WO2017131346A1 - 네트워크 접속 제어 시스템 및 제어 방법 - Google Patents

네트워크 접속 제어 시스템 및 제어 방법 Download PDF

Info

Publication number
WO2017131346A1
WO2017131346A1 PCT/KR2016/015191 KR2016015191W WO2017131346A1 WO 2017131346 A1 WO2017131346 A1 WO 2017131346A1 KR 2016015191 W KR2016015191 W KR 2016015191W WO 2017131346 A1 WO2017131346 A1 WO 2017131346A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
computing device
portable computing
portable
access
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/KR2016/015191
Other languages
English (en)
French (fr)
Other versions
WO2017131346A9 (ko
Inventor
송중호
윤진
이도섭
이민주
김학민
백성연
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Korea Basic Science Institute KBSI
Original Assignee
Korea Basic Science Institute KBSI
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Korea Basic Science Institute KBSI filed Critical Korea Basic Science Institute KBSI
Publication of WO2017131346A1 publication Critical patent/WO2017131346A1/ko
Publication of WO2017131346A9 publication Critical patent/WO2017131346A9/ko
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols

Definitions

  • the present invention relates to a network access control system and a control method for controlling a network connection of a user using a portable access controller.
  • a separate management or security program must be installed on a user's portable computing device in order to access and use a network managed by an organization and an institution.
  • a portable computing device wants to access a network, the network administrator must set up information (e.g. IP address) for each portable computing device to identify the network connection. You must enter a security policy.
  • IP address e.g. IP address
  • An object of the present invention is to provide a network access control system and a control method capable of simple and detailed network security policy and network access management of a portable computing device possessed by a user.
  • Another object of the present invention can control the network security policy and network access according to the user's rights and business functions.
  • the object of the present invention is connected to a portable computing device capable of connecting to a network, the portable connection controller for managing a network connection of the portable computing device based on a network security policy and the portable connection controller is connected via the network to the portable connection
  • the present invention provides a network access control system and a control method for providing a network security policy to a controller and including a network manager for performing device authentication of the portable computing device.
  • an administrator can easily and finely manage the network security policy and network access management of a portable computing device possessed by a user.
  • the network access control system and control method according to the present invention can control the network security policy and network access according to the user's rights and business functions.
  • FIG. 1 is a schematic diagram illustrating a network access control system according to an embodiment of the present invention.
  • FIG. 2 is a block diagram showing the configuration of the portable connection controller of FIG.
  • FIG. 3 is a flowchart illustrating a network access control process according to an embodiment of the present invention.
  • FIG. 1 is a schematic diagram showing a network connection control system according to an embodiment of the present invention
  • Figure 2 is a block diagram showing the configuration of the portable connection controller of FIG.
  • the network access control system includes a portable access controller 110 and a network manager 120.
  • Network access control system when the user wants to access the network 102 using the portable computing device 101 capable of network connection, the connection between the portable computing device 101 and the network 102
  • the technical focus is to provide a control system and control method that can control and manage the system.
  • the portable computing device 101 may be a device owned by a user and connected to the network, and may be a smartphone, a notebook, a smart pad, or the like, and any device may be used as long as the user is portable and may be connected to the network 102. Do.
  • the portable access controller 110 may be connected to a portable computing device 101 capable of accessing the network 102 to manage network 102 connection of the portable computing device 101 based on a network security policy.
  • the portable connection controller 110 may be configured to be portable by the user.
  • a plurality of portable computing devices 101 may be provided, and the portable connection controller 110 may be connected to at least one of the plurality of portable computing devices 101 to manage the network 102 connection.
  • the portable access controller 110 may be connected to a plurality of portable computing devices 101 at the same time, and may simultaneously manage the network 102 connection of the plurality of portable computing devices 101.
  • the portable connection controller 110 may include a network interface 111, a network connection module 112, and a network connection control module 113.
  • the network interface 111 may be connected to the portable computing device 101 and the network 102, respectively, to connect the portable access controller 110 between the portable computing device 101 and the network 102.
  • the network interface 111 may connect the portable access controller 110 to the portable computing device 101 and the network 102 in a wireless or wired manner.
  • the network connection module 112 may be connected to the network interface 111 to request the network 102 connection.
  • the network connection module 112 may request connection with the network 102.
  • the network connection module 112 may request device authentication to determine whether the portable computing device 101 connected to the network interface 111 is the new portable computing device 101.
  • the network access control module 113 may be connected to the network access module 112 to determine whether to allow the portable computing device 101 to access the network 102 based on a network security policy.
  • the network security policy may be any one of authentication information, an IP address, a port number, an access allowance number, an access allowance time, and an amount of transmission data.
  • the network access control module 113 may determine whether to allow the portable computing device 101 to access the network 102 based on pre-stored authentication information.
  • the network connection control module 113 checks whether authentication information of the portable computing device 101 connected according to the network 102 connection request of the network connection module 112 is stored in the network connection control module 113. If the authentication information is stored in the network access control module 113, the network 102 may be allowed to access the network, and if the authentication information is not stored, the network 102 may not be allowed to access the network 102.
  • the network access control module 113 may determine whether to allow the portable computing device 101 to access the network 102 based on a pre-stored IP address.
  • the network access control module 113 checks whether the IP address of the connected portable computing device 101 is stored in the network access control module 113 according to the network 102 connection request of the network access module 112. If the IP address is stored in the network access control module 113, the network 102 may be allowed to access the network. If the IP address is not stored, the network 102 may not be allowed to access the network.
  • the network connection control module 113 may determine whether to allow the portable computing device 101 to access the network 102 based on previously stored port information.
  • the network connection control module 113 checks whether port information of the portable computing device 101 connected according to the network 102 connection request of the network connection module 112 is stored in the network connection control module 113. If the port information is stored, the network 102 may be allowed to be connected. If the port information is not stored, the network 102 may be allowed to be connected.
  • the network connection control module 113 may determine whether to allow the portable computing device 101 to access the network 102 based on a preset number of network connection allowances. In this case, the network connection control module 113 may be set in advance the number of network connection allowance for each portable computing device 101, and the network connection allowance number may be set in advance for each portable connection controller 110.
  • the network connection control module 113 may be configured to allow the number of network connection per portable computing device 101 and the number of portable connections previously set in the network connection control module 113 according to the network 102 connection request of the network connection module 112. Check the number of network connection allowances per connection controller 110, and if the number of network connection allowances of the connected portable computing device 101 remains, permit the network 102 connection of the corresponding portable computing device 101, and access the network. If the number of allowances does not remain, it may be impossible to allow the corresponding portable computing device 101 to access the network 102.
  • the network access control module 113 permits the network 102 access of the connected portable computing device 101 when the number of network access allowances per portable access controller 110 remains, and the number of network access allowances remains. If not, it may be impossible to allow the connected portable computing device 101 to access the network 102.
  • the network access control module 113 may determine whether to allow the portable computing device 101 to access the network 102 based on a preset access allowance time.
  • the network connection control module 113 checks whether the time for requesting connection according to the network 102 connection request of the network connection module 112 is within a preset connection allowance time, and allows the connection request time to be preset. If the time is within the time period, the network 102 may be allowed to be connected, and if the access request time is not the preset access time, the network 102 may not be allowed to be allowed.
  • the network access control module 113 may determine whether to allow the portable computing device 101 to access the network 102 based on a predetermined amount of transmission data.
  • the network connection control module 113 checks whether a predetermined amount of transmission data remains according to a network 102 connection request of the network connection module 112, and a predetermined amount of transmission data remains and the network 102. If the connection is allowed and the preset amount of transmission data is not left, the network 102 may not be allowed to connect.
  • the update module 114 may be connected to the network access control module 113 to update a network security policy provided by the network manager 120.
  • the update module 114 may be connected to the network manager 120 and the network 102. That is, when the administrator sets the network security policy in the network manager 120, the update module 114 may update the network security policy provided by the network manager 120 to the network control module 113 at any time.
  • the portable connection controller 110 may further include a monitoring module 115 for monitoring data transmitted and received and a storage unit 116 storing monitoring data monitored by the monitoring module 115.
  • the monitoring module 115 may be connected to the network connection module 112 to monitor the data transmitted and received.
  • the storage unit 116 may store the monitoring data monitored by the monitoring module 115. That is, the monitoring module 115 may monitor which data is transmitted and received and store the data in the storage unit 116, thereby preventing leakage of data requiring security.
  • the portable access controller 110 may further include an encryption module 117 connected to the network connection module 112 to encrypt data transmitted and received based on the network security policy.
  • the encryption module 117 may encrypt data transmitted and received on the basis of IP address or port information previously set in the network access control module 113.
  • the network access control module 113 is an IP address and port information for requesting encryption IP set in advance in the network access control module 113 Check whether it corresponds to address or port information, and if so, the encryption module 117 may encrypt and transmit data.
  • the IP address and port information for which encryption is performed in the encryption module 117 may be updated and changed by the network access control module 113 through the update module 114.
  • the encryption module 117 can safely protect the data transmitted and received through the network 102 without installing a separate security program, and through the update module 114, the administrator encrypts the main data as needed Can be controlled to transmit and receive.
  • the portable access controller 110 may further include a screen display unit 118 that displays a state of the portable computing device 101 and a network 102 connection state.
  • the screen display unit 118 may display whether the portable computing device 101 is connected to the network 102.
  • the network manager 120 may be connected to the portable access controller 110 through the network 102 to provide a network security policy and perform device authentication of the portable computing device 101.
  • the network manager 120 may provide a network security policy to the update module 114 of the portable access controller 110 through the network 102.
  • the network manager 120 may perform device authentication when the portable computing device 101 connected to the portable access controller 110 is a new portable computing device 101 that has not received device authentication.
  • each user can carry the portable computing device 101 without having to manage all of the portable computing devices 101. Since only the connection controller 110 can be managed to manage the plurality of portable computing devices 101, network security policy and network connection management can be simplified and detailed.
  • FIG. 3 is a flowchart illustrating a network access control process according to an embodiment of the present invention.
  • a network connection may be requested (S1100).
  • the portable access controller 110 may check whether the device is authenticated based on pre-stored authentication information to determine whether it is a new portable computing device 101 (S1200).
  • the portable computing device having already performed device authentication by comparing the device information such as MAC information, IP address, and user information of the portable computing device 101 requesting a network connection with the authentication information previously stored in the portable access controller 110 ( 101) can be determined.
  • the network management unit 120 may perform the device authentication (S1300).
  • the portable computing device 101 requesting a network connection is a new portable computing device 101
  • the portable computing device 101 may request and receive information for device authentication, and transmit the information to the network manager 120. have.
  • the network manager 120 may determine whether to allow the portable computing device 101 to access the network 102 based on the received information.
  • the received additional Device authentication may be performed based on the authentication information and the information for device authentication.
  • the device authentication disable message may be transmitted to the portable access controller 110 to display a device authentication disable message on the screen display unit 118.
  • the portable access controller 110 is based on the network security policy provided by the network management unit 120 of the portable computing device 101 It may be determined whether to allow the network access (S1400).
  • the network security policy may be any one of an IP address, a port number, an access allowance number, an access allowance time, and a transmission data amount.
  • the network 102 is allowed to access the connection.
  • Network 102 may not be allowed to connect.
  • the network management unit 120 when the number of connection allowances provided by the network management unit 120 does not exceed the preset number of connection allowances in response to the portable computing device 101 requesting a network connection, the network 102 connection is allowed, and the preset connection is established. If the number of allowances is exceeded, the network 102 may not be allowed to connect.
  • the network 102 connection is allowed, and the preset access allowance time is set. If not, network 102 may not be allowed to connect.
  • the network 102 is allowed to connect and the preset transmission data is set. If the amount is exceeded, network 102 may not be allowed to connect.
  • 112 network connection module 113: network connection control module

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Small-Scale Networks (AREA)

Abstract

본 발명은 휴대용 접속제어기를 이용하여 사용자의 네트워크 접속을 제어하는 네트워크 접속 제어 시스템 및 제어 방법에 관한 것으로, 네트워크 접속이 가능한 휴대용 컴퓨팅 기기에 연결되어 네트워크 보안정책을 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속을 관리하는 휴대용 접속제어기 및 상기 휴대용 접속제어기에 상기 네트워크를 통해 연결되어 상기 휴대용 접속제어기에 상기 네트워크 보안정책을 제공하며, 상기 휴대용 컴퓨팅 기기의 기기인증을 수행하는 네트워크관리부를 포함한다.

Description

네트워크 접속 제어 시스템 및 제어 방법
본 발명은 휴대용 접속제어기를 이용하여 사용자의 네트워크 접속을 제어하는 네트워크 접속 제어 시스템 및 제어 방법에 관한 것이다.
기술의 발달로 인해 인터넷 등과 같은 네트워크를 사용할 수 있는 기기가 기하급수적으로 늘어나고 있으며 이러한 기기가 소형화되고 있다. 이러한 이유로 사용자들은 소형화된 장치를 직접 들고 다니면서 필요에 의해 네트워크에 접속하여 필요한 업무를 수행한다. 이러한 변화로 인하여 네트워크 접속을 위해 관리하고 유지하기 위해 사용된 기술 역시 변화 또는 변모하고 있다.
일반적으로 모든 사용자가 접속 할 수 있는 네트워크망을 제외하고, 조직 및 기관에서 관리하는 네트워크에 접속 및 사용을 하고자 하는 경우에 사용자의 휴대용 컴퓨팅 기기에 별도의 관리 또는 보안 프로그램을 설치해야 한다.
그러나, 네트워크의 접속을 관리하고 보호하기 위해서 설치되는 프로그램이 휴대용 컴퓨팅 기기에 설치되는 경우, 해당 기기의 운영체제 및 프로그램적인 요인으로 인하여 정상적으로 동작하지 않거나 설치되지 못하는 상황이 발생하기도 하며, 바이러스가 사용자의 휴대용 컴퓨팅 기기에 설치되어, 해당 프로그램을 통해서 네트워크 연결이 허용되는 경우, 감염된 휴대용 컴퓨팅 기기와 연결된 동일 네트워크에 연결되어 있는 모든 컴퓨팅 기기가 감염되거나, 주요 데이터가 유출될 수 있다.
상기와 같은 상황을 해결하기 위해 조직 및 기관에서는 고비용의 보안 시스템을 설치하여 운영해야 하며, 신규 서비스 및 시스템을 보호하는 장비를 추가적으로 구축해야 하는 문제가 있고, 다양한 보안 시스템 및 장비를 운영함으로 인하여 네트워크 구조가 복잡해지는 문제가 있다.
더구나, 휴대용 컴퓨팅 기기에서 네트워크를 접속하고자 하는 경우, 네트워크 관리자가 각각의 휴대용 컴퓨팅 기기가 네트워크 접속을 식별할 수 있는 정보(예를 들어 IP주소)를 설정해야 하고, 각각의 휴대용 컴퓨팅 기기별로 별도의 보안정책을 입력해야 한다.
그리고 컴퓨팅 기술이 발전하여 사용자가 업무에 사용하는 네트워킹이 가능한 휴대용 컴퓨팅 기기 기기가 늘어남에 따라 네트워크 보안정책 및 네트워크 접속 관리가 어려운 문제점이 있다.
(선행기술문헌)
(특허문헌)
한국공개특허공보 제2013-0040662호
본 발명의 목적은 사용자가 소지한 휴대용 컴퓨팅 기기의 네트워크 보안정책 및 네트워크 접속 관리를 간편하고 세밀하게 할 수 있는 네트워크 접속 제어 시스템 및 제어 방법을 제공하는 것이다.
본 발명의 또 다른 목적은 사용자의 권한 및 업무 기능에 따라 네트워크 보안정책 및 네트워크 접속을 제어할 수 있다.
본 발명의 상기 목적은, 네트워크 접속이 가능한 휴대용 컴퓨팅 기기에 연결되어 네트워크 보안정책을 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속을 관리하는 휴대용 접속제어기 및 상기 휴대용 접속제어기에 상기 네트워크를 통해 연결되어 상기 휴대용 접속제어기에 상기 네트워크 보안정책을 제공하며, 상기 휴대용 컴퓨팅 기기의 기기인증을 수행하는 네트워크관리부를 포함하는 네트워크 접속 제어 시스템 및 제어 방법이 제공됨에 달성된다.
이상에서 설명한 바와 같이, 본 발명에 따른 네트워크 접속 제어 시스템 및 제어 방법은 관리자가 사용자가 소지한 휴대용 컴퓨팅 기기의 네트워크 보안정책 및 네트워크 접속 관리를 간편하고, 세밀하게 할 수 있다.
또한, 본 발명에 따른 네트워크 접속 제어 시스템 및 제어 방법은 사용자의 권한 및 업무 기능에 따라 네트워크 보안정책 및 네트워크 접속을 제어할 수 있다.
도 1은 본 발명의 실시예에 따른 네트워크 접속 제어 시스템을 나타낸 개략도.
도 2는 도 1의 휴대용 접속제어기의 구성을 나타낸 블럭도.
도 3은 본 발명의 실시예에 따른 네트워크 접속 제어 과정을 나타낸 순서도.
이하, 도면을 참조하여 본 발명의 구체적인 실시형태를 설명하기로 한다. 그러나 특정한 구조적 내지 기능적 설명들은 단지 본 발명의 실시예를 설명하기 위한 목적으로 예시된 것으로, 본 발명의 실시예들은 다양한 형태로 실시될 수 있고, 본문에 설명된 실시예들에 대해 한정하려는 것이 아니며, 본 발명의 사상 및 기술 위치에 포함되는 모든 변경, 균등물 내지 대체물을 포함하는 것으로 이해되어야 한다.
부가적으로, 각 도면에 걸쳐 표시된 동일 참조 부호는 동일 구성 요소를 지칭하며, 본 발명의 설명된 실시예의 논의를 불필요하게 불명료하도록 하는 것을 피하기 위해 공지된 특징 및 기술의 상세한 설명은 생략될 수 있다. 본 명세서에서 제1, 제2 등의 용어는 하나의 구성요소를 다른 구성요소로부터 구별하기 위해 사용되는 것으로서, 구성요소가 상기 용어들에 의해 제한되는 것은 아니다.
본 발명을 설명함에 있어서, 본 발명과 관련된 공지기술에 대한 구체적인 설명이 본 발명의 요지를 불필요하게 흐릴 수 있다고 판단되는 경우에는 그 상세한 설명을 생략하기로 한다.
도 1은 본 발명의 실시예에 따른 네트워크 접속 제어 시스템을 나타낸 개략도이고, 도 2는 도 1의 휴대용 접속제어기의 구성을 나타낸 블럭도이다.
도 1 및 도 2에 도시된 바와 같이, 본 발명의 실시예에 따른 네트워크 접속 제어 시스템은 휴대용 접속제어기(110) 및 네트워크관리부(120)를 포함한다.
본 발명의 실시예에 따른 네트워크 접속 제어 시스템은 사용자가 네트워크 접속이 가능한 휴대용 컴퓨팅 기기(101)를 사용하여 네트워크(102)에 접속하고자 하는 경우, 휴대용 컴퓨팅 기기(101)와 네트워크(102)의 접속을 제어 및 관리할 수 있는 제어 시스템 및 제어 방법을 제공하는데 기술적 주안점을 두고 있다.
여기서, 상기 휴대용 컴퓨팅 기기(101)는 사용자가 소유하여 네트워크 접속이 가능한 장치로 스마트폰, 노트북, 스마트 패드 등일 수 있으며, 사용자가 휴대 가능하고 네트워크(102)와의 접속이 가능한 장치라면 어떠한 장치도 무방하다.
상기 휴대용 접속제어기(110)는 네트워크(102)접속이 가능한 휴대용 컴퓨팅 기기(101)에 연결되어 네트워크 보안정책을 토대로 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속을 관리할 수 있다.
여기서, 상기 휴대용 접속제어기(110)는 사용자가 휴대 가능하도록 구성될 수 있다. 이때, 상기 휴대용 컴퓨팅 기기(101)는 다수가 구비될 수 있는데, 상기 휴대용 접속제어기(110)는 다수의 휴대용 컴퓨팅 기기(101) 중 적어도 어느 하나와 연결되어 네트워크(102) 접속을 관리할 수 있다. 또한, 상기 휴대용 접속제어기(110)는 동시에 다수의 휴대용 컴퓨팅 기기(101)와 연결될 수 있으며, 다수의 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속을 동시에 관리할 수 있다.
한편, 상기 휴대용 접속제어기(110)는 네트워크인터페이스(111), 네트워크접속모듈(112) 및 네트워크접속제어모듈(113)을 포함할 수 있다.
상기 네트워크인터페이스(111)는 휴대용 컴퓨팅 기기(101)와 네트워크(102)에 각각 연결되어 휴대용 접속제어기(110)를 휴대용 컴퓨팅 기기(101)와 네트워크(102) 사이에 연결할 수 있다. 여기서, 상기 네트워크인터페이스(111)는 무선 또는 유선 방식으로 휴대용 컴퓨팅 기기(101)와 네트워크(102)에 휴대용 접속제어기(110)를 연결할 수 있다.
상기 네트워크접속모듈(112)은 네트워크인터페이스(111)와 연결되어 네트워크(102) 접속을 요청할 수 있다. 여기서, 상기 네트워크접속모듈(112)은 네트워크인터페이스(111)에 휴대용 컴퓨팅 기기(101)와 네트워크(102)가 연결되는 경우, 네트워크(102)와의 접속을 요청할 수 있다. 이때, 상기 네트워크접속모듈(112)은 네트워크인터페이스(111)에 연결되는 휴대용 컴퓨팅 기기(101)가 신규 휴대용 컴퓨팅 기기(101) 인지 확인하는 기기인증을 요청할 수 있다.
상기 네트워크접속제어모듈(113)은 네트워크접속모듈(112)에 연결되어 네트워크 보안정책을 토대로 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속 허용 여부를 결정할 수 있다.
여기서, 상기 네트워크 보안정책은 인증정보, IP 주소, 포트번호, 접속 허용 횟수, 접속 허용 시간, 전송데이터양 중 어느 하나일 수 있다.
한편, 상기 네트워크접속제어모듈(113)은 미리 저장된 인증정보를 토대로 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속 허용 여부를 결정할 수 있다.
구체적으로 상기 네트워크접속제어모듈(113)은, 네트워크접속모듈(112)의 네트워크(102) 접속 요청에 따라 연결된 휴대용 컴퓨팅 기기(101)의 인증정보가 네트워크접속제어모듈(113)에 저장되어 있는지 확인하고, 인증정보가 네트워크접속제어모듈(113)에 저장되어 있는 경우 네트워크(102) 접속을 허용하고, 인증정보가 저장되어있지 않는 경우 네트워크(102) 접속 허용을 불가할 수 있다.
또한, 상기 네트워크접속제어모듈(113)은 미리 저장된 IP 주소를 토대로 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속 허용 여부를 결정할 수 있다.
구체적으로 상기 네트워크접속제어모듈(113)은 네트워크접속모듈(112)의 네트워크(102) 접속 요청에 따라 연결된 휴대용 컴퓨팅 기기(101)의 IP 주소가 네트워크접속제어모듈(113)에 저장되어 있는지 확인하고, IP 주소가 네트워크접속제어모듈(113)에 저장되어 있는 경우 네트워크(102) 접속을 허용하고, IP 주소가 저장되어있지 않는 경우 네트워크(102) 접속 허용을 불가할 수 있다.
아울러, 상기 네트워크접속제어모듈(113)은 미리 저장된 포트정보를 토대로 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속 허용 여부를 결정할 수 있다.
구체적으로 상기 네트워크접속제어모듈(113)은, 네트워크접속모듈(112)의 네트워크(102) 접속 요청에 따라 연결된 휴대용 컴퓨팅 기기(101)의 포트정보가 네트워크접속제어모듈(113)에 저장되어 있는지 확인하고, 포트정보가 저장되어 있는 경우 네트워크(102) 접속을 허용하고, 포트정보가 저장되어있지 않는 경우 네트워크(102) 접속 허용을 불가할 수 있다.
그리고 상기 네트워크접속제어모듈(113)은, 미리 설정된 네트워크 접속 허용 횟수를 토대로 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속 허용 여부를 결정할 수 있다. 이때, 상기 네트워크접속제어모듈(113)에는 휴대용 컴퓨팅 기기(101)별로 네트워크 접속 허용 횟수가 미리 설정될 수 있고, 휴대용 접속제어기(110)별로 네트워크 접속 허용 횟수가 미리 설정될 수 있다.
구체적으로 상기 네트워크접속제어모듈(113)은, 네트워크접속모듈(112)의 네트워크(102) 접속 요청에 따라 네트워크접속제어모듈(113)에 미리 설정된 휴대용 컴퓨팅 기기(101)별 네트워크 접속 허용 횟수와 휴대용 접속제어기(110)별 네트워크 접속 허용 횟수를 확인하고, 연결된 휴대용 컴퓨팅 기기(101)의 네트워크 접속 허용 횟수가 남아있는 경우 해당하는 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속을 허용하고, 네트워크 접속 허용 횟수가 남아있지 않는 경우 해당하는 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속 허용을 불가할 수 있다. 또한, 상기 네트워크접속제어모듈(113)은 휴대용 접속제어기(110)별 네트워크 접속 허용 횟수가 남아있는 경우 연결된 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속을 허용하고, 네트워크 접속 허용 횟수가 남아있지 않는 경우 연결된 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속 허용을 불가할 수 있다.
아울러, 상기 네트워크접속제어모듈(113)은 미리 설정된 접속 허용 시간을 토대로 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속 허용 여부를 결정할 수 있다.
구체적으로 상기 네트워크접속제어모듈(113)은, 네트워크접속모듈(112)의 네트워크(102) 접속 요청에 따라 접속을 요청한 시간이 미리 설정된 접속 허용 시간 내인지 확인하고, 접속 요청 시간이 미리 설정된 접속 허용 시간 내이면 네트워크(102) 접속을 허용하고, 접속 요청 시간이 미리 설정된 접속 허용 시간이 아니면 네트워크(102) 접속 허용을 불가할 수 있다.
한편, 상기 네트워크접속제어모듈(113)은 미리 설정된 전송데이터양을 토대로 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속 허용 여부를 결정할 수 있다.
구체적으로 상기 네트워크접속제어모듈(113)은, 네트워크접속모듈(112)의 네트워크(102) 접속 요청에 따라 미리 설정된 전송데이터양이 남았는지 확인하고, 미리 설정된 전송데이터양이 남았으며 네트워크(102) 접속을 허용하고, 미리 설정된 전송데이터양이 남지 않았으면 네트워크(102) 접속 허용을 불가할 수 있다.
상기 업데이트모듈(114)은 네트워크접속제어모듈(113)에 연결되어 네트워크관리부(120)에서 제공되는 네트워크 보안정책을 업데이트할 수 있다.
여기서, 상기 업데이트모듈(114)은 네트워크관리부(120)와 네트워크(102)를 통해 연결될 수 있다. 즉, 상기 업데이트모듈(114)은 관리자가 네트워크관리부(120)에 네트워크 보안정책을 설정하는 경우, 네트워크관리부(120)에서 제공되는 네트워크 보안정책을 네트워크제어모듈(113)에 수시로 업데이트할 수 있다.
한편, 상기 휴대용 접속제어기(110)는 송수신되는 데이터를 모니터링하는 모니터링모듈(115) 및 모니터링모듈(115)에서 모니터링된 모니터링데이터가 저장되는 저장부(116)를 더 포함할 수 있다.
여기서, 상기 모니터링모듈(115)은 네트워크접속모듈(112)에 연결되어 송수신되는 데이터를 모니터링할 수 있다. 또한, 상기 저장부(116)는 모니터링모듈(115)에서 모니터링된 모니터링데이터가 저장될 수 있다. 즉, 상기 모니터링모듈(115)은 어떠한 데이터가 송수신되는지 모니터링하여 저장부(116)에 저장할 수 있으므로, 보안이 필요한 데이터의 유출을 방지할 수 있다.
한편, 상기 휴대용 접속제어기(110)는 네트워크접속모듈(112)에 연결되어 상기 네트워크 보안정책을 토대로 송수신되는 데이터를 암호화하는 암호화모듈(117)을 더 포함할 수 있다.
여기서, 상기 암호화모듈(117)은 네트워크접속제어모듈(113)에 미리 설정된 IP 주소 또는 포트정보를 토대로 송수신되는 데이터를 암호화할 수 있다.
구체적으로, 상기 네트워크접속모듈(112)에서 송수신되는 데이터에 대한 암호화가 요청되면, 네트워크접속제어모듈(113)은 암호화를 요청하는 IP 주소와 포트정보가 네트워크접속제어모듈(113)에 미리 설정된 IP 주소 또는 포트정보에 해당하는지 확인하고, 이에 해당하는 경우 암화화모듈(117)은 데이터를 암호화하여 송신 및 수신할 수 있다.
이때, 상기 암호화모듈(117)에서 암호화가 수행되는 IP 주소와 포트정보는 업데이트모듈(114)을 통해 네트워크접속제어모듈(113)에 업데이트되어 변경될 수 있다.
따라서, 상기 암호화모듈(117)를 통해 별도의 보안 프로그램을 설치하지 않고도 네트워크(102)를 통해 송수신되는 데이터를 안전하게 보호할 수 있으며, 업데이트모듈(114)을 통해 관리자는 필요에 따라 주요 데이터를 암호화하여 송수신할 수 있도록 제어할 수 있다.
한편, 상기 휴대용 접속제어기(110)는 휴대용 컴퓨팅 기기(101)의 상태 및 네트워크(102) 접속 상태를 표시하는 화면표시부(118)를 더 포함할 수 있다.
여기서, 상기 화면표시부(118)는 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속 여부를 표시할 수 있다.
상기 네트워크관리부(120)는 휴대용 접속제어기(110)에 네트워크(102)를 통해 연결되어 네트워크 보안정책을 제공하며, 휴대용 컴퓨팅 기기(101)의 기기인증을 수행할 수 있다.
여기서, 상기 네트워크관리부(120)는 네트워크(102)를 통해 네트워크 보안정책을 휴대용 접속제어기(110)의 업데이트모듈(114)로 제공할 수 있다.
또한, 상기 네트워크관리부(120)는 휴대용 접속제어기(110)에 연결되는 휴대용 컴퓨팅 기기(101)가 기기인증을 받지 않은 신규 휴대용 컴퓨팅 기기(101)인 경우, 기기인증을 수행할 수 있다.
따라서, 상술한 휴대용 접속제어기(110)를 통해 휴대용 컴퓨팅 기기(101)의 네트워크(102) 접속을 관리함으로써, 관리자가 각각 휴대용 컴퓨팅 기기(101)를 모두 관리할 필요 없이 각각의 사용자가 휴대한 휴대용 접속제어기(110)만을 관리하여 복수의 휴대용 컴퓨팅 기기(101)를 관리할 수 있으므로, 네트워크 보안정책 및 네트워크 접속 관리를 간편하고, 세밀하게 할 수 있다.
또한, 사용자가 휴대한 휴대용 접속제어기(110)를 관리함으로써, 사용자의 권한 및 업무 기능에 따라 네트워크 보안정책 및 네트워크 접속을 제어할 수 있다.
이하, 상술한 네트워크 접속 제어 시스템을 이용한 제어과정을 설명한다.
도 3은 본 발명의 실시예에 따른 네트워크 접속 제어 과정을 나타낸 순서도이다.
도 3에 도시된 바와 같이, 본 발명의 실시예에 따른 네트워크 접속 제어 과정은, 먼저, 휴대용 컴퓨팅 기기(101)가 휴대용 접속제어기(110)에 연결되면, 네트워크 접속을 요청할 수 있다(S1100).
다음으로, 휴대용 접속제어기(110)에서 미리 저장된 인증정보를 토대로 기기인증 여부를 확인하여 신규 휴대용 컴퓨팅 기기(101)인지 확인할 수 있다(S1200).
여기서, 네트워크 접속을 요청한 휴대용 컴퓨팅 기기(101)의 MAC 정보, IP 주소, 사용자정보 등의 기기정보와 휴대용 접속제어기(110)에 미리 저장된 인증정보를 비교하여 이미 기기인증이 수행된 휴대용 컴퓨팅 기기(101)인지를 판단할 수 있다.
다음으로, 휴대용 컴퓨팅 기기(101)의 기기정보를 확인한 결과에 따라 신규 휴대용 컴퓨팅 기기(101)이면, 네트워크관리부(120)에서 기기인증을 수행할 수 있다(S1300).
여기서, 네트워크 접속을 요청한 휴대용 컴퓨팅 기기(101)가 신규 휴대용 컴퓨팅 기기(101)인 경우, 휴대용 컴퓨팅 기기(101)에 기기인증을 위한 정보를 요청하여 수신하고, 이를 네트워크관리부(120)로 전송할 수 있다.
이후, 네트워크관리부(120)는 기기인증을 위한 정보가 수신되면, 수신되는 정보를 토대로 휴대용 컴퓨팅 기기(101)를 네트워크(102)의 접속을 허용할지를 판단할 수 있다.
다음으로, 네트워크(102)의 접속을 허용하는 경우, 해당 휴대용 컴퓨팅 기기(101)의 등록을 원하는 사용자에게 비밀번호와 같은 별도의 추가인증정보의 입력을 요청하여 추가인증정보를 수신하고, 수신된 추가인증정보와 기기인증을 위한 정보를 토대로 기기인증을 수행할 수 있다.
이때, 휴대용 컴퓨팅 기기(101)의 기기인증이 수행되지 않는 경우, 휴대용 접속제어기(110)로 기기인증 불가 메시지를 송신하여 화면표시부(118)에 기기인증 불가 메시지를 표시할 수 있다.
다음으로, 휴대용 접속제어기(110)에서 휴대용 컴퓨팅 기기(101)의 기기인증이 확인되면, 휴대용 접속제어기(110)는 네트워크관리부(120)에서 제공되는 네트워크 보안정책을 토대로 휴대용 컴퓨팅 기기(101)의 네트워크 접속 허용 여부를 결정할 수 있다(S1400).
여기서, 상기 네트워크 보안정책은 IP 주소, 포트번호, 접속 허용 횟수, 접속 허용 시간, 전송데이터양 중 어느 하나일 수 있다.
구체적으로, 네트워크 접속을 요청하는 휴대용 컴퓨팅 기기(101)의 IP 주소 및 포트번호가 네트워크관리부(120)에서 제공되는 IP 주소 및 포트번호와 동일한 경우 네트워크(102) 접속을 허용하고, 동일하지 않는 경우 네트워크(102) 접속 허용을 불가할 수 있다.
또한, 네트워크 접속을 요청하는 휴대용 컴퓨팅 기기(101)에 대응하여 네트워크관리부(120)에서 제공되는 접속 허용 횟수가 미리 설정된 접속 허용 횟수를 초과하지 않는 경우 네트워크(102) 접속을 허용하고, 미리 설정된 접속 허용 횟수를 초과하는 경우 네트워크(102) 접속 허용을 불가할 수 있다.
아울러, 네트워크 접속을 요청하는 휴대용 컴퓨팅 기기(101)에 대응하여 네트워크관리부(120)에서 제공되는 접속 허용 시간이 미리 설정된 접속 허용 시간 내인 경우 네트워크(102) 접속을 허용하고, 미리 설정된 접속 허용 시간이 아닌 경우 네트워크(102) 접속 허용을 불가할 수 있다.
그리고 네트워크 접속을 요청하는 휴대용 컴퓨팅 기기(101)에 대응하여 네트워크관리부(120)에서 제공되는 전송데이터양이 미리 설정된 전송데이터양을 초과하지 않는 경우 네트워크(102) 접속을 허용하고, 미리 설정된 전송데이터양을 초과한 경우 네트워크(102) 접속 허용을 불가할 수 있다.
본 명세서에서 '연결된다' 또는 '연결하는' 등과 이런 표현의 다양한 변형들의 지칭은 다른 구성요소와 직접적으로 연결되거나 다른 구성요소를 통해 간접적으로 연결되는 것을 포함하는 의미로 사용된다. 또한, 본 명세서에서 단수형은 문구에서 특별히 언급하지 않는 한 복수형도 포함한다. 아울러 본 명세서에서 사용되는 '포함한다' 또는 '포함하는'으로 언급된 구성요소, 단계, 동작 및 소자는 하나 이상의 다른 구성요소, 단계, 동작, 소자 및 장치의 존재 또는 추가를 배제하지 않는다.
이제까지 본 발명에 대하여 그 바람직한 실시예들을 중심으로 살펴보았다. 본 명세서를 통해 개시된 모든 실시예들과 조건부 예시들은, 본 발명의 기술 분야에서 통상의 지식을 가진 당업자가 독자가 본 발명의 원리와 개념을 이해하도록 돕기 위한 의도로 기술된 것으로, 당업자는 본 발명이 본 발명의 본질적인 특성에서 벗어나지 않는 범위에서 변형된 형태로 구현될 수 있음을 이해할 수 있을 것이다. 그러므로 개시된 실시예들은 한정적인 관점이 아니라 설명적인 관점에서 고려되어야 한다. 본 발명의 범위는 전술한 설명이 아니라 특허청구범위에 나타나 있으며, 그와 동등한 범위 내에 있는 모든 차이점은 본 발명에 포함된 것으로 해석되어야 할 것이다.
(부호의 설명)
101 : 휴대용 컴퓨팅 기기 102 : 네트워크
110 : 휴대용 접속제어기 111 : 네트워크인터페이스
112 : 네트워크접속모듈 113 : 네트워크접속제어모듈
114 : 업데이트모듈 115 : 모니터링모듈
116 : 저장부 117 : 암호화모듈
118 : 화면보시부 120 : 네트워크관리부

Claims (18)

  1. 네트워크 접속이 가능한 휴대용 컴퓨팅 기기에 연결되어 네트워크 보안정책을 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속을 관리하는 휴대용 접속제어기; 및
    상기 휴대용 접속제어기에 상기 네트워크를 통해 연결되어 상기 휴대용 접속제어기에 상기 네트워크 보안정책을 제공하며, 상기 휴대용 컴퓨팅 기기의 기기인증을 수행하는 네트워크관리부;
    를 포함하는 네트워크 접속 제어 시스템.
  2. 제1항에 있어서,
    상기 휴대용 접속제어기는
    다수의 휴대용 컴퓨팅 기기 중 적어도 어느 하나와 연결되는 네트워크 접속 제어 시스템.
  3. 제1항에 있어서,
    상기 휴대용 접속제어기는
    상기 휴대용 컴퓨팅 기기와 상기 네트워크에 각각 연결되는 네트워크인터페이스;
    상기 네트워크인터페이스와 연결되어 네트워크 접속을 요청하는 네트워크접속모듈;
    상기 네트워크접속모듈에 연결되어 상기 네트워크 보안정책을 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크접속제어모듈; 및
    상기 네트워크접속제어모듈에 연결되어 상기 네트워크관리부에서 제공되는 상기 네트워크 보안정책을 업데이트하는 업데이트모듈;
    을 포함하는 네트워크 접속 제어 시스템.
  4. 제3항에 있어서,
    상기 휴대용 접속제어기는
    상기 네트워크접속모듈에 연결되어 송수신되는 상기 데이터를 모니터링하는 모니터링모듈; 및
    상기 모니터링모듈에서 모니터링한 모니터링데이터를 저장하는 저장부를 더 포함하는 네트워크 접속 제어 시스템.
  5. 제3항에 있어서,
    상기 휴대용 접속제어기는
    상기 네트워크접속모듈에 연결되어 상기 네트워크 보안정책을 토대로 송수신되는 상기 데이터를 암호화하는 암호화모듈을 더 포함하는 네트워크 접속 제어 시스템.
  6. 제3항에 있어서,
    상기 휴대용 접속제어기는
    상기 휴대용 컴퓨팅 기기의 상태 및 네트워크 접속 상태를 표시하는 화면 표시부를 더 포함하는 네트워크 접속 제어 시스템.
  7. 제3항에 있어서,
    상기 네트워크접속제어모듈은
    미리 저장된 인증정보를 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크 접속 제어 시스템.
  8. 제3항에 있어서,
    상기 네트워크접속제어모듈은
    미리 저장된 IP 주소를 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크 접속 제어 시스템.
  9. 제3항에 있어서,
    상기 네트워크접속제어모듈은
    미리 저장된 포트정보를 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크 접속 제어 시스템.
  10. 제3항에 있어서,
    상기 네트워크접속제어모듈은
    미리 설정된 네트워크 접속 허용 횟수를 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크 접속 제어 시스템.
  11. 제3항에 있어서,
    상기 네트워크접속제어모듈은
    미리 설정된 네트워크 접속 허용 시간을 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크 접속 제어 시스템.
  12. 제3항에 있어서,
    상기 네트워크접속제어모듈은
    미리 설정된 전송데이터양을 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크 접속 제어 시스템.
  13. 휴대용 컴퓨팅 기기가 휴대용 접속제어기에 연결되면, 네트워크 접속을 요청하는 접속 요청 단계;
    상기 휴대용 접속제어기에서 미리 저장된 인증정보를 토대로 기기인증 여부를 확인하여 신규 휴대용 컴퓨팅 기기인지 확인하는 기기정보 확인 단계;
    상기 휴대용 컴퓨팅 기기의 기기정보를 확인한 결과에 따라 신규 휴대용 컴퓨팅 기기이면, 네트워크관리부에서 기기인증을 수행하는 기기인증 단계;
    상기 휴대용 접속제어기에서 상기 휴대용 컴퓨팅 기기의 기기인증이 확인되면, 상기 네트워크관리부에서 제공되는 네트워크 보안정책을 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크 접속 결정 단계;
    를 포함하는 네트워크 접속 제어 방법.
  14. 제13항에 있어서,
    상기 네트워크 접속 결정 단계는,
    상기 네트워크관리부에서 제공되는 IP 주소를 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크 접속 제어 방법.
  15. 제13항에 있어서,
    상기 네트워크 접속 결정 단계는,
    상기 네트워크관리부에서 제공되는 포트정보를 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크 접속 제어 방법.
  16. 제13항에 있어서,
    상기 네트워크 접속 결정 단계는,
    상기 네트워크관리부에서 제공되는 네트워크 접속 허용 횟수를 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크 접속 제어 방법.
  17. 제13항에 있어서,
    상기 네트워크 접속 결정 단계는,
    상기 네트워크관리부에서 제공되는 네트워크 접속 허용 시간을 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크 접속 제어 방법.
  18. 제13항에 있어서,
    상기 네트워크 접속 결정 단계는,
    상기 네트워크관리부에서 제공되는 전송데이터양을 토대로 상기 휴대용 컴퓨팅 기기의 네트워크 접속 허용 여부를 결정하는 네트워크 접속 제어 방법.
PCT/KR2016/015191 2016-01-26 2016-12-23 네트워크 접속 제어 시스템 및 제어 방법 Ceased WO2017131346A1 (ko)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
KR1020160009386A KR101869347B1 (ko) 2016-01-26 2016-01-26 네트워크 접속 제어 시스템 및 제어 방법
KR10-2016-0009386 2016-01-26

Publications (2)

Publication Number Publication Date
WO2017131346A1 true WO2017131346A1 (ko) 2017-08-03
WO2017131346A9 WO2017131346A9 (ko) 2017-09-08

Family

ID=59398461

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2016/015191 Ceased WO2017131346A1 (ko) 2016-01-26 2016-12-23 네트워크 접속 제어 시스템 및 제어 방법

Country Status (2)

Country Link
KR (1) KR101869347B1 (ko)
WO (1) WO2017131346A1 (ko)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2004272792A (ja) * 2003-03-11 2004-09-30 Toshiba Corp ネットワークアクセス制御方法、情報提供装置及び証明書発行装置
JP2009521820A (ja) * 2005-12-26 2009-06-04 パナソニック株式会社 モバイルネットワーク管理装置及び移動情報管理装置
JP4832516B2 (ja) * 2006-05-26 2011-12-07 富士通株式会社 ネットワークアクセス制御方法、ネットワークアクセス制御システム、認証処理装置、アクセス制御装置、代理要求装置およびアクセス要求装置
JP2015038667A (ja) * 2011-10-18 2015-02-26 株式会社ベーシック アプリケーションマネージャ及びネットワークアクセス制御システム
JP2015166966A (ja) * 2014-03-04 2015-09-24 株式会社エヌワーク 通信管理システム

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20130040662A (ko) 2011-10-14 2013-04-24 최중락 휴대용 저장 장치에 방화벽 시스템 구축 및 방법

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2004272792A (ja) * 2003-03-11 2004-09-30 Toshiba Corp ネットワークアクセス制御方法、情報提供装置及び証明書発行装置
JP2009521820A (ja) * 2005-12-26 2009-06-04 パナソニック株式会社 モバイルネットワーク管理装置及び移動情報管理装置
JP4832516B2 (ja) * 2006-05-26 2011-12-07 富士通株式会社 ネットワークアクセス制御方法、ネットワークアクセス制御システム、認証処理装置、アクセス制御装置、代理要求装置およびアクセス要求装置
JP2015038667A (ja) * 2011-10-18 2015-02-26 株式会社ベーシック アプリケーションマネージャ及びネットワークアクセス制御システム
JP2015166966A (ja) * 2014-03-04 2015-09-24 株式会社エヌワーク 通信管理システム

Also Published As

Publication number Publication date
WO2017131346A9 (ko) 2017-09-08
KR20170089235A (ko) 2017-08-03
KR101869347B1 (ko) 2018-06-21

Similar Documents

Publication Publication Date Title
WO2013183814A1 (ko) 개선된 보안 기능 기반의 클라우드 서비스 시스템 및 이를 지원하는 방법
WO2014185594A1 (ko) Vdi 환경에서의 싱글 사인온 시스템 및 방법
WO2013062352A1 (ko) 클라우드 컴퓨팅 서비스에서의 접근제어 방법 및 시스템
WO2013100419A1 (ko) 애플릿 액세스 제어 시스템 및 방법
WO2014058130A1 (ko) 네트워크 드라이브 접근 제어 방법 및 네트워크 드라이브 시스템
WO2013191325A1 (ko) 트러스티드 플랫폼 기반의 개방형 아이디 인증 방법, 이를 위한 장치 및 시스템
WO2015030511A1 (ko) 단말 보호를 위한 단말 장치와 그 단말 보호 방법 및 단말 관리 서버 장치
WO2014003516A1 (ko) 데이터 공유 제공 방법 및 장치
WO2018151480A1 (ko) 인증 관리 방법 및 시스템
WO2024071535A1 (ko) Saas 기반 데이터베이스 접근제어 게이트웨이 서비스 시스템 및 방법
WO2020045826A1 (ko) 디지털 키를 처리하는 전자 디바이스 및 그 동작 방법
WO2014175704A1 (ko) 웹사이트 로그인 및 개인정보 보안을 위한 홍채인증 시스템 및 그 방법
WO2021096001A1 (ko) 프라이빗 블록체인 기반 모바일 디바이스 관리 방법 및 시스템
WO2014181970A1 (ko) 휴대 단말의 어플리케이션 데이터 관리 방법 및 그 장치
WO2023113081A1 (ko) 클라우드 환경 내 이벤트 스트림 방식의 컨테이너 워크로드 실행 제어 방법, 장치 및 컴퓨터-판독 가능 기록 매체
WO2018169150A1 (ko) 잠금화면 기반의 사용자 인증 시스템 및 방법
WO2016190663A1 (ko) 홈 네트워크 시스템에서의 보안 관리 장치 및 보안 관리 방법
WO2016085050A1 (ko) 주변기기와 연동하는 사용자 단말기 및 그것을 이용한 정보 유출 방지 방법
WO2023204414A1 (ko) 스마트 공장의 자산 정보에 대한 접근 관리 시스템 및 방법
WO2018016830A1 (ko) 파일 암호화 방지 장치 및 방법
WO2015182873A1 (ko) Dns 서버 선별 차단 및 proxy를 이용한 dns 주소 변경 방법
WO2016108478A1 (ko) 데이터 접근 관리 방법, 이를 위한 컴퓨터 프로그램, 그 기록매체
WO2017131346A1 (ko) 네트워크 접속 제어 시스템 및 제어 방법
WO2021020918A1 (ko) 논리적 내부 네트워크를 제공하는 방법, 이를 구현하는 모바일 단말 및 어플리케이션
EP4483565A1 (en) Method and electronic device of forwarding traffic

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16888322

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16888322

Country of ref document: EP

Kind code of ref document: A1