期刊文献+

公钥基础设施的高校电子政务安全研究

Research of security university E-government based on public key infrastructure
下载PDF
导出
摘要 为了解决高校电子政务中的身份认证、访问控制、信息安全等安全问题,提出了一种基于公钥基础设施(PKI)核心技术的高校电子政务模型.该模型采用桥认证(CA)结构建立PKI信任机制,在各部门内部使用分级的CA认证,各部门之间通过中心CA进行桥接CA交叉认证;采用轻量目录访问协议(LDAP)建立PKI证书库,以目录复制(Replica)实现CA对主从LDAP的数据一致性,提高使用者的身份有效认证.该模型还采用角色及权限访问控制(RBAC)进行用户合法安全访问控制,在用户和访问权限之间引入角色,用户通过角色分配的权限来访问系统资源.此模型在实践中得以验证,符合安全要求. A model based on the core technology in the public key infrastructure (PKI) was introduced to resolve the safety problems in the E-government affairs of colleges and universities, such as identity authentication, access control and information safety. A PKI trust mechanism was established by using the bridge certificate authentication (CA), a hierarchical CA in every internal department and the bridge CA to cross authentication between various departments through a center CA were used. A PKI certificate base was established by using the lightweight directory access protocol (LDAP), which used directory replication to realize master-slave LDAP data consistency, so the availability of identity authentication of users was enhanced. The legal safety access of users was controlled by using role based access control (RBAC), the role between the user and the access was introduced , then the user accessed system resources through the permissions granted to the roles. The model is proved in practice according to the safety requests and is useful for the development of the E-government affairs of colleges and universities.
出处 《武汉工程大学学报》 CAS 2013年第1期75-79,共5页 Journal of Wuhan Institute of Technology
基金 湖北工程学院科研项目(Z2011006)
关键词 认证中心 高校电子政务 信息安全 公钥基础设施 authentication center university E-government information security public key infrastructure
  • 相关文献

参考文献9

二级参考文献25

  • 1吴立军.一种基于角色PMI的访问控制安全模型[J].微机发展,2004,14(8):123-125. 被引量:3
  • 2张文凯,曹元大.基于PKI/PMI的应用安全平台模型的研究[J].计算机工程,2004,30(9):131-133. 被引量:10
  • 3任军.基于LDAP的目录服务综述[J].计算机应用研究,2005,22(5):8-10. 被引量:42
  • 4熊桂喜 王小虎 等.计算机网络[M].北京:清华大学出版社,1998..
  • 5覃证,陈俊英,王昱.电子政务导论[M].北京:高等教育出版社,2005:35.
  • 6中国电子政务年鉴编委会.中国电子政务年鉴[M].北京:人民邮电出版社,2003:32.
  • 7[1]Sandhu R S, Coyne E J, Feinstein H L, et al. Role-based Access Control Models. IEEE Computer, 1995
  • 8[2]Maly K J, Gupta A, Levinstein I B. A Privilege Management System for A Secure Network. Services in Distributed and Networked Environments, 1996.
  • 9[3]ITU-T Recommendation X.5091ISO/IEC 9594-8: Information Technology-open Systems Interconnection-the Directory: Public-key and Attribute Certificate Frameworks. 1995
  • 10[4]Service by e-Contract-a Security Model for Authentication, Aecess Control and Online Subscription Management in Multi-service-multi Provider Architectures. www.nue.et-inf. uni-siegen.de/~friesen/publications/

共引文献35

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部