摘要
针对企业构建统一门户平台进行应用集中时面临的"身份集成"的问题,提出了统一认证和单点登录方案.基于Web单点登录的基本架构及其实现条件,引入集中认证服务(CAS)单点登录的开源工具,描述了CAS协议模型,对其单点登录的实现流程和协议进行了安全性分析.通过简单的环境配置和Java编程,对基于CAS的单点登录(SSO)模型作了实验性开发,并验证了其合理性和可行性.
To the problem of "Identity Integration" in the construction of enterprise unified portal platform, SSO(Single Sign-On) solution was put forward. First,issues about Web-SSO basic structure and its implement condition were discussed. Next, CAS, open source SSO tool, was introduced. And then, the detailed description of CAS Protocol Model, its flow of SSO and analysis of its security were given. Finally, the trial development of SSO model based on CAS was made by simple setting configuration and Java coding.
出处
《上海工程技术大学学报》
CAS
2009年第2期165-169,共5页
Journal of Shanghai University of Engineering Science
关键词
统一认证
单点登录
CAS协议模型
unified authentication
SSO (Single Sign-On)
CAS ( Central Authentication Service) protocal model