为了对终端接入可信网络的全生命周期的完整性进行实时监控与调节,通过分析现有可信网络认证模型的不足,基于可信网络认证与接入的三方模型,加入了元数据存储模块和流量控制器以及传感器模块,提出了一种扩展的可信网络平台接入与认证模型,并描述了一个基本的验证过程。通过在可信网络服务器端引入一个用于判定资源属性的模块,大大提高了服务器性能。然后描述了全生命周期监控的定义和实例。最后指出了扩展的可信网络认证与接入模型需要考虑的安全性和机密性问题。
To monitor and regulate the integrity of terminates at whole lifecycle of accessing trusted network, existing authorization model is analyzed. An expanded authentication and access model of trusted network is introduced by adding a meta-data storage module and traffic controller and the sensor module, basing on authentication and access of trusted network' s tripartite model. Then a basic veri- fication process is described. Through adding a module at the trusted network connection server-side which determining the attributes of resources, the performance of server is greatly improved. Then the definition and instance of the whole lifecycle control are described. Finally, the security and confidentiality issues which the expansion of the authentication and access model need to consider is introduced.