期刊文献+

面向HTTP身份鉴别协议的单点登录透明集成技术研究 被引量:9

Single sign-on transparent integration technology for Web systems with HTTP authentication protocols
下载PDF
导出
摘要 针对单点登录技术实施过程中,采用HTTP身份鉴别协议的已有Web应用系统不能修改、改变的技术难题,提出了一种无须修改Web应用程序和Web服务器的身份鉴别方式即可实现单点登录的单点登录透明集成技术。该技术通过插入到Web服务器的HTTP请求、响应处理通道中的一个插件,自动处理与Web服务器交互的HTTP身份鉴别协议数据,从而在对Web服务器不作改变、对Web应用程序不作修改的情况下,实现单点登录功能。实际应用和测试结果表明,该方案实现了预定的功能,达到了预期的效果。所提方案对单点登录的应用实施非常有帮助。 To address the problem that existing legacy Web application systems using HTrP authentication protocols cannot be modified in implementing SSO technology, this paper proposed a transparent SSO integration technology which required no modifications to the existing legacy systems. The proposed technology employed a plug-in module which inserted into the HTI'P request and response processing pipelines of a Web server. The plug-in automatically processed the reciprocal exchanges of au- thentication data with the Web server employing a HT'FP authentication protocol. As a result, it achieved SSO without the chan- ges or modifications to the Web server and application. Practical applications and tests demonstrate that the proposed technolo- gy has achieved the predined functionality and the expected effects. The technology is highly helpful to the implementations of SSO.
出处 《计算机应用研究》 CSCD 北大核心 2013年第9期2813-2818,共6页 Application Research of Computers
关键词 身份鉴别 单点登录 HTTP身份鉴别 透明集成 单点登录插件 authentication single sign-on HTrP authentication transparent integration SSO plug-in
  • 相关文献

参考文献12

  • 1陈天玉,谢冬青,杨小红,杨海涛.基于SAML与XKMS的安全单点登录认证模型的研究与实现[J].计算机应用研究,2010,27(3):1019-1021. 被引量:10
  • 2高昊江,肖田元.基于SAML改进的单点登录模型研究[J].计算机工程与设计,2011,32(3):827-829. 被引量:9
  • 3李小标,温巧燕,代战锋.PKI/PMI支持多模式应用的单点登录方案[J].北京邮电大学学报,2009,32(3):104-108. 被引量:10
  • 4嵇智辉,倪宏,刘磊,匡振国.一种基于双令牌机制的单点登录模型研究[J].计算机工程与应用,2008,44(30):131-134. 被引量:5
  • 5Organization ibr the Advancement of Structured Intbrmation Standards (OASIS). Asseltions and protoco|s for the OASIS security assertion markup language (SAME) v2.0 [ S ]. [ S. 1. ]: OASIS, 2005.
  • 6Organization for the Advancement of Structured hfformation Standards (OASIS). Security assertion markup language (SAME) v2.0 techni- caloverview[EB/OL]. (2008-03- 15) [20|2- 11-06]. http:// docs. oasis-open, org/security/saml/Post2.0/sstc-saml-tech-overview- 2.0-cd-02. html.
  • 7Organization for the Advancement of Structured Information Standards (OASIS). Web services federation language (WS-federation) version 1.2[S]. [S. 1. ] :OASIS,2009.
  • 8FRANKS J, HALLAM-BAKER P, HOSTETLER J, et al. RFC2617, HTTP authentication: basic and digest access authentication[ S]. [ S. L ] :lntemet Engineering Task Force, 1999.
  • 9Micros@ Corporation. NTLM over HTTP protocnl specification[ S]. [ S. 1. ] :Microsoft Corporation,2012.
  • 10JAGANATHAN K, ZHU L, BREZAK J. RFC4559,SPNEGO-based Kerberos and NTLM HTTP authentication in Microsoft Windows [ S ]. [ S. 1. ] :lntemet Engineering Task Force,2006.

二级参考文献35

共引文献28

同被引文献74

引证文献9

二级引证文献11

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部