期刊文献+

一种基于可信DAA连接的单点登录模型 被引量:1

Single Sign-on Model Based on Trusted-DAA Connection
下载PDF
导出
摘要 针对云计算环境下传统单点登录模式采用SSL连接时存在的证书更新不及时、证书更新需要第三方CA参与等问题,在云身份认证服务器和云服务供应商之间引入TPM,采用DAA身份认证方式设计了一种可信DAA连接(T-D-SSL)来实现跨平台的可信身份认证、安全信道建立及证书更新操作。在此基础上,结合SAML2.0和ID-FF1.2,设计并实现了云计算环境下基于可信DAA连接的单点登录模型,在保证安全的同时减少了TPM带来的性能损耗。仿真实验结果表明,该模型能够安全高效的实现云计算环境下的跨域单点登录。 Traditional single sign-on(SSO) models adopt SSL connections in the cloud computing environments, while there exist several problems such as certificates cannot be updated in time, certificate updating needs a third party CA, etc.. To solve above problems, TPM was introduced between cloud identity providers and cloud service providers, and a trusted DAA connection(T-D-SSL) was designed by adopting the DAA authentication method to implementation cross platform trusted authentication, secure channel establishment, and certificate updating operation. Combining with T-D-SSL, SAML2.0, and ID-FF1.2, a new SSO model of the cloud computing environments was proposed, which could make sure the system security and reduce the performance lose due to the introduction of TPM. The simulation experiment results indicate T-D-SSL model can realize cross domain SSO safely and efficiently in the cloud computing environments.
出处 《系统仿真学报》 CAS CSCD 北大核心 2016年第4期890-897,906,共9页 Journal of System Simulation
基金 国家科技支撑计划(2013BAK07B04) 国家自然科学基金(61170254) 河北省自然科学基金(F2014201152)
关键词 可信计算 单点登录 直接匿名验证 身份认证 trusted computing single sign-on direct anonymous attestation authentication
  • 相关文献

参考文献14

  • 1冯登国,张敏,张妍,徐震.云计算安全研究[J].软件学报,2011,22(1):71-83. 被引量:1069
  • 2Radha V, Reddy D H. A Survey on Single Sign-On Techniques [J]. Procedia Technology (S1877-7058), 2012, 4: 134-139.
  • 3Microsoft Windows Live ID 服务 [EB/OL]. (2006-06-19) [2014-02-06] https://msdn.microsoft.com/zh-cn/library/aa479889.aspx.
  • 4Cantor S, Hodges J, Kemp J, et al. Liberty ID-FF Architecture Overview [EB/OL]. (2004-09-30) [2014-02-06]http://www.proj ectliberty.org/liberty/.
  • 5Internet2. Shibboleth Project [EB/OL]. (2014-02-26) [2014-03-10]http://shibboleth.net/about/.
  • 6Lewis K D, Lewis J E. Web Single Sign-On Authentication using SAML [J]. International Journal of Computer Science Issues (IJCSI) (S1694-0784), 2010, 7(4): 41-48.
  • 7Armando A, Carbone R, Compagna L, et al. From Multiple Credentials to Browser-based Single Sign-on:Are We More Secure? [M]// Future Challenges in Security and Privacy for Academia and Industry. Germany: Springer Berlin Heidelberg, 2011: 68-79.
  • 8Kirandeep K, Divya B. Security Vulnerabilities in SAML based Single Sign-On Authentication in Cloud [C]// 1 st International Workshop on Cloud Computing and Information Security. Amsterdam, Holland: Atlantis Press, 2013: 294-298.
  • 9沈昌祥,张焕国,王怀民,王戟,赵波,严飞,余发江,张立强,徐明迪.可信计算的研究与发展[J].中国科学:信息科学,2010,40(2):139-166. 被引量:252
  • 10冯登国,秦宇,汪丹,初晓博.可信计算技术研究[J].计算机研究与发展,2011,48(8):1332-1349. 被引量:116

二级参考文献178

共引文献1405

同被引文献11

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部