节点文献

RBAC扩展J2EE/JAAS安全机制的设计与实现

Research and Implementation of RBAC-based Security Architecture of J2EE

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 陈阳佘堃周明天

【Author】 CHEN Yang,SHE Kun,ZHOU Ming-tian (Information Secure United Laboratory of UESTC-Westone,School of Compuer Science & Engineering,University of Electronic Science & Technology of China,Chengdu Sichuan 610054,China)

【机构】 电子科技大学计算机学院卫士通信息安全实验室电子科技大学计算机学院卫士通信息安全实验室 四川成都610054四川成都610054四川成都610054

【摘要】 提出了一种拓展J2EE平台安全性的设计,将基于角色的访问控制应用到Web应用中。设计方案将In ternet上的各种资源抽象成URI,采用JAAS和Filter技术集中管理,将开发阶段需要考虑的安全问题转移到了部署阶段,从而实现应用逻辑与安全逻辑分离的目的。归纳了面临的问题和解决办法,最后给出了典型环境下的应用。

【Abstract】 Here gives a design of expending security of J2EE architecture, which applied role-based access control to Web application on Internet. Web resources are considered as entitys identifiered by URI. An additional tire is applied to Web container to adapt 3th security products. The security issue considered in development phase can be moved to deployment.

【关键词】 Java认证与授权服务J2EEFilter基于角色访问控制Web安全
【Key words】 JAASJ2EEFilterRBACWeb Security
【基金】 总装备部基金资助项目(51415010101DZ02)
  • 【文献出处】 计算机应用研究 ,Application Research of Computers , 编辑部邮箱 ,2005年01期
  • 【分类号】TP393.08
  • 【被引频次】19
  • 【下载频次】221
节点文献中: 

本文链接的文献网络图示:

本文的引文网络