CN106411857B - A kind of private clound GIS service access control method based on virtual isolation mech isolation test - Google Patents
A kind of private clound GIS service access control method based on virtual isolation mech isolation test Download PDFInfo
- Publication number
- CN106411857B CN106411857B CN201610807010.5A CN201610807010A CN106411857B CN 106411857 B CN106411857 B CN 106411857B CN 201610807010 A CN201610807010 A CN 201610807010A CN 106411857 B CN106411857 B CN 106411857B
- Authority
- CN
- China
- Prior art keywords
- service
- gis
- tenant
- data
- access
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Classifications
- 
        - H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
 
- 
        - G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
 
- 
        - H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/46—Interconnection of networks
- H04L12/4641—Virtual LANs, VLANs, e.g. virtual private networks [VPN]
 
- 
        - H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
 
- 
        - H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
 
- 
        - H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/50—Network services
- H04L67/52—Network services specially adapted for the location of the user terminal
 
Landscapes
- Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Computing Systems (AREA)
- Theoretical Computer Science (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Storage Device Security (AREA)
Abstract
本发明公开一种基于虚拟隔离机制的私有云GIS服务访问控制方法,依次包括以下步骤:(1)网络控制:(2)数据隔离与访问控制:(3)云GIS服务接口策略。本发明在私有云平台环境中为多租户GIS服务的使用设计一套安全隔离、访问控制和通信机制,使得私有云平台能具有多租户处理地理空间数据的能力,能提高GIS服务处理的安全性,达到变地理空间数据为资产的目的。
The invention discloses a private cloud GIS service access control method based on a virtual isolation mechanism, which sequentially includes the following steps: (1) network control: (2) data isolation and access control: (3) cloud GIS service interface strategy. The present invention designs a set of security isolation, access control and communication mechanisms for the use of multi-tenant GIS services in the private cloud platform environment, so that the private cloud platform can have the ability of multi-tenant processing of geospatial data, and can improve the security of GIS service processing , to achieve the purpose of turning geospatial data into assets.
Description
Claims (4)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title | 
|---|---|---|---|
| CN201610807010.5A CN106411857B (en) | 2016-09-07 | 2016-09-07 | A kind of private clound GIS service access control method based on virtual isolation mech isolation test | 
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title | 
|---|---|---|---|
| CN201610807010.5A CN106411857B (en) | 2016-09-07 | 2016-09-07 | A kind of private clound GIS service access control method based on virtual isolation mech isolation test | 
Publications (2)
| Publication Number | Publication Date | 
|---|---|
| CN106411857A CN106411857A (en) | 2017-02-15 | 
| CN106411857B true CN106411857B (en) | 2019-03-29 | 
Family
ID=57999565
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date | 
|---|---|---|---|
| CN201610807010.5A Active CN106411857B (en) | 2016-09-07 | 2016-09-07 | A kind of private clound GIS service access control method based on virtual isolation mech isolation test | 
Country Status (1)
| Country | Link | 
|---|---|
| CN (1) | CN106411857B (en) | 
Families Citing this family (16)
| Publication number | Priority date | Publication date | Assignee | Title | 
|---|---|---|---|---|
| CN106685994A (en) * | 2017-02-22 | 2017-05-17 | 河海大学 | A cloud GIS resource access control method based on GIS role level authority | 
| CN109787938B (en) * | 2017-11-14 | 2021-04-30 | 中国电信股份有限公司 | Method and device for realizing access to virtual private cloud and computer readable storage medium | 
| CN107819875B (en) * | 2017-11-27 | 2021-04-09 | 深信服科技股份有限公司 | Method and device for sharing service exclusively by user under cloud platform | 
| CN108270858A (en) * | 2018-01-15 | 2018-07-10 | 郑州云海信息技术有限公司 | A kind of private cloud framework and its data processing method based on API gateway | 
| CN108846634B (en) * | 2018-05-30 | 2022-08-12 | 北京尚易德科技有限公司 | A kind of case automatic authorization method and system | 
| CN108810024A (en) * | 2018-07-19 | 2018-11-13 | 广东浪潮大数据研究有限公司 | A kind of isolation network data transmission method, device, medium, management platform | 
| CN110109731B (en) * | 2019-04-19 | 2021-02-09 | 苏州浪潮智能科技有限公司 | A management method and system for a virtual root of trust in a cloud environment | 
| CN110417863B (en) * | 2019-06-27 | 2021-01-29 | 华为技术有限公司 | Method and device for generating identity identification code and method and device for authenticating identity | 
| CN110827167A (en) * | 2019-09-29 | 2020-02-21 | 武汉开目信息技术股份有限公司 | Product design manufacturability knowledge sharing method and device for collaborative manufacturing | 
| CN110826101B (en) * | 2019-11-05 | 2021-01-05 | 安徽数据堂科技有限公司 | Privatization deployment data processing method for enterprise | 
| CN111432024B (en) * | 2020-04-09 | 2022-11-04 | 兰州聚源信息科技有限公司 | Construction method of composite cloud training platform based on SCORM technology | 
| CN112532474B (en) * | 2020-11-19 | 2022-08-19 | 用友网络科技股份有限公司 | Control method and device of data management system and readable storage medium | 
| CN112637232B (en) * | 2020-12-29 | 2022-09-27 | 国云科技股份有限公司 | Cloud platform resource isolation framework implementation method and device supporting multiple strategies | 
| CN114398457A (en) * | 2021-12-31 | 2022-04-26 | 核工业北京地质研究院 | A method for accessing, displaying and managing MapGIS and ArcGIS services based on OGC standards | 
| CN115604028A (en) * | 2022-11-28 | 2023-01-13 | 北京鸿迪鑫业科技有限公司(Cn) | Cloud server data security protection system | 
| CN116910015B (en) * | 2023-09-12 | 2024-01-19 | 苏州浪潮智能科技有限公司 | Storage platform service method, device, equipment and storage medium | 
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title | 
|---|---|---|---|---|
| CN102708316A (en) * | 2012-04-19 | 2012-10-03 | 北京华胜天成科技股份有限公司 | Method for isolating data in multi-tenant architecture | 
| CN102307185B (en) * | 2011-06-27 | 2015-02-25 | 北京大学 | Data isolation method used in storage cloud | 
| CN103067406B (en) * | 2013-01-14 | 2015-07-22 | 暨南大学 | Access control system and access control method between public cloud and private cloud | 
| CN105591863A (en) * | 2014-10-20 | 2016-05-18 | 中兴通讯股份有限公司 | Method and device for realizing interworking between virtual private cloud network and external network | 
- 
        2016
        - 2016-09-07 CN CN201610807010.5A patent/CN106411857B/en active Active
 
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title | 
|---|---|---|---|---|
| CN102307185B (en) * | 2011-06-27 | 2015-02-25 | 北京大学 | Data isolation method used in storage cloud | 
| CN102708316A (en) * | 2012-04-19 | 2012-10-03 | 北京华胜天成科技股份有限公司 | Method for isolating data in multi-tenant architecture | 
| CN103067406B (en) * | 2013-01-14 | 2015-07-22 | 暨南大学 | Access control system and access control method between public cloud and private cloud | 
| CN105591863A (en) * | 2014-10-20 | 2016-05-18 | 中兴通讯股份有限公司 | Method and device for realizing interworking between virtual private cloud network and external network | 
Non-Patent Citations (3)
| Title | 
|---|
| 一种基于虚拟隔离机制的安全私有云存储系统;鲍爱华等;《计算机科学》;20140115(第1期);第202-207页 | 
| 云GIS平台构建的关键技术研究;唐权等;《测绘与空间地理信息》;20160325(第3期);第32-36页 | 
| 基于ArcGIS的云GIS平台设计方案研究;曹全龙等;《测绘与空间地理信息》;20141025;第37卷(第10期);第36-38页 | 
Also Published As
| Publication number | Publication date | 
|---|---|
| CN106411857A (en) | 2017-02-15 | 
Similar Documents
| Publication | Publication Date | Title | 
|---|---|---|
| CN106411857B (en) | A kind of private clound GIS service access control method based on virtual isolation mech isolation test | |
| CN108293045B (en) | Single sign-on identity management between local and remote systems | |
| US10623406B2 (en) | Access authentication for cloud-based shared content | |
| US9047462B2 (en) | Computer account management system and realizing method thereof | |
| US9787659B2 (en) | Techniques for secure access management in virtual environments | |
| US10148637B2 (en) | Secure authentication to provide mobile access to shared network resources | |
| US8978122B1 (en) | Secure cross-tenancy federation in software-as-a-service system | |
| US9998446B2 (en) | Accessing a cloud-based service platform using enterprise application authentication | |
| RU2598324C2 (en) | Means of controlling access to online service using conventional catalogue features | |
| CN105247830B (en) | Provides mobile device management capabilities | |
| CN105991734B (en) | A kind of cloud platform management method and system | |
| US9215225B2 (en) | Mobile device locking with context | |
| CN105247531A (en) | Providing managed browser | |
| CN106375323A (en) | Kerberos identity authentication method in multi-tenant mode | |
| JP2015537269A (en) | LDAP-based multi-tenant in-cloud identity management system | |
| CN105074713A (en) | Systems and methods for identifying a secure application when connecting to a network | |
| US9130904B2 (en) | Externally and internally accessing local NAS data through NSFV3 and 4 interfaces | |
| US10911299B2 (en) | Multiuser device staging | |
| CN110636057A (en) | Application access method and device and computer readable storage medium | |
| RU2415466C1 (en) | Method of controlling identification of users of information resources of heterogeneous computer network | |
| CN106375334A (en) | An Authentication Method for Distributed System | |
| KR20060062319A (en) | Home network gateway that manages authority assignment and access for each user and control method | |
| US11411813B2 (en) | Single user device staging | |
| Wei et al. | A VDI system based on cloud stack and active directory | |
| CN107608768A (en) | Resource access method, electronic equipment and storage medium based on command mode | 
Legal Events
| Date | Code | Title | Description | 
|---|---|---|---|
| C06 | Publication | ||
| PB01 | Publication | ||
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| GR01 | Patent grant | ||
| GR01 | Patent grant | ||
| CB03 | Change of inventor or designer information | ||
| CB03 | Change of inventor or designer information | Inventor after: Ge Ying Inventor before: Ge Ying Inventor before: AISIKAER.ABULIMITI Inventor before: Chen Gangrui | |
| TR01 | Transfer of patent right | ||
| TR01 | Transfer of patent right | Effective date of registration: 20211227 Address after: 200241 330, floor 3, building 2, No. 588, Zixing Road, Minhang District, Shanghai Patentee after: Shanghai Nongsheng Intelligent Technology Co.,Ltd. Address before: No.8, Fucheng West Road, Jiangning Development Zone, Nanjing, Jiangsu Province Patentee before: HOHAI University | |
| TR01 | Transfer of patent right | ||
| TR01 | Transfer of patent right | Effective date of registration: 20240329 Address after: Room 05, 12th Floor, Building D2, No. 32 Dazhou Road, Yuhuatai District, Nanjing City, Jiangsu Province, 210000 Patentee after: Nanjing Pintu Surveying and Mapping Technology Co.,Ltd. Country or region after: China Address before: 200241 330, floor 3, building 2, No. 588, Zixing Road, Minhang District, Shanghai Patentee before: Shanghai Nongsheng Intelligent Technology Co.,Ltd. Country or region before: China |