期刊文献+

一种基于双角色的代码授权Web安全组件的设计 被引量:1

Design of a Web Security Component for Code Authorization Based on Dual-roles
下载PDF
导出
摘要 安全性问题一直是计算机软件应用中的一个重大问题。本文介绍了一种适用于ASP NET应用程序的基于双角色的代码授权安全技术 ,通过对代码进行静态的或动态的授权配置 ,在受安全保护的代码被调用或被执行前验证用户身份 ,只有通过验证的用户才被授予执行特定操作的权限 ,从而才能调用或执行代码。应用这种技术可以保护只允许特定用户执行的特定操作 ,保护业务规则 ,应对数据信息篡改泄漏的威胁 ,并防止恶意行为。考虑到组件的重用性 ,作者设计了安全组件。 Security is one of weighty problems in computer software application at all times. This paper presents a method that provides guidelines for designing code authorization based on dual-roles in ASP NET application. Through performing authorization configuration for code statically or dynamically, authenticating user's identity is requested before protected code is executed, and only authenticated users can get the permission to perform specific actions. Using this technique can allow appointed users to perform certain actions, protect business rules, prevent data tampering and information disclosure and avoid malicious acts. Considering the reusability of component, the author design a security component using this method.
作者 杨君 雷电
出处 《微计算机应用》 2004年第6期660-664,共5页 Microcomputer Applications
基金 上海高等学校科学技术发展基金资助 (0 3AK11)
关键词 双角色 代码授权 WEB 组件 ASP.NET 身份验证 security Dual-roles authentication authorization ASP.NET component
  • 相关文献

参考文献2

  • 1Chris Schoon, Doug Rees, Edward Jezierski. Designing Application-Managed Authorization [ EB/OL]. http: //www. microsoft. com/downloads/details. aspx? FamilyId = 40A58453-EC1B-4627-874B-F83437DBE00C&displaylang = en, 2002 -12~17.
  • 2J D. Meier Alex Mackman, Michael Dunner, Srinath Vasireddy. Building Secure ASP. NETApplications [EB/OL].http: //www. microsoft. com/downloads/details. aspx? displaylang = en&FamilyID = 055FF772-97FE-41B8-A58C-BF9C6593F25E, 2002 - 10 - 15.

同被引文献5

  • 1CHUCK C. programming jakarta struts. USA. OReilly & Associates, Inc, ,2002.
  • 2JAMES G. mastering jakarta struts. USA. Wiley Publishing, Inc. ,2002.
  • 3WERNER R. security in struts: user delegation made possible, http://www.onjava. com/. 2004. 2.
  • 4MICHAEL C. Secure a web application, java-style, http://www.javaworld.com/. 2000.
  • 5TED H. struts in action [M]. USA. Manning Publications Co. 2002

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部