为应对身份认证及权限控制等安全问题,构建可信的网络环境,完备、高性能的网络准入控制系统,通过分析准入控制系统的研究现状,结合实际工作中对于网络资源的优化分配、网络行为的全局控制以及网络的自动配置等高级目标的需求,提出了一种可行的系统架构,并以此为基础设计实现了一种新的网络策略自动部署系统。重点阐述了网络拓扑表示与策略展示流程,以及相关接口设计。已完成的原型系统表明,该系统具有良好的功能实现性。
In order to cope with the security threats such as identity authentication and access control arise,a reliable network environment,an impeccable and high performance network access control system is constructed.The present research situation of the network access control is analyzed,a feasible NAC structure is put forward,a new automatic network strategy deploying system is designed and implemented.Then the network topology expressing,network strategy displaying process and design of philosophy of some related interfaces are particularly expounded.The completed prototype system shows that this system has a good performance on functions implementation.