期刊文献+

ASP平台安全认证技术的研究与实现 被引量:7

Research and implementation of security authentication technology on ASP platform
下载PDF
导出
摘要 为满足应用服务提供商平台集成多种异构应用系统的实际需求,提出了一种采用统一安全认证技术进行轻量级应用集成的解决方案。该方案采用目录服务数据库,统一存储用户身份和权限信息,使用会话令牌保证用户身份的持久有效性,通过策略代理保护应用服务资源的安全,并对用户的访问进行统一授权和控制。为实现用户在平台和应用系统之间的单点登录,提出了令牌和代理相结合进行身份信息传递与验证的实现方案,尤其是解决了跨域单点登录的难题。该方案已成功应用于上海电信理想商务应用服务提供商平台。 To satisfy requirements from Application Service Providers" (ASPs) on integrating different application systems into ASP platform, a light--weighted integration method was brought forward based on the unified security authentication technology. According to the method, all users" identification and authorization information were stored in a Light--weight Directory Access Protocol (LDAP) based directory database, tokens were set to keep user session's validity, policy agents were installed to protect all the application resources, and user's access to these resources were granted and controlled centrally. Combining the use of tokens and policy agents, the problem of Single Sign On (SSO) among platforms and applications, especially SSO among cross--domains, could be solved. Finally, this method has been successfully implemented in, "Shanghai Telecom Ideal Biz ASP Platform" Project.
出处 《计算机集成制造系统》 EI CSCD 北大核心 2005年第12期1738-1742,共5页 Computer Integrated Manufacturing Systems
基金 国家863/CIMS主题资助项目(2003AA414012)~~
关键词 应用服务提供商 认证 授权 单点登录 访问控制 目录服务数据库 application service provider authentication authorization single sign on access control directory database
  • 相关文献

参考文献7

二级参考文献23

  • 1蔡菁.基于角色的多层应用系统安全控制[J].计算机工程与应用,2001,37(14):106-108. 被引量:5
  • 2(美)Blum D 天宏工作室 译.Active Directory服务实用教程[M].北京:清华大学出版社,2002..
  • 3余彤鹰.复杂系统的层级原理与模型驱动软件体系结构[EB/OL].http://www.ee-forum.org,2002-05.
  • 4[1]Sandhu RS, et al. Role-Based Access Control Models[J]. Computer IEEE,1996,29(2):38-47.
  • 5[6]Lee R. The JNDI Tutorial[EB/OL]. http://Java.sun.com/products/jndi/tutorial,2002-11.
  • 6[7]Donnelly M. An Introduction to LDAP[EB/OL].http://ldapman.org/articles/intro_to_ldap.html,2002-11.
  • 7[8]Adatia R, et al. EJB编程指南[M]. 喻文中, 等译. 北京:电子工业出版社,2002.
  • 8孙延明.应用服务供应商ASP解决方案[M].北京:电子工业出版社,2003..
  • 9Ferrraiolo D F,Barkley J F,Kuhn D R.A Role Based Access Control Model and Refernence Implementation Within a Corporate Intranet [J].ACM Transactions on Information Systems Security, 1999-02.
  • 10http ://www-9OO.ibm.com/developerWorks/cn/security/syscontrol/index.shtml.

共引文献80

同被引文献42

引证文献7

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部