IAM(Identity and Access Management)
Product Overview

Iam (identity and access manag謝子ement) is used to define and manage dig湖公ital identities, securely contro新山l authentication and authorize the議國m to use specific resources, ensure th花慢at digital identities are well 答農maintained, adjusted, controlled and m離快onitored throughout the "access 風媽life cycle", and provide customers 船和with the ability to modify user i事慢dentity roles, track role acti白喝vities Tools and techniques for creat個兵ing user activity reports and impleme門物nting management policies. We provide頻船 an Iam all-in-one machine with 4A 離哥as the core benchmark to create an 懂這enterprise ecological platform o聽說f "enterprise unified portal", 數靜"application single sign on", "c關身entralized account control", "auth上歌entication access authorizatio多兒n management" and "unified audit trace如也ability and threat analysis" f又吃or users.

Deployment mode

Support modular deployment

The core component supports clus知業ter expansion

Do not change user network architectu習海re

No user secondary development 技音is required
There is no need to install the 道姐client engine




Advantages
1. Application safety manageme了舞nt and control system (iam-casb朋海)

Iam-casb consists of one basic 會信module and two extension modules:


Single sign on management module (i海銀am-sso) 
Iam-sso does not need the secondary dev唱聽elopment of the user business syst林志em to realize the single sign o黑事n of the HTTP / HTTPS business system事話 account. Each business system can un靜民iformly set up multi factor strong大媽 identity authentication on the Iam pla白鄉tform, including radius, ad, LDA工討P, OTP, digital certificate, SMS, w離鐘echat, fingerprint, etc. 有門
Application account management mo亮頻dule (iam-acm)
The iam-acm module provides the 唱生establishment of a centralized accou坐北nt management system and the imple明公mentation of the effective life cycle山但 management strategy of user acco著件unts. The addition, deletion an來鄉d modification of business syste畫開m accounts caused by personnel chang學白es can be managed only through Iam. On 報自the basis of centralized accoun開對t management, a centralized accou高玩nt authorization system is establis視麗hed to support the periodic aut她嗎omatic modification of business account林話s and eradicate the problem of wea志但k passwords. 
Application security reinforceme北少nt module (iam-wvp)

Iam-wvp establishes a white list model 用事for all business file paths and busin空開ess parameters through high-fine-grai上近ned feature library defense an草睡d the exclusively developed "white lis城事t" dynamic modeling technology, elim舊房inating the tedious work of strengthe雨鐘ning parameters in the source co間文de.


2. Operation and maintenance safety man新議agement system (iam-sms)

Provide support for various opera喝制tion and maintenance protocols and to間錯ols, expand a variety of multi f頻嗎actor identity authentication methods, 紅歌unify and reasonably divide permissio街秒ns, centralized access control, support西房 single sign on, account and passwo機討rd filling, seamless application publis人外hing, support mobile operation a窗看nd maintenance and distributed clu雨裡sters, and quickly meet compliance r朋金equirements.


3. Security policy control system通從 (iam-scm)

Iam-scm uses TCP quintuple contr資月ol to prevent business personne雨答l from bypassing the Iam platform to di算跳rectly access the business system. I煙外t can support two modes: Series deploym又舊ent and bypass deployment. Bypass 個樹deployment can also achieve 100% 光票blocking effect, and can effectively 跳兒control the connection initiated 不西by the intranet host to the extr業錢anet service port.


4. Audit traceability and threat長劇 analysis

The Iam platform can conduct compre來一hensive audit records on the access of拿跳 enterprise business personnel to OA, E就白RP, CRM, his / boss and other sy兒金stems, standardize the recording of費鄉 business form information, access 北車URL information, etc., and gene煙年rate e-mail and SMS reminders for the為放 logs that trigger security pol計黃icies; Uniformly display and an店跳alyze all delivery information at the o相體peration and maintenance level and影短 business level of the enterprise, a頻短nd can trace the whole business de你用livery process of Iam users. Help媽秒 enterprises protect confidential近能 information, continuously improve info大生rmation system management system答能, and meet compliance and best 個書practice requirements.

Customer Benefits

The operation contents of business per樂風sonnel are completely recorded by pal機市ladi Iam platform, which not only me事又ets the audit requirements of regula生的tory authorities, but also provides有技 technical support for accidents cau是區sed by misoperation and illegal opera他房tion. Reasonably allocate the 物舞specific conditions of users' use of re村靜sources in the business system, 房水realize the legal access of diffe那水rent users to different entity resou子地rces, and eliminate illegal access a書開nd unauthorized access. The per道草missions of each business personnel公亮 are effectively controlled, a對新nd the policy is fine-grained to工分 the accessible devices and avail開作able system accounts and application ac公市counts.


Providing effective audit reports and 關湖original and accurate operation l美公og records for the regulatory dep的林artment will help to improve the organ雜服ization's it internal control 做服and external audit system, so that 熱店the organization can successfully 農技pass the IT audit. Establish a unified 月農application security delivery 志們platform for customers, provide a unifi電司ed operation entrance for the core bu我妹siness system, and realize sin美懂gle sign on. All business and oper麗錢ation and maintenance personnel first熱技 log in to the Iam platform to con北又duct business operations on the sy海分stem to realize unified identity ma遠老nagement.

Classic case
  • Shanghai Yunda Freight Co., Ltd
  • Shanghai paipai loan financial informa道計tion service
  • Shanghai Honglu Data Technology 南文Co., Ltd
  • Shanghai Oriental Fortune futu務議res
  • Shangmeng Business Service Co., 船內Ltd
  • PLA 302 Hospital
  • Everbright Futures
  • State Grid Corporation of China
  • Noah Wealth Management
  • Citic Trust
Copyright © 2019 All Rights Re南內served Designed
Hangzhou pldsec Network Technology Co光報