节点文献
RBAC扩展J2EE/JAAS安全机制的设计与实现
Research and Implementation of RBAC-based Security Architecture of J2EE
【摘要】 提出了一种拓展J2EE平台安全性的设计,将基于角色的访问控制应用到Web应用中。设计方案将In ternet上的各种资源抽象成URI,采用JAAS和Filter技术集中管理,将开发阶段需要考虑的安全问题转移到了部署阶段,从而实现应用逻辑与安全逻辑分离的目的。归纳了面临的问题和解决办法,最后给出了典型环境下的应用。
【Abstract】 Here gives a design of expending security of J2EE architecture, which applied role-based access control to Web application on Internet. Web resources are considered as entitys identifiered by URI. An additional tire is applied to Web container to adapt 3th security products. The security issue considered in development phase can be moved to deployment.
【关键词】 Java认证与授权服务;
J2EE;
Filter;
基于角色访问控制;
Web安全;
【Key words】 JAAS; J2EE; Filter; RBAC; Web Security;
【Key words】 JAAS; J2EE; Filter; RBAC; Web Security;
【基金】 总装备部基金资助项目(51415010101DZ02)
- 【文献出处】 计算机应用研究 ,Application Research of Computers , 编辑部邮箱 ,2005年01期
- 【分类号】TP393.08
- 【被引频次】19
- 【下载频次】221