System and method for storing data-network activity information
    1.
    发明申请
    System and method for storing data-network activity information 审中-公开
    用于存储数据网络活动信息的系统和方法

    公开(公告)号:US20070180101A1

    公开(公告)日:2007-08-02

    申请号:US11328823

    申请日:2006-01-10

    IPC分类号: G06F17/00 G06F15/173

    CPC分类号: H04L67/22 H04L63/0227

    摘要: A system and method are disclosed that may include receiving a first event log for a data network user; identifying the user that is the subject of the first event log; updating a user activity record, within stored user activity records, with activity information included in the first event log, the activity information being represented in a first format in the first event log; and repeating the steps of receiving, identifying, and updating for at least one additional event log having activity information stored therein in at least one format other than the first format.

    摘要翻译: 公开了一种可以包括接收数据网络用户的第一事件日志的系统和方法; 识别作为第一事件日志主题的用户; 在所存储的用户活动记录中,使用包括在所述第一事件日志中的活动信息来更新用户活动记录,所述活动信息以所述第一事件日志中的第一格式表示; 并且以除了第一格式之外的至少一种格式重复对存储有活动信息的至少一个附加事件日志进行接收,识别和更新的步骤。

    System and Method to Associate a Private User Identity with a Public User Identity
    5.
    发明申请
    System and Method to Associate a Private User Identity with a Public User Identity 有权
    将私人用户身份与公共用户身份相关联的系统和方法

    公开(公告)号:US20100217819A1

    公开(公告)日:2010-08-26

    申请号:US12771491

    申请日:2010-04-30

    IPC分类号: G06F15/16

    摘要: The inventive system includes a host, a network including a security gateway, and a public application. Established are an access session between the network and the host and an application session between the public application and the network. An application session record is created for the application session, and includes the user's public user identity used to access the public application, the user's private user identity used to access the network, a host identity, and an application session time. To determine the private user identity for the application session, the security gateway sends a query with the host identity and the application session time. These are compared with the host identity and access session time in an access session record. If they match, then the private user identity in the access session record is returned, and it is stored as the private user identity in the application session record.

    摘要翻译: 本发明的系统包括主机,包括安全网关的网络和公共应用。 建立在网络和主机之间的访问会话以及公共应用程序和网络之间的应用程序会话。 为应用会话创建应用会话记录,并且包括用于访问公共应用的用户的公共用户标识,用于访问网络的用户的私有用户标识,主机标识和应用会话时间。 为了确定应用程序会话的私有用户身份,安全网关发送具有主机标识和应用程序会话时间的查询。 这些与访问会话记录中的主机身份和访问会话时间进行比较。 如果匹配,则返回访问会话记录中的私有用户身份,并将其作为私有用户身份存储在应用程序会话记录中。

    System and method to associate a private user identity with a public user identity
    6.
    发明授权
    System and method to associate a private user identity with a public user identity 有权
    将私有用户身份与公共用户身份相关联的系统和方法

    公开(公告)号:US07716378B2

    公开(公告)日:2010-05-11

    申请号:US11582613

    申请日:2006-10-17

    IPC分类号: G06F15/16 G06F15/173 H04W4/00

    摘要: The inventive system includes a host, a network including a security gateway, and a public application. Established are an access session between the network and the host and an application session between the public application and the network. An application session record is created for the application session, and includes the user's public user identity used to access the public application, the user's private user identity used to access the network, a host identity, and an application session time. To determine the private user identity for the application session, the security gateway sends a query with the host identity and the application session time. These are compared with the host identity and access session time in an access session record. If they match, then the private user identity in the access session record is returned, and it is stored as the private user identity in the application session record.

    摘要翻译: 本发明的系统包括主机,包括安全网关的网络和公共应用。 建立在网络和主机之间的访问会话以及公共应用程序和网络之间的应用程序会话。 为应用会话创建应用会话记录,并且包括用于访问公共应用的用户的公共用户标识,用于访问网络的用户的私有用户标识,主机标识和应用会话时间。 为了确定应用程序会话的私有用户身份,安全网关发送具有主机标识和应用程序会话时间的查询。 这些与访问会话记录中的主机身份和访问会话时间进行比较。 如果匹配,则返回访问会话记录中的私有用户身份,并将其作为私有用户身份存储在应用程序会话记录中。

    Systems and methods for user access authentication based on network access point
    7.
    发明申请
    Systems and methods for user access authentication based on network access point 有权
    基于网络接入点的用户接入认证系统和方法

    公开(公告)号:US20070271598A1

    公开(公告)日:2007-11-22

    申请号:US11435043

    申请日:2006-05-16

    摘要: Systems and methods of authenticating user access based on an access point to a secure data network include a secure data network having a plurality of a network access points serving as entry points for a user to access the secure data network using a user device. The user is associated with a user identity, each network access point with a network access point identity. The user uses a user device to send an access request, requesting access to the secure data network, to the network access point, which then sends an authentication request to an identity server. The identity server processes the authentication request, by validating the combination of the user identity and the network access point identity, and responds with an authentication response, granting or denying access, as communicated to the user device via an access response. The secure data network may comprise an application level secure data network, in which the user uses the user device to request access to a network application. Furthermore, the identity server may validate the combined user identity and network access point identity data in conjunction with time information, access allowance data, and/or traffic volume data.

    摘要翻译: 基于对安全数据网络的接入点认证用户接入的系统和方法包括具有多个网络接入点的安全数据网络,该网络接入点用作用户使用用户设备访问安全数据网络的入口点。 用户与用户身份相关联,每个网络接入点具有网络接入点身份。 用户使用用户设备向网络接入点发送访问安全数据网络的访问请求,网络接入点然后向认证服务器发送认证请求。 身份服务器通过验证用户身份和网络接入点身份的组合来处理身份验证请求,并通过访问响应传达给用户设备的认证响应,授予或拒绝访问进行响应。 安全数据网络可以包括应用级安全数据网络,其中用户使用用户设备来请求对网络应用的访问。 此外,身份服务器可以结合时间信息,访问允许数据和/或业务量数据来验证组合的用户身份和网络接入点身份数据。

    System and method to associate a private user identity with a public user identity
    8.
    发明授权
    System and method to associate a private user identity with a public user identity 有权
    将私有用户身份与公共用户身份相关联的系统和方法

    公开(公告)号:US08423676B2

    公开(公告)日:2013-04-16

    申请号:US13462822

    申请日:2012-05-03

    IPC分类号: G06F15/16 G06F15/173

    摘要: The inventive system includes a host, a network including a security gateway, and a public application. Established are an access session between the network and the host and an application session between the public application and the network. An application session record is created for the application session, and includes the user's public user identity used to access the public application, the user's private user identity used to access the network, a host identity, and an application session time. To determine the private user identity for the application session, the security gateway sends a query with the host identity and the application session time. These are compared with the host identity and access session time in an access session record. If they match, then the private user identity in the access session record is returned, and it is stored as the private user identity in the application session record.

    摘要翻译: 本发明的系统包括主机,包括安全网关的网络和公共应用。 建立在网络和主机之间的访问会话以及公共应用程序和网络之间的应用程序会话。 为应用会话创建应用会话记录,并且包括用于访问公共应用的用户的公共用户标识,用于访问网络的用户的私有用户标识,主机标识和应用会话时间。 为了确定应用程序会话的私有用户身份,安全网关发送具有主机标识和应用程序会话时间的查询。 这些与访问会话记录中的主机身份和访问会话时间进行比较。 如果匹配,则返回访问会话记录中的私有用户身份,并将其作为私有用户身份存储在应用程序会话记录中。

    Systems and Methods for User Access Authentication Based on Network Access Point
    9.
    发明申请
    Systems and Methods for User Access Authentication Based on Network Access Point 有权
    基于网络接入点的用户接入认证系统与方法

    公开(公告)号:US20120204236A1

    公开(公告)日:2012-08-09

    申请号:US13423953

    申请日:2012-03-19

    IPC分类号: G06F21/20

    摘要: Systems and methods of authenticating user access based on an access point to a secure data network include a secure data network having a plurality of a network access points serving as entry points for a user to access the secure data network using a user device. The user is associated with a user identity, each network access point with a network access point identity. The user uses a user device to send an access request, requesting access to the secure data network, to the network access point, which then sends an authentication request to an identity server. The identity server processes the authentication request, by validating the combination of the user identity and the network access point identity, and responds with an authentication response, granting or denying access, as communicated to the user device via an access response.

    摘要翻译: 基于对安全数据网络的接入点认证用户接入的系统和方法包括具有多个网络接入点的安全数据网络,该网络接入点用作用户使用用户设备访问安全数据网络的入口点。 用户与用户身份相关联,每个网络接入点具有网络接入点身份。 用户使用用户设备向网络接入点发送访问安全数据网络的访问请求,网络接入点然后向认证服务器发送认证请求。 身份服务器通过验证用户身份和网络接入点身份的组合来处理身份验证请求,并通过访问响应传达给用户设备的认证响应,授予或拒绝访问进行响应。

    System and method to resolve an identity interactively
    10.
    发明授权
    System and method to resolve an identity interactively 有权
    以交互方式解析身份的系统和方法

    公开(公告)号:US07647635B2

    公开(公告)日:2010-01-12

    申请号:US11592473

    申请日:2006-11-02

    IPC分类号: G06F11/30 G06F15/173

    摘要: A system and method for resolving an identity includes a security console, which displays security information regarding a secure network. The security information includes at least a first identity used to access the secure network. An operator selects the first identity, and the security console sends it to a resolver. The resolver connects with an identity server to find an access session record with an identity matching the first identity. A second identity is extracted from this record, and the resolver returns a result that includes the second identity. The security console displays the second identity; The first identity can be a user identity of a user, where the second identity is corresponding host identity, or vise versa. In this manner, an efficient interface to security information is provided to an operator, where the operator may resolve a user/host identity to a host/user identity interactively.

    摘要翻译: 用于解决身份的系统和方法包括安全控制台,其显示关于安全网络的安全信息。 安全信息至少包括用于访问安全网络的第一身份。 操作员选择第一个身份,安全控制台将其发送到解析器。 解析器与身份服务器连接,以查找具有与第一身份匹配的身份的访问会话记录。 从该记录中提取第二个身份,解析器返回包含第二个身份的结果。 安全控制台显示第二个身份; 第一身份可以是用户的用户身份,其中第二身份是相应的主机身份,反之亦然。 以这种方式,向运营商提供对安全信息的有效接口,其中运营商可以交互地将用户/主机身份解析为主机/用户身份。