摘要
针对跨应用系统交互过程中存在的安全认证问题,提出了一种基于安全断言标记语言(SAML)和授权管理基础设施(PMI)的授权管理模型。该模型运用逻辑分离和应用结合的方法实现用户权限管理和授权访问。在PMI的基础上运用SAML断言、SAML协议和SAML绑定技术实现身份验证、属性获取和授权决策,通过属性权威机构(AA)和目录服务器(LDAP)实现对证书的管理。实验结果表明,该模型能有效实现对多角色用户的跨应用系统安全访问控制。
During message exchange in across-application there is risk of security certificate. An authorization management model based on Security Assertion Markup Language (SAML) and Privilege Management Infrastructure (PMI) is presented in this paper. The model implements authority management and grants access through combination of logic separation and application. It uses SAML assertion, SAML protocol and SAML binding technologies to conduct identification, attribute acquisition and grant decision based on PMI. This model attains the ability of certificate management by the Attribute Authority (AA) and the Light weight Directory Access Protocol (LDAP). Experiment results demonstrate that the model is competent for across-application security access control of multi-role users.
出处
《吉林大学学报(工学版)》
EI
CAS
CSCD
北大核心
2009年第5期1321-1325,共5页
Journal of Jilin University:Engineering and Technology Edition
基金
国家自然科学基金项目(60776807)
'863'国家高技术研究发展计划项目(2006AA12A106)
关键词
计算机应用
授权管理
身份验证
安全断言标记语言
授权管理基础设施
computer application
authorization management
identification
security assertion markup language(SAML)
privilege management infrastructure(PMI)