Single sign-on (SSO) is an identity management technique that provides the ability to use multiple Web services with one set of credentials. However, when the authentication server is down or unavailable, users cannot...Single sign-on (SSO) is an identity management technique that provides the ability to use multiple Web services with one set of credentials. However, when the authentication server is down or unavailable, users cannot access these Web services, regardless of whether they are operating normally. Therefore, it is important to enable continuous use alongside SSO. In this paper, we present an identity continuance method for SSO. First, we explain four such continuance methods and identify their limitations and problems. Second, we propose a new solution based on an identifier migration approach that meets the requirement for identity continuance. Finally, we discuss these methods from the viewpoint of continuity, security, efficiency, and feasibility.展开更多
本文设计了一种适用于B/S结构的,复杂度和安全性适中的SSO协议,它在设计上吸取了很多Kerberos和CAS的设计思想,如Kerberos协议的票据与CAS协议中的重定向和Cookie管理技术。它的特点是使用加强的密码校验协议,不需传输密码或加密密码即...本文设计了一种适用于B/S结构的,复杂度和安全性适中的SSO协议,它在设计上吸取了很多Kerberos和CAS的设计思想,如Kerberos协议的票据与CAS协议中的重定向和Cookie管理技术。它的特点是使用加强的密码校验协议,不需传输密码或加密密码即可完成校验;采用简化的Kerberos票据管理技术;增加票据有效性的检验;由于鉴权服务器和应用服务器之间使用对称密码,所以在票据的加密时,使用主密钥分散技术,更安全的保护主密钥;改进Kerberos票据,增加application server sequence number,与时间戳共同解决重传攻击问题。展开更多
该文设计了一种适用于B/S结构的,复杂度和安全性适中的SSO协议,它在设计上吸取了很多Kerberos和CAS的设计思想,比如Kerberos协议的票据与CAS协议中的重定向和Cookie管理技术。它的特点有:使用加强的密码校验协议,不需传输密码或...该文设计了一种适用于B/S结构的,复杂度和安全性适中的SSO协议,它在设计上吸取了很多Kerberos和CAS的设计思想,比如Kerberos协议的票据与CAS协议中的重定向和Cookie管理技术。它的特点有:使用加强的密码校验协议,不需传输密码或加密密码即可完成校验;采用简化的Kerberos票据管理技术;增加票据有效性的检验;由于鉴权服务器和应用服务器之间使用对称密码,所以在票据的加密时,使用主密钥分散技术,更安全的保护主密钥;改进Kerberos票据,增加application server seque ncenumber,与时间戳共同解决重传攻击问题。展开更多
Collaborative platform on clustering applications for governments consists of six large-scale systems, including the clustering Government Internet portal system, clustering public-mailboxes collaboration system, clus...Collaborative platform on clustering applications for governments consists of six large-scale systems, including the clustering Government Internet portal system, clustering public-mailboxes collaboration system, clustering government affairs portal system, clustering emergency information collaboration system, clustering office automation collaboration system, and clustering messages collaboration systems. The appli-cation and technology architectures of the collaborative platform are elaborated in this paper,and the major key technologies on the platform are also expounded, which includes realization of many governments ap-plications’ scale integration and collaborative application, business model driven software development plat-form based on SOA, SSO, tans-departmental and cross-level multi-engine clustering protocol. Based on the "clustering application"design, to maximize the utilization of hardware, software resources and administra-tive resources of the provincial government collaborative platform, rural districts and counties can build their own platforms based on the provincial platform. The platform having been running for over 2 years shows that planning of urban and rural e-governments’ construction and maintenance is achieved, thus reducing costs greatly and improving governments’ functions.展开更多
The trend in businesses is moving towards a single browser tool on portable devices to access cloud applications which would increase portability but at the same time would introduce security vulnerabilities. This res...The trend in businesses is moving towards a single browser tool on portable devices to access cloud applications which would increase portability but at the same time would introduce security vulnerabilities. This resulted in the need for several layers of password authentications for cloud applications access. Single Sign-On (SSO) is a tool of access control of multiple software systems. This research explores the effects and implications of SSO solutions on cloud applications. We utilize a new framework of different attributes developed by acquiring IT experts’ opinions through extensive interviews to expand significant strategic parameters at the workplace. The framework was further tested using data collected from a sample of 400+ users in the UAE.展开更多
文摘Single sign-on (SSO) is an identity management technique that provides the ability to use multiple Web services with one set of credentials. However, when the authentication server is down or unavailable, users cannot access these Web services, regardless of whether they are operating normally. Therefore, it is important to enable continuous use alongside SSO. In this paper, we present an identity continuance method for SSO. First, we explain four such continuance methods and identify their limitations and problems. Second, we propose a new solution based on an identifier migration approach that meets the requirement for identity continuance. Finally, we discuss these methods from the viewpoint of continuity, security, efficiency, and feasibility.
文摘本文设计了一种适用于B/S结构的,复杂度和安全性适中的SSO协议,它在设计上吸取了很多Kerberos和CAS的设计思想,如Kerberos协议的票据与CAS协议中的重定向和Cookie管理技术。它的特点是使用加强的密码校验协议,不需传输密码或加密密码即可完成校验;采用简化的Kerberos票据管理技术;增加票据有效性的检验;由于鉴权服务器和应用服务器之间使用对称密码,所以在票据的加密时,使用主密钥分散技术,更安全的保护主密钥;改进Kerberos票据,增加application server sequence number,与时间戳共同解决重传攻击问题。
文摘该文设计了一种适用于B/S结构的,复杂度和安全性适中的SSO协议,它在设计上吸取了很多Kerberos和CAS的设计思想,比如Kerberos协议的票据与CAS协议中的重定向和Cookie管理技术。它的特点有:使用加强的密码校验协议,不需传输密码或加密密码即可完成校验;采用简化的Kerberos票据管理技术;增加票据有效性的检验;由于鉴权服务器和应用服务器之间使用对称密码,所以在票据的加密时,使用主密钥分散技术,更安全的保护主密钥;改进Kerberos票据,增加application server seque ncenumber,与时间戳共同解决重传攻击问题。
文摘Collaborative platform on clustering applications for governments consists of six large-scale systems, including the clustering Government Internet portal system, clustering public-mailboxes collaboration system, clustering government affairs portal system, clustering emergency information collaboration system, clustering office automation collaboration system, and clustering messages collaboration systems. The appli-cation and technology architectures of the collaborative platform are elaborated in this paper,and the major key technologies on the platform are also expounded, which includes realization of many governments ap-plications’ scale integration and collaborative application, business model driven software development plat-form based on SOA, SSO, tans-departmental and cross-level multi-engine clustering protocol. Based on the "clustering application"design, to maximize the utilization of hardware, software resources and administra-tive resources of the provincial government collaborative platform, rural districts and counties can build their own platforms based on the provincial platform. The platform having been running for over 2 years shows that planning of urban and rural e-governments’ construction and maintenance is achieved, thus reducing costs greatly and improving governments’ functions.
文摘The trend in businesses is moving towards a single browser tool on portable devices to access cloud applications which would increase portability but at the same time would introduce security vulnerabilities. This resulted in the need for several layers of password authentications for cloud applications access. Single Sign-On (SSO) is a tool of access control of multiple software systems. This research explores the effects and implications of SSO solutions on cloud applications. We utilize a new framework of different attributes developed by acquiring IT experts’ opinions through extensive interviews to expand significant strategic parameters at the workplace. The framework was further tested using data collected from a sample of 400+ users in the UAE.