期刊文献+

基于JAAS和J2EE Web容器的验证与授权 被引量:3

Implementation of Authentication and Authorization Based on JAAS and J2EE Web Container
下载PDF
导出
摘要 在Borland应用服务器的基础上,使用JAAS与J2EEWeb容器内在的安全机制,并借助Oracle数据库的用户验证,实现了Web应用中对用户的验证和授权。把用户能访问到的资源控制到页面级,将开发阶段需要考虑的安全问题转移到部署阶段,实现了应用逻辑与安全逻辑的彻底分离。实践表明,使用JAAS可以提高整个系统的开发效率,而Web容器提供的验证与授权可以很好地和数据库安全域相结合。 To implement the authentication and authorization in a Web application based on Browser/Server model. JAAS and J2EE Web Container's security realm, combining with Oracle's self authentication, are used to authenticate and authorize users who want to access the Web application. The resources that a user can access are limited at Web page level and the security issue considered in development phase is moved to deployment. The business logic and rights management are isolated so that programmers are no need to write codes in each page to examine whether the user have rights to access it. The results show that using Java Authentication and Authorization Service (JAAS) can enhance the entire system's development efficiency and the security mechanism provided by Web Container can work with the database's security realm well.
出处 《电子科技大学学报》 EI CAS CSCD 北大核心 2007年第5期969-972,共4页 Journal of University of Electronic Science and Technology of China
基金 国家863/CIMS主题资助项目(2003AA411210)
关键词 验证 授权 JAAS J2EEWeb容器 安全 authentication authorization JAAS J2EE Web container security
  • 相关文献

参考文献10

二级参考文献44

共引文献62

同被引文献16

  • 1陈圣俭,徐明华.JAAS认证和授权机制在J2EE中的应用[J].中国电力教育,2007(z2):51-52. 被引量:1
  • 2陈阳,佘堃,周明天.RBAC扩展J2EE/JAAS安全机制的设计与实现[J].计算机应用研究,2005,22(1):114-116. 被引量:7
  • 3冉春玉,毕建信.基于JAAS技术的J2EE安全性应用与研究[J].计算机与数字工程,2006,34(8):70-73. 被引量:3
  • 4Morita I. Toward realization of service-oriented architecture[J]. Fujitsu Sci and Tech J, 2006, 42(3): 306 -315.
  • 5Phan C. Service-oriented architecture (SOA)--Security challenges and mitigation strategies [C] // Military Communications Conference. Piscataway, N J: IEEE Press, 2007 : 1 - 7.
  • 6Kanneganti R, Chodavarapu P. SOA Security [M]. Greenwich: Manning Publications Co, 2008.
  • 7Chou W. Inside SSL: Accelerating secure transactions [J]. IT Professional, 2002, 4(5) : 37 - 41.
  • 8Gudivada V N, Nandigam J. Enterprise application integration using extensible Web services [C] // 2005 IEEE International Conference on Web Services. Piscataway, NJ: IEEE Computer Society Press, 2005 : 41 - 48.
  • 9JavaTM Authentication and Authorization Service (JAAS) Reference Guide [EB/OL]. (2001-08-08). http://java.sun. com/j2se/1.4/docs/guide/security/j aas/JAASRe fGuide. html#Sample.
  • 10PISTOIAM,NAGARATNAMN.企业级Java安全性:构建安全的J2EE应用[M].尹亚,明喻卫,严进宝,译.北京:清华大学出版社,2006:132.167.

引证文献3

二级引证文献16

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部