节点文献
基于SAML的WEB单点登录系统安全模型设计
Design of SAML-Based Web Services Single Sign-on Security Model
【摘要】 本文从安全性、互操作性基础上提出了一种基于SAML规范的单点登录模型,在设计本模型时,考虑到SAML在安全性上的弱点,使用WS-Security规范来保证SAML断言和重要信息的端到端的安全传输。本文描述了该模型的单点登录过程及实现,对其安全性进行了分析并给出了相应的安全策略。该模型具有兼容性、容易部署及良好的可扩展性等特点。
【Abstract】 Considering security and interoperability,the paper puts forward a Single Sign-On model based on SAML specification.In developing and implementing the system and in view of the weakness of SAML on security,the author depend on WS-Security speci-fication to ensure end to end safe transfer of SAML assertion and other sensitive message.The paper analyzes the flow and security of this single sign-on System.The system has compatibility and better expansibility it can be deployed easily.
【关键词】 安全声明标记语言;
单点登录;
安全令牌;
Web服务安全性;
【Key words】 SAML; Single Sign-on; Security Token; WS-Security;
【Key words】 SAML; Single Sign-on; Security Token; WS-Security;
【基金】 基金申请人:陈运;项目名称:3G移动宏支付安全研究;基金颁发部门:四川省科技厅应用基础项目(2008JY0078)
- 【文献出处】 微计算机信息 ,Microcomputer Information , 编辑部邮箱 ,2009年21期
- 【分类号】TP393.08
- 【被引频次】11
- 【下载频次】129