基于SAML的口令单点登录身份验证

来源 :华东理工大学 | 被引量 : 0次 | 上传用户:lost123321
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
With the rapid development of technology in the world of the Internet today,most enterprises and large organizations have embarked to store and share their business details into the cloud hereby if one wanted to access data information,had to authenticate to one of the sites to access the data.The basic philosophy ofsingle sign on is to provide unlimited accessing with single sign on.Because web services involve the coordination of many sites belonging to different domains,this brought about the issue of cross—domain coordinated identification and the security message transport.Based on the analysis of security requirements of current web services,the basic philosophy of single sign on system,and the frequently employed single sign on technology based the present dissertation elaborates on such issues as the lack of uniform standards,over-complicacy of the flow, the inability of cross—domain operation and security deficiency,to name but a few,are beyond the capability of the current single sign on system,though it can provide clients/users with joint identification between many sites in the single domain.Under the present single sign on services,which provides a simple and convenient authentication service to a number of organizations when applied appropriately,on the other hand it has instead led to an increase in number of service providers and this came along with a good deal of setbacks in that users/clients have felt a burden to login to every website of the service provider with their credentials.This also has put the engineersinturmoilof configuring, deploying,and supporting the system for every client/user with the internal resources and the resulted into inconveniences,insecurity and mistrust to the clients.The Shibboleth provides a federated single sign-on and attribute exchange framework.It allows sites to make informed authorization decisions for individual access of protected online resources.A user is authenticated by his own organization,which passes the minimal identity information necessary to the service provider to enable an authorization decision.In this thesis,I recommended a single sign on based Shibboleth authentication approach.The log-in method in shibboleth is modified,so the identity authentication provided by the SSO servers is only used for determining if the user is permitted to log in the system when the user try to visit the Service Provider,while the users role is still verified by the service provider.Security assertion Markup Language (SAML) is provided for exchanging user security information between an identity provider and a service provider which is flexible and can allow customers data to be transmitted safely to the external service provider.First,our project proposed the integrated Shibboleth based on SAML SSO infrastructure which will deliver a production level service for accessing the organizations under federation in a user friendly manner.Second,I proposed a simple and convenient authentication method of the identity roaming to enable a user to sign up for one website and extend the connectivity service in a location that is different from the home location where the user was registered and authenticated.Third,this thesis also elaborated an architecture by which users are authenticated by the Service provider access management federation to acquire low assurance credentials to access resources on the identity agent.In this project,the user login to identity agent resources via identity provider portal using their local instructions authentication system.In other words, the user signs in once and accesses many safe resources with the mechanism of trust and his credential remain safe and saved which reduces the burden of daily prompt authentication.
其他文献
随着大数据、云计算时代的来临,I/O密集型应用亟需高性能的存储介质。作为当前主流备份存储介质的机械磁盘,其数据读/写速度已远远落后于CPU对I/O性能的需求。基于NAND闪存构造
随着电子商务的发展,基于Agent技术的商务协商功能模块的智能化研究是新一代电子商务研究的热点。协商是传统商业活动中最重要、最能体现人类智慧的组成环节;在当今海量信息共
贝叶斯网络是20世纪80年代提出的不确定性推理方法,它为依赖关系和因果关系提供了一种自然而有效的表达方式。贝叶斯网络具备概率推理能力强、语义清晰、易于理解等技术特点,
随着数据库技术的迅速发展以及数据库管理系统的广泛应用,很多企业已经建立了自己的数据库信息管理系统,积累了大量的业务操作数据。这其中也同样蕴藏着大量有价值的但却未被发
目前网络信息利用模式有许多根本性缺陷,网络完全按照用户指定的信息类型和信息源地址,搜索和提供用户所需要的信息,网络中海量的、随机的、并发的、分布的利用信息的行为,被看作
图像处理技术是利用计算机来处理、分析和理解视觉信息的一项技术。随着计算机科学技术的巨大进步,图像处理技术研究和应用的领域正在迅速的延伸。一些具有高鲁棒性的图像处理
软件可靠性是软件质量的重要因素,可靠性评估是对软件可靠性进行定量控制的必要手段。传统的可靠性评估方法都是基于系统运行期间的失效分析,对于武器型号软件,由于其使用试验耗
随着企业规模、范围、分支机构的不断扩展,企业内部及企业之间的信息量迅速增大,使得基于 Internet 的传统商务应用出现了诸多问题:网络的复杂性、管理的繁重性、信息的安全
多媒体技术及网络技术的飞速发展使得大量音乐数据可以在网上流通,多媒体数据库中的音频尤其是音乐数据呈爆炸式增长。然而,大规模音乐库的价值与用户能否有效地浏览音乐库的内
本文给出了一个基于J2EE的管理信息系统的设计方案.我们首先从系统背景及开发技术选择谈起,介绍了软件体系结构的发展.在第三章详细说明了所选的J2EE模型的概念、体系结构和