critical Current

Links

Images

Landscapes

  • Computer And Data Communications (AREA)

Abstract

The present invention relates to a network management interface information access control system which comprises a network management system and a network managed system. In the network management interface information access control system, a network interface information management processing device is arranged between the network management system and the network managed system, and is used for receiving and processing access information of an interface between the network management system and the network managed system. The present invention is used for releasing the network management system from a cockamamie work of storing a large amount of 'network management interface access information ' so as to reduce the burden of the network management system; the network interface information management processing device is used for strengthening the system flexibility, and can dynamically update the content of the access information of interfaces relevant to the network managed system so as to improve the validity of data; the access information of the interfaces of the whole management system is charged by the network interface information management processing device so as to largely increase the expandability of network management.

Description

A kind of network management interface message reference control system and control method thereof
Technical field
The present invention relates to the system and the control method thereof of a kind of secure access Element management system (Element Management System) or network element (Network Element).The invention belongs to communication network management system.
Background technology
Under existing network management environment, a primary condition finishing the management function of certain communication network management system is that the management information that realize to constitute between the multiple network management resource key element of this network management system is mutual, management information between, Element management system mutual as, the management information between network management system and the Element management system (agency) and the network element (agency) is mutual etc.Theoretical and the network management project practice from webmaster, the interactive mode of network management information mainly adopts interface mode at present, as shown in Figure 1 meaning.Among Fig. 1, need to have set up interface standard or privately owned negotiation between the mutual network management resource key element, realize that by interface predetermined network management information is mutual, thereby finish the function of network management system.The managerial ability of whole network management system depends on the definition ability of network management interface and the network management system managerial ability to network management interface to a certain extent.
Be in different administrative structures, fulfil the network management system of different management responsibilities by management system (agency of each management domain) before by the network management interface visit, need obtain relevant with this network management interface by management system " network management interface visit information ", thereby begin by management system (agency's of each management domain) visit." network management interface visit information " ability that presents and mode managerial ability of having embodied the network management system docking port to a certain extent on network management interface.After network management system has been obtained " network management interface visit information " by interface, just possessed and set up and communicated by letter with the ability of interactive maintenance information by management system related proxy (object).In the network management system of reality, particularly under the network management environment of multi-vendor, many equipment, how network management system relevant " network management interface visit information " being managed effectively and made it and searched safely by network management system and use, is the previous problem demanding prompt solution of order.
In existing realization technology, especially the time under the complex network environment of multi-vendor, many equipment, when network management system need be undertaken alternately when finishing the regulatory requirement of each management domain (configuration, fault, performance etc.) by a plurality of agencies in management system or a plurality of managed device interface with a plurality of, some management methods to " network management interface visit information " have been arranged, but the specific implementation method is often relevant with the technology that realizes interface.Mainly contain following two kinds of methods at present, first method is by the method for management system " network management interface visit information " opening.The main feature of this method be in the network management system storage " the network management interface visit information " that might visit and need pass through external means, as means such as mail, file transfers, keep its with by management system or by the consistency of " the network management interface visit information " of interface tube.Though this method also has certain practicality, but its shortcoming is to need artificial " network management interface visit information " data that participate in reporting, be difficult to accomplish the data that upgrade in time, artificial factor is a lot, and main shortcoming is to have increased the work load of network management system and the factor of makeing mistakes; Second method is the method for using in the corba interface technology at present.In CORBA used, the universal method that announcement and storage object are quoted was that object reference is placed in the name service routine.But different manufacturers often uses different name services to come storage object is quoted.In many producers environment, for obtaining " network management interface visit information ", network management system is had to associated each producer of directly visit by the name service of management system, and the name service of directly visiting other producer has been proved to be the relatively poor method of fail safe in actual applications.Simultaneously, if the information category and the content of " network management interface visit information " change, the system that each manufacturer has been developed can bring edition upgrading and a series of relevant issues of bringing thus (as consistent problem of version etc.), and the flexibility of whole system is relative with extensibility relatively poor.So, need new method remedy the existing methods deficiency, its target is to make network management system can find by " the network management interface visit information " of management system easily and safely and can be carried out bookkeeping visit safely by management system to relevant with this.
Summary of the invention
The technical problem to be solved in the present invention has provided a kind of network management interface message reference control system and control method thereof, make network management system can by interface obtain safely and effectively associated by " the interface accessing information " of management system and thus secure access by management system.
System of the present invention comprises that network management system, network are by management system, and network interface information management processing device is set between network management system, network are by management system, be used to receive and handle from network management system and network by the visit information of interface between the management system.Be provided with the interface message security authentication module in the network interface information management processing device, be used for determining the fail safe of interface accessing information.
At least comprise memory module, processing module and communication module in the network interface information management processing device, wherein communication module is responsible for network management system, network by the reception of management system information and transmission; Processing module is used for proxy interface information, and memory module is used to deposit interface message.Comprise the renewal control module in the network interface information management processing device, be used for the interface message in the memory module is dynamically updated.
Network interface information management processing device adopts independently that the external equipment mode is provided with, and makes network interface information management processing device and is in by management system in the different physical entities, adopts interface or alternate manner interactive interface visit information each other.The mode of obtaining data comprises mode and/or the passive mode of obtaining data of initiatively obtaining data.
Network interface information management processing device with taked integrated mode to be provided with by management system; Make network interface information management processing device and on a physical entity, realized by management system, network interface information management processing device with can be adopted the internal bus mode by management system, shared buffer mode and message transfer mode, or multiple mode Fabric Interface visit information such as middleware Technology.
The method of the invention comprises the steps:
Step 1, network interface information management processing device obtain link to each other with network management system by interface certain by " network management interface visit information " content of management system and be stored in this locality.
Simultaneously, this processing unit be responsible for keeping local data with relevant by the dynamic conformance of " interface accessing information " data of management system.
Step 2, this processing unit carries out safety certification to the network management system of desiring to obtain " interface accessing information ", network management system is through safety certification obtained by " the network management interface visit information " of management system from network interface information management processing device, simultaneously, network interface information management processing device produces corresponding " authenticated encryption information " in the mode of cryptographic algorithm, comprises the rights of using to the agency in the authenticated encryption information.
This device possesses the demand of the network management system change password that satisfies Lawful access simultaneously;
This device also possesses version negotiation mechanism, if " the network management interface visit information " of network management system appointment be not when being supported, this device can return this request can be Lawful access and the version informations of all these type of managed objects that can be supported at present reselect for network management system.
Step 3, network interface information management processing device after producing " authenticated encryption information ", simultaneously " authenticated encryption information " is distributed to the NMS that gets access to interface accessing information unify be acquired interface accessing information by management system;
Step 4, obtain that " authenticated encryption information " parameter that the network management system of interface accessing information will receive sends that it need visit to by management system, the authenticated encryption information that is sent respectively by management system contrast interface message collection point and network management system and confirm after, open corresponding access rights.
Adopt the present invention network management system can be freed from needs storage a large amount of " network management interface visit information " the loaded down with trivial details work of (as, address of managed object etc.), significantly alleviated the burden of network management system; By utilizing network interface information management processing device, network management system can be as required accesses network interface message management processing device safely at any time, thereby obtain appointment by the relevant interface visit information of management system, strengthened the flexibility of system; Network interface information management processing device can dynamically update with by the relevant interface accessing information content of management system, improved the validity of data; The interface accessing information of whole management system is responsible for by network interface information management processing device, thereby the autgmentability of network management is increased greatly.Version negotiation mechanism in the network interface information management processing device has improved network management system can select the object of visiting, the flexibility that has improved system.In addition, as network management system and by the mutual primary access object of management system, " the authenticated encryption information " of network interface information management processing device distribution mechanisms is synchronously also providing effective mechanism aspect the access security control, improve the fail safe of system, reduced the possibility of makeing mistakes.
Description of drawings
Fig. 1 be the prior art network management system with by management system (agency's) structural representation;
Fig. 2 constitutes and the data flow schematic diagram for system of the present invention;
Fig. 3 is also dynamically kept the principle schematic of data consistent by the network management interface visit information of management system for collection of the present invention;
Fig. 4 is the work basic flow sheet of the method for the invention.
Embodiment
Specify the present invention below in conjunction with accompanying drawing.
Fig. 1 has provided the applied environment of the network interface information management processing device that the present invention proposes, and it is actual to have comprised 3 network management elements, that is, network management system, it is as the manager; By management system, comprise functions such as alarm management agency, configuration management agency, performance management agency, and the connection management system with by the network management interface of management system.As previously mentioned, the present invention proposes the notion of " network management interface visit information ", it comprises the following information content: first: carry out different management domains (as, fault management, configuration management, performance management etc.) management function agent address or carry out the agent address of a plurality of management domain functions; Second: agency's range of management; The the 3rd: unique indications of agency; The the 4th: the interface standard version information that the agency is supported; The 5th: each is acted on behalf of accessed authority and is provided with etc.Except that above-mentioned four kinds of information, the content of " network management interface visit information " can increase new interface message type as required, has dynamic expandability.Therefore, the network interface information management processing device among Fig. 2, Fig. 3 just is responsible for " network management interface visit information " managed.
Fig. 2 represents that the interface message collection point carries out the situation of work at environment shown in Figure 1: (1) manager will visit by management system, will provide self user name, password earlier, carries out safety certification by the interface message collection point; (2) through safety certification after, the interface message collection point generates encryption parameter to validated user; (3) the interface message collection point is returned interface accessing information and is given the manager; (4) the interface message collection point is to the manager with by the synchronously reliable distribution of encrypted parameter of management system; (5) manager's visit is by management system, and the safety certification, the encryption parameter that the manager are provided by management system contrast; (6) through safety certification, after the encryption parameter contrast, the manager with carried out normal operational access by management system.
Among Fig. 3, in order to gather by the management system interface visit information and to keep the dynamic conformance of data, the interface message collection point is according to certain interval, to being the agency of each management domain by management system, act on behalf of as alarm management,, configuration management agency, performance management agency etc., the renewal that conducts interviews is in order to avoid changed by the data of management system.
The method of the invention such as flow process are illustrated in Figure 4:
Step 1, network interface information management processing device obtains by " network management interface visit information " relevant information of management system and is stored in this locality, and network interface information management processing device is responsible for dynamically updating relevant information simultaneously.Its operation principle as schematically shown in Figure 3.
In this step 1, network interface information management processing device obtain by the mode of " the network management interface visit information " of management system according to " the interface message collection point " and set-up mode can be divided into two kinds:
First kind of mode is: network interface information management processing device adopts " independently external equipment " mode, under this kind mode, this network interface information management processing device be implemented in by management system in the different physical entities, adopt interface or the alternate manner mutual each other " the network management interface visit information ".
The second way: network interface information management processing device be provided with by the integrated mode of management system; At this moment, network interface information management processing device with realized on a physical entity by management system.For this mode, network interface information management processing device with can be adopted multiple mode Fabric Interface visit information by management system, as the internal bus mode, shared buffer mode and message transfer mode, or middleware Technology etc.
For first kind of mode, be that network interface information management processing device is the situation of independent peripheral, network interface information management processing device with can be had multiplely by the mode of management system interaction data, but can reduce following two classes again from the mode of obtaining data.One is the mode that network interface information management processing device initiatively obtains data; It is two for the passive mode of obtaining data of network interface information management processing device.Initiatively to the request mode of being sent by management system agent, require to obtain relevant interface accessing information for network interface information management processing device.Comprise:
(1) network interface information management processing device initiatively initiate with each by the request of connecting of management system, this connection can be used TCP or other reliable transmission layer connection protocol; After connecting foundation, the request of sending of network interface information management processing device requires to be reported the relevant interface visit information by management system.This mode needs network interface information management processing device to know to each by the entry address of management system;
(2) network interface information management processing device adopts the mode of external management, promptly adopt external modes such as mail, file transfers, initiatively sent request by management system to each, require it to provide relevant " network management interface visit information ", and when information updating report network interface message management processing device.This mode defective is more, and analysis had been done in the front, and only related work has been given network interface information management processing device and freed the work of network management system.
(3) network interface information management processing device with adopted the middleware mode by management system, the implementation method of middleware is depended in the specifying information transmission.
The second class mode, i.e. the passive mode of obtaining data of network interface information management processing device, it refers to initiatively be sought network interface information management processing device by management system, and relevant information is reported network interface information management processing device.Such mode also comprises different ways:
(1) network interface information management processing device is as a Control Server, and its address is to open by management system.After network interface information management processing device starts, wait for the request of being initiated by management system of connecting; After connecting foundation, network interface information management processing device is waited for and is sent out data on the management system.What newly add management environment is needed initiatively reliably be connected with the foundation of network interface information management processing device (as the TCP connection) by management system or network element, accepts reported data then.
(2) network interface information management processing device is as Control Server, with by management system foundation reliably be not connected, network interface information management processing device can be announced specific User Data Protocol udp port, can be adopted UDP mode report network interface accessing information data and data updated by management system.
(3) adopted external mode by management system,, do not wait the requirement of network management system and the active applications externalist methodology reports relevant " network management interface visit information " to network management system as mail, file transfers etc.
(4) adopt middleware Technology, network interface information management processing device obtains the data that initiatively reported by management system by middleware.
Step 2, network management system accesses network interface message management processing device.Network management system is initiated the connection request of accesses network interface message management processing device, this connection request comprises the user name and password of network management system, and network interface information management processing device carries out the legitimacy safety certification to the network management system of desiring to obtain data.Network management system by authentication is obtained by the network management interface visit information of management system, and simultaneously, network interface information management processing device produces " the authenticated encryption parameter " of this visit, and this parameter comprises the access rights of this request simultaneously.
The interface message collection point possesses the demand of the network management system change password that satisfies Lawful access simultaneously.
The interface message collection point also possesses version negotiation mechanism, when if the network management interface visit information of network management system appointment can not get supporting, this request can be returned in the interface message collection point, and can reselect for network management system with version informations Lawful access and all these type of managed objects that can be supported at present.
In this step 2, network management system need be known address, interface message collection point.Network management system can be obtained address, interface message collection point in two ways.First kind of mode is external mode; The second way is a broadcast mode.External mode promptly adopts modes such as mail, file transfers as preceding narration.Because the uniqueness and the finiteness of network interface information management processing unit address, network management system adopt external mode to obtain the fail safe that network interface information management processing unit address information helps system.The second way is a broadcast mode, and network management system can obtain network interface information management processing unit address by receiving the external broadcasting of network interface information management processing device.
Network management system successfully set up with network interface information management processing device be connected and through safety certification after, request from interface to network interface information management processing device that can send " the interface accessing information " of obtaining needs by.The concrete way of the present invention is, having designed one can be for calling the call function of " obtaining interface message ", and the design input of this function, output parameter are anticipated as shown in Table 1 and Table 2.
The input parameter table of table 1 " obtains address information " function
Parameter name Parameter type Implication
Address version Character string For easy and simple to handle, input parameter only can be defined as a character string, this character string can be expressed the Agent Type of representative (as fault by predefined format by predefine specific format (as xx.yy.zz), configuration, performance etc.) and version information, represent Agent Type as different xx, yy.zz represents version information etc.
The output parameter table of table 2 " obtains address information " function
Parameter name Parameter type Implication
The interface message tabulation of supporting This tabulation comprises a sequence data: { interface IP address version-character string; Interface IP address; The unique indications of interface; Interface management scope-character string } If supported the interface type and the version of this functional query, then return the range of management of relevant address information, version, the unique indications of interface and this interface by management system; Otherwise, this function will return to that this user can Lawful access this by interface type and corresponding information such as version that management system is supported, be convenient to the management system utilization;
Step 3, network interface information management processing device is reliable distribution " authenticated encryption information " synchronously.Network interface information management processing device at first carries out safety certification to the network management system of visit, user for Lawful access, network interface information management processing device will produce " authenticated encryption information " with certain cryptographic algorithm, and this enciphered message comprises the agency's of the information of being acquired access rights.Simultaneously, network interface information management processing device network management system that " authenticated encryption information " reliably is distributed to the information of obtaining be acquired information by management system agent.
The purpose that network interface information management processing device increases distribution " authenticated encryption information " synchronously provides a kind of assurance by the means of the fail safe of management system, mainly is to prevent from by management system to be prevented the super authority visit of validated user simultaneously by unauthorized access.Because unauthorized system exists the possibility that adopts illegal means to obtain interface accessing information; Validated user exists the possibility of super authority visit.After taking this method, significantly reduced by the possibility of illegal operation of unauthorized system and the super authority visit of validated user by management system.
In this step 3, described network interface information management processing device enciphered message distribution synchronously comprises following step:
(1) network interface information management processing device carries out safety certification to the user name and password that obtains, can adopt specific cryptographic algorithm to produce encryption parameter for legal users network interface information management processing device, comprise corresponding access rights in the encryption parameter.Cryptographic algorithm can adopt existing various commercial cryptographic algorithm by implementor's decision of network interface information management processing device;
(2) after enciphered message produced, network interface information management processing device need adopt reliable fashion that enciphered message is distributed to and require to obtain the management of information system and be acquired the management of information system.In order to reach the reliable purpose that transmits of enciphered message, network interface information management processing matching requirements recipient returns confirmation, finishes the function of synchronous distribution, otherwise needs to retransmit until success, and this also is that the network management system visit is by the prerequisite of management system.
When network management system was visited by management system once more, all accessing operations directly carried out between NMS is unified by management system.But before normal management activities begins, by management system network management system is passed to by the encryption parameter of management system and to carry out safety certification once more; This process is transparent to the end user of network management system, and promptly the user of network management system only need once import the user name and password.
Described network management system is transmitted encryption parameter and is carried out safety certification once more by management system, comprises following two kinds of forms:
First: the step of carrying out safety certification once more is: network management system is all compared encryption parameter by management system to each operation all increase encryption parameter in by each operation of management system, to guarantee the legitimacy of each operation.
Second: network management system with connected by management system after, only use encryption parameter to carry out the once safety authentication, through safety certification the subsequent operation after is legal operation.This time verification process is transparent to the end user as mentioned above.
It should be noted last that: above embodiment is the unrestricted technical scheme of the present invention in order to explanation only, although the present invention is had been described in detail with reference to the foregoing description, those of ordinary skill in the art is to be understood that: still can make amendment or be equal to replacement the present invention, and not breaking away from any modification or partial replacement of the spirit and scope of the present invention, it all should be encompassed in the middle of the claim scope of the present invention.

Claims (31)

1, a kind of network management interface message reference control system, it comprises network management system, network is by management system, it is characterized in that: in network management system, network is provided with network interface information management processing device between the management system, be used to receive the interface accessing information of being sent by management system, and the information of network management system request interface visit information, handling the back provides by the interface accessing information of management system to network management system, also be provided with the interface message security authentication module in the described network interface information management processing device, be used for determining the fail safe of interface accessing information.
2, network management interface message reference control system according to claim 1, it is characterized in that: comprise memory module, processing module and communication module at least in the described network interface information management processing device, wherein communication module is responsible for network management system, network by the reception of information between the management system and transmission; Processing module is used to handle management system and by the scheduling decision of management system interface information, memory module is used to deposit by management system interface information.
3, network management interface message reference control system according to claim 2 is characterized in that: comprise the renewal control module in the described network interface information management processing device, be used for the interface message in the memory module is dynamically updated.
4, network management interface message reference control system according to claim 1, it is characterized in that: described network interface information management processing device adopts independently that the external equipment mode is provided with, make network interface information management processing device and be in by management system in the different physical entities, adopt interactive interfacing interface accessing information each other.
5, network management interface message reference control system according to claim 1 is characterized in that: described network interface information management processing device with taked integrated mode to be provided with by management system; Make network interface information management processing device and on a physical entity, realized by management system, network interface information management processing device with can be adopted the internal bus mode by management system, shared buffer mode and message transfer mode, or middleware Technology mode Fabric Interface visit information.
6, network management interface message reference control system according to claim 4 is characterized in that: the mode that described network interface information management processing device obtains data comprises mode and/or the passive mode of obtaining data of initiatively obtaining data.
7, a kind of network management interface information access control method based on each described system in the claim 1~6, it is characterized in that: it comprises the steps:
Step 1, network interface information management processing device obtain link to each other with network management system by interface certain by the interface accessing information content of management system and be stored in this locality;
Step 2, described network interface information management processing device carries out safety certification to the network management system of desiring to obtain interface accessing information, network management system through safety certification can be obtained by the interface accessing information of management system from network interface information management processing device, simultaneously, network interface information management processing device produces corresponding authenticated encryption information in the mode of cryptographic algorithm;
Step 3, network interface information management processing device after producing " authenticated encryption information ", simultaneously " authenticated encryption information " is distributed to the NMS that gets access to interface accessing information unify be acquired interface accessing information by management system.
8, method according to claim 7, it is characterized in that: described step also comprises step 4, obtain that " authenticated encryption information " parameter that the network management system of interface accessing information will receive sends that it need visit to by management system, the authenticated encryption information that is sent respectively by management system contrast network interface information management processing device and network management system and confirm after, open corresponding access rights.
9, method according to claim 7 is characterized in that: in the described step 1, network interface information management processing device is the updating interface visit information regularly, with keep local data with relevant by the dynamic conformance of the interface accessing information data of management system.
10, method according to claim 7, it is characterized in that: described network interface information management processing device with can be adopted the internal bus mode by management system, shared buffer mode and message transfer mode, or the middleware Technology mode exchanges the interface accessing information of obtaining.
11, method according to claim 10 is characterized in that: the mode that described network interface information management processing device obtains data comprises mode and/or the passive mode of obtaining data of initiatively obtaining data.
12, method according to claim 11 is characterized in that: the described mode of initiatively obtaining data comprises: network interface information management processing device can use Transmission Control Protocol initiatively initiate with each by the request of connecting of management system; After connecting foundation, the request of sending of network interface information management processing device requires to be reported the relevant interface visit information by management system.
13, method according to claim 11, it is characterized in that: the described mode of initiatively obtaining data, comprise: network interface information management processing device adopts the external mode of mail, file transfers, initiatively sent request by management system to each, require it to provide relevant " network management interface visit information ", and when information updating report network interface message management processing device.
14, method according to claim 11 is characterized in that: the described mode of initiatively obtaining data comprises: network interface information management processing device with adopted the middleware mode by management system, the information transmission is carried out according to the attribute specification transmission of middleware.
15, method according to claim 11, it is characterized in that: the described passive mode of obtaining data, comprise: network interface information management processing device is set to an address to by the disclosed Control Server of management system, after network interface information management processing device is started working, wait for the request of being initiated by management system of connecting; After connecting foundation, network interface information management processing device is waited for and is sent out data on the management system.
16, method according to claim 11, it is characterized in that: the described passive mode of obtaining data, comprise: network interface information management processing device is as Control Server, announce the User Data Protocol udp port that it is specific, adopted UDP mode report network interface accessing information data and data updated by management system.
17, method according to claim 11 is characterized in that: the described passive mode of obtaining data comprises: adopted external mode by management system, the active applications externalist methodology reports relevant interface accessing information to network management system.
18, method according to claim 11 is characterized in that: the described passive mode of obtaining data comprises: adopt middleware Technology, network interface information management processing device obtains the data that initiatively reported by management system by middleware.
19, method according to claim 7, it is characterized in that: produce the authenticated encryption parameter in the described step 2, transmit interface accessing information to after the network management system, if network management system is not supported the interface accessing information of being asked, network interface information management processing device can return this request, and can reselect for network management system with version informations Lawful access and all these type of managed objects that can be supported at present.
20, method according to claim 7 is characterized in that: in the described step 2, network management system can external mode or broadcast mode obtain network interface information management processing unit address.
21, method according to claim 7, it is characterized in that: network management system successfully set up with network interface information management processing device be connected also through safety certification after, comprise that also network management system sends the request of " the interface accessing information " of obtaining needs to network interface information management processing device.
22, method according to claim 21 is characterized in that: described request of sending " the interface accessing information " of obtaining needs is obtained interface message by a call function.
23, method according to claim 22 is characterized in that: the input parameter of described call function comprises the information of presentation address information and/or version; Parameter type adopts character string definition form.
24, method according to claim 22 is characterized in that: the output parameter of described call function comprises the interface message tabulation that expression is supported.
25, method according to claim 24 is characterized in that: the tabulation of described interface message comprises and comprises unique indications of interface IP address version and/or interface IP address and/or interface and/or interface management range data.
26, method according to claim 24 is characterized in that: described interface message table data also comprises operating right information.
27, method according to claim 7 is characterized in that: in this step 3, described network interface information management processing device authentication enciphered message distribution synchronously comprises following step:
(1) network interface information management processing device carries out safety certification to the user name and password that obtains, can adopt specific cryptographic algorithm to produce encryption parameter for legal users network interface information management processing device, comprise corresponding access rights in the encryption parameter;
(2) after authenticated encryption information produces, network interface information management processing device with the authenticated encryption distribution of information to require to obtain the management of information system and be acquired information by management system, network interface information management processing matching requirements recipient returns confirmation, finish the function of synchronous distribution, otherwise need to retransmit, until success.
28, according to the described method of above-mentioned each claim, it is characterized in that: when network management system was visited by management system once more, all accessing operations directly carried out between NMS is unified by management system.
29, method according to claim 28, it is characterized in that: between NMS is unified by management system, directly conduct interviews before the operation, also comprise: by management system network management system is passed to by the encryption parameter of management system and carry out safety certification once more.
30, method according to claim 29, it is characterized in that: described step of carrying out safety certification once more is: network management system is all increasing encryption parameter in by each operation of management system, by management system encryption parameter is all compared in each operation, to guarantee the legitimacy of each operation.
31, method according to claim 29, it is characterized in that: described step of carrying out safety certification once more is: network management system with connected by management system after, only use encryption parameter to carry out the once safety authentication, through safety certification the subsequent operation after is legal operation.
CN 02148707 2002-11-15 2002-11-15 A network management interface information access control system and control method thereof Expired - Lifetime CN1240201C (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN 02148707 CN1240201C (en) 2002-11-15 2002-11-15 A network management interface information access control system and control method thereof

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN 02148707 CN1240201C (en) 2002-11-15 2002-11-15 A network management interface information access control system and control method thereof

Publications (2)

Publication Number Publication Date
CN1501627A CN1501627A (en) 2004-06-02
CN1240201C true CN1240201C (en) 2006-02-01

Family

ID=34233271

Family Applications (1)

Application Number Title Priority Date Filing Date
CN 02148707 Expired - Lifetime CN1240201C (en) 2002-11-15 2002-11-15 A network management interface information access control system and control method thereof

Country Status (1)

Country Link
CN (1) CN1240201C (en)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100375443C (en) * 2005-02-25 2008-03-12 中兴通讯股份有限公司 Method of access network element managing system for mobile communication service managing system
CN101018149A (en) * 2006-02-09 2007-08-15 华为技术有限公司 A method for the network element management system establishing the interconnection
CN101415019A (en) * 2007-10-15 2009-04-22 华为技术有限公司 Method and apparatus for managing information transmission availability negotiation
CN103475741A (en) * 2013-09-29 2013-12-25 方正国际软件有限公司 Data synchronization system and data synchronization method

Also Published As

Publication number Publication date
CN1501627A (en) 2004-06-02

Similar Documents

Publication Publication Date Title
CN1842031B (en) Data processing method and system
US8935398B2 (en) Access control in client-server systems
CN1311660C (en) Server apparatus, and method of distributing a security policy in communication system
US8745223B2 (en) System and method of distributed license management
CN100553202C (en) The method and system that is used for dynamic device address management
CN101032147A (en) Method for updating a table of correspondence between a logical address and an identification number
CN106874461A (en) A kind of workflow engine supports multi-data source configuration security access system and method
CN1787513A (en) System and method for safety remote access
CN1926801A (en) Extranet access management apparatus and method
CN1439978A (en) Access limitation controlling device and method
US20030014386A1 (en) Account management module database interface
JP2000349747A (en) Public key managing method
CN110336718A (en) A kind of method of internet of things equipment safely and fast access-in management platform
CN102045413A (en) DHT expanded DNS mapping system and method for realizing DNS security
CN1820264A (en) System and method for name resolution
CN1852169A (en) Method and system for centralized management of multiple functional units
CN1240201C (en) A network management interface information access control system and control method thereof
CN1601954A (en) Moving principals across security boundaries without service interruption
CN112464215B (en) Identity authentication and control method for enterprise service system
CN100344091C (en) Distributed certificate verification method
CN101060398A (en) A new safety group safety certificate generating method, communication method, and network system
CN1197296C (en) An information switch
CN115396229B (en) Cross-domain resource isolation sharing system based on blockchain
CN114466038B (en) Communication protection system of electric power thing networking
CN1652078A (en) Method for implementing remote-call by application program interface system on database

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CX01 Expiry of patent term
CX01 Expiry of patent term

Granted publication date: 20060201