期刊文献+

基于数字证书的openstack身份认证协议 被引量:10

Openstack authentication protocol based on digital certificate
下载PDF
导出
摘要 openstack作为开源云平台的行业标准,其身份认证机制采用的是keystone组件提供的基于用户名/口令的单因素认证方式,不适用于对安全等级需求较高的应用场景。因此,设计出一种基于数字证书的身份认证协议,该协议包括云用户身份标识协议和云用户身份鉴别协议,来满足高安全性应用场景的安全需求。通过对keystone组件进行扩展实现了基于数字证书的身份认证系统,该系统综合运用了密码认证服务器、UKey、加密、完善的密钥管理等技术。经分析,该系统能够有效抵抗多种网络攻击,提高了云用户在登录云平台时的安全性。 As the industry standard for open source cloud platforms,openstack uses the single-factor authentication method based on username and password that provides by keystone components to identity authentication mechanism,while it is not suitable for application scenarios with high security level requirements.A digital certificate-based identity authentication protocol which had cloud user identification protocol and authentication protocol was designed to meet the requirements.With expending the keystone component to achieve a digital certificate-based identity authentication system,a combination of authentication server,UKey technology,encryption technology and well-established key management and so on was used.According to the research,the system can effectively resist multiple cyber-attacks and improve the security of cloud users when they log in to the cloud platform.
作者 朱智强 林韧昊 胡翠云 ZHU Zhiqiang;LIN Renhao;HU Cuiyun(Institute of Cryptography Engineering,Information Engineering University,Zhengzhou 450001,China;Zhengzhou Xinda Institute of Advanced Technology,Zhengzhou 450001,China)
出处 《通信学报》 EI CSCD 北大核心 2019年第2期188-196,共9页 Journal on Communications
基金 国家重点研发计划基金资助项目(No.2016YFB0501900)~~
关键词 云计算 数字证书 身份认证系统 身份认证协议 cloud computing digital certificate authentication system authentication protocol
  • 相关文献

参考文献4

二级参考文献89

  • 1夏晔,钱松荣.OpenID身份认证系统的认证等级模型研究[J].微型电脑应用,2011(4):7-9. 被引量:3
  • 2吴志勇,孙乐昌.针对钓鱼攻击的防范技术研究[J].信息安全与通信保密,2006,28(11):126-128. 被引量:7
  • 3汪涛.基于USBKey的远程身份认证系统的设计与实现[D].成都:电子科技大学,2009.
  • 4MELL P, GRANCE T. The NIST definition of cloud computing, SPS00-145 [ R ]. [ S. 1. ] : NIST,2011.
  • 5Microsoft. White paper: remote desktop protocol (RDP) features and performance[ EB/OL]. (2005-12-09) [2013-05-20]. http://www. microsoft, com/technet/prodtechnol/'Win2 KTS/evaluate/featfunc/rd- pfperf, mspx.
  • 6RESCORLA E. SSL and TLS: designing and building secure systems [ M ]. [ S. 1. ] : Addison-Wesley,2002.
  • 7赵粮.云计算面临的七大安全威胁[EB/OL].(2011-09-01)[2013-05-20].http://www.edu.cn/paper-11947/20110901/t20110901_678256_2.shtml.
  • 8Vamanan B, Hasan ], Vijaykumar T N. Deadline-aware datacenter TCP (D2TCP) [J]. ACM SIGCOMM Computer Communication Review, 2012, 42(4): 115-126.
  • 9Rasley J, Stephens B, Dixon C, et al. Planck: Millisecond- scale monitoring and control for commodity networks [C] // Proc of the 2014 ACM Conf on SICOMM. New York: ACM, 2014:407-418.
  • 10Guo Z, Yang Y. Multicast fat-tree data center networks with bounded link oversubscription [C] // Proc of IEEE INFOCOM'13. Piscstaway, NJ: IEEE, 2013:350-354.

共引文献259

同被引文献80

引证文献10

二级引证文献35

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部