Go to Main Contents

:: Wireless WIF authentication access

How does the Zhejiang Mintai Commercial Bank public WiFi combine experience, safety auditing and integrated management?

The programme case, based on the needs of the Chengdu branch of Zhejiang Mintai Commercial Bank, is WiFi, which seems to be a mere web connection for visitors who are actually arriving at the site with identification, user segregation, access.

Your position:Home > Cases > Wireless WIF authentication access > > Text
Programme case based on needs of the Chengdu branch of Zhejiang Mintai Commercial Bank



The public WiFi looks like a mere network connection for visitors, and when they really land, they are faced with identification, user segregation, access control, log capacity, equipment management, and monitoring of the transport and subsequent expansion. The project needs of the Zhejiang Mintai Commercial Bank, which is a typical financial institution’s public WiFi programme scenario: to improve service experience and make network access identifiable, controlled, searchable, and manageable.
 
 
I. Background to the project: beyond the public service experience, there is also security and management responsibility
Based on the project statement of needs, Zhejiang Mintai Commercial Bank Chengdu plans to develop a unified wireless network access system in public areas that will provide easier access for the general public, visitors and insiders.
Unlike the ordinary business, bankers and WiFi can't just fix it.“Do you have a signal? Can you get it online?”. The project also needs to consider identity differentiation, access rights, user segregation, log retention, security strategy and transport management while retaining space for future additional area coverage, increased user size and expanded business functionality.
The project requirements therefore do not focus on a single certification page, but rather on a public WiFi management system that combines wireless access, identification, access control, behaviour management, log capacity and centralized transport.
II. OVERVIEW OF PROJECT REQUIREMENTS
Title of the project Zhejiang Mintai Commercial Bank, Chengdu Public WiFi Project
Clients Public, visitors, VIP visitors and line personnel
Main authentication modalities Visitors SMS authentication code; employee certification confirmed by security level, bank scene recommended business account + dynamic authentication code double factor; fixed office terminals can assess post-string insensitive authentication under controlled conditions
Management objectives Harmonization of user management, equipment management, strategy control, state monitoring and report analysis
Safety and compliance objectives User segregation, access control, access to behavioural records, log retention for not less than 6 months (as confirmed by contract and regulatory requirements) and security incident monitoring
Capacity targets Supports at least 1000 co-distributes users and presets the ability to expand to 5000 co-distributes
Direction of deployment Wireless controller + thin AP centralized structure, authentication, behaviour management and confirmed log capacity co-deployment
Information status This draft is based on project needs and programme development and does not represent actual operational results that have been online, accepted or achieved
 
III. THE PROJECT COVERS
1. The same public WiFi, who serves people of different identities
Ordinary visitors, VIP visitors, internal employees, and authorized equipment require different types of authentication, access rights, and length of use.
The project requires separate management of visitor identification, staff identity and fixed internal equipment: visitors can be certified by SMS; employee certification should be confirmed by the customer ' s actual security level; a two-factor approach to business account plus dynamic authentication code is recommended for the banking scene; and for stationary office terminals, unsense access after MAC binding may be assessed subject to first mandatory verification, limited binding scope and validity.
2. Certification success is only the beginning, and control is required“What can I get you?”
Public WiFi security cannot stay.“Release after entering the authentication code”. Different users should have access to different areas of access, the visitors’ network needs and internal business networks are kept reasonably separate, and unnecessary double-level visits between users are avoided.
The project also proposes a differentiated strategy for the configuration of users, user groups, locations and time, such as bandwidth limits, access times, black-and-white lists and site classification controls. This means that authentication results must continue to be passed on to network side strategies rather than certification pages and network control separate from each other.
3. “Log”Not equal to building an audit link
The bank WiFi needs to focus on the retention and search of user login, exit, IP, MAC, and access records. The login in the authentication system is only a part of it; if the project also requires URL filtering, application control, threat detection and more fine-scale access behaviour records, it will require a certification system, online behavior management and corresponding log capacity to work together.
The logbooks record the range, how long it is stored and whether anti-pollification measures are available, which need to be confirmed in accordance with final deployment modules, collection location, storage planning and regulatory requirements, not only by one.“Support Log”General.
4. The large number and coverage of equipment requires centralized follow-on transport
The public WiFi construction will not end. APs require continuous possession by the operator if they are online, if there is an abnormal number of users, if there is a surge in traffic, whether the equipment is malfunctioning and whether the authentication failed.
The project therefore requires a uniform view of users, equipment, network status and alert information through the Web management platform and supports AP batch configuration, upscaling, performance monitoring and report output to reduce the costs of carrying the multiple systems decentralized.
IV. NatShell Programme Design Concept
1. Tier-building, rather than all capabilities being plugged into a device
This project is based on a centralized wireless architecture, with wireless controllers responsible for AP management, roaming and wireless strategies; NATSHEL_BRAND NATSHEL_AUTH_BILLING system responsible for Portal authentication, SMS switch interface, user sessions and certification strategies; online behavior management responsible for traffic control, content filtering, access control and access to behavioural records; and log capacity needs to be clearly defined according to the final build-up scope, whether the internal log module of the certification platform or the independent log system, and responsible for the corresponding central storage, query and archiving.
This division of labour allows the modules to assume clear responsibilities and facilitates subsequent expansion according to user size, security requirements and coverage.
2. Different access modes for visitors and internal staff
For the public and temporary visitors, the primary means of establishing basic links between identity information and mobile phone numbers is SMS authentication; for line personnel, certification should be confirmed by customer actual security level; a two-factor approach to business account plus dynamic authentication code is recommended in the banking context; and for fixed office terminals, MAC insensitive authentication can be evaluated under first mandatory verification, binding scope and controlled validity.
The established capacity commitment to double-accredited or non-encouraged non-consensual experiences across institutions is only an assessment. A common validation platform, network equipment compatibility, a talking strategy, organizational scope and on-site implementation conditions are required to be identified as achievable.
3. Set up isolation and differentiation strategies from the point of access
The program uses SSID, VLAN, user groups and web strategies to make a reasonable distinction between the visitors’ network and the internal network and limit unnecessary exchange of visits among visitors. Different identities match different access times, bandwidth, website classification and black-and-white list strategies.
The specific strategies are determined by bank management requirements, existing exchange and wireless equipment capabilities and the extent of connection to security systems.
4. Synergy of accreditation, behaviour management and log capacity
Certification system resolution“Who's online?”, network equipment and behavioural management system solution“What is allowed to access, how to control and document access behaviour”Log capacity solution“Record what, how to search and save”. The modules are coordinated to enhance the connection between user identification, terminal information, web addresses and access records within the project context.
For the capabilities of the URL level audit, malicious acts identification, virus terminal isolation and cloud threat information, they need to be provided by the corresponding security module and confirmed in accordance with actual procurement, authorization and deployment conditions.
5. Unified management and space for future expansion
The project requires centralized management of users, roles, equipment and strategies, along with visual information on online users, traffic, security incidents, and equipment status. Security incident monitoring and alerts should be undertaken by wireless security, Internet behavior management or other safety modules that are ultimately procured and deployed and not only presented as abstract capabilities.
Actual co-processing capacity requires a combination of authentication platforms, wireless controllers, AP density, export bandwidth, server resources and log storage capabilities.
V. PROJECT value
1. Upgrading visitors ' experience: providing the public, visitors and internals with clearer access through a unified portal and multiple accreditation processes.
2. Enhanced access management: From anonymously shared passwords to identifiable, groupable and configured policy access.
3. Enhancing security control: reducing the impact of public networks on internal business networks through user segregation, access control, behaviour management and security alerts.
4. Forming an audit basis: Link identification, terminal, IP, time and access records within confirmed deployments to provide a data base for query, archiving and supervisory inspection.
5. Reduced transport-dimensional complexity: Centralize user, device, traffic and alarm viewing through a unified web platform and support batch configuration and report output.
6. Retaining the following extension capability: use of scalable design on user capacity, coverage and functional modules to facilitate future additions of AP, area coverage and security capabilities.
VI. PROJECT BASIC STATEMENT
Proposed boundaries for retention at the time of external publication
The final compliance conclusion of the project, Log Audit scope, security detection capabilities, uniform equipment management coverage and co-performance should be based on actual procurement modules, equipment compatibility, site network architecture, implementation of acceptance and inspection results, and regulatory requirements.“Full compliance, full traceability of conduct, unified control of all equipment, absolute no risk”And so on, absolute.
 
 
VII. Summary
The public WiFi construction of financial institutions, ostensibly an upgrade in wireless access, is backed by user identification, access rights, security audits and long-term expansion of equipment transport and peacekeeping.
The value of this project requirement lies in putting these previously fragmented issues into the same set of building logic: identifying access persons before matching network privileges; and ensuring that the use experience is accompanied by a manageable, searchable and sustainable basis for the process.
NATSHEL_BRAND will continue to provide a more adapted access management programme for banking, business and public service scenes around the competencies of authentication, billing, user administration, network strategy and NATSHEL_LOG_AUDIT.
Access Program I'll be right back. Telephone counselling