节点文献

制造资源重组中的访问控制与统一身份认证技术的研究

Research of Access Control & Unitive Authentication Technology on Recombinating Manufacture Resource

【作者】 任河

【导师】 李杰;

【作者基本信息】 机械科学研究院 , 机械制造及其自动化, 2004, 硕士

【摘要】 动态联盟、资源共享和信息安全是现代制造资源重组中的关键问题。制造企业动态联盟的出现,带动了制造业传统生产方式的变革,实现了联盟企业间的优势互补、相互协作和资源共享,进一步优化了制造资源重组的环境。而如何保证联盟资源共享环境的安全性,为联盟企业建立良好资源访问控制机制、建立统一资源管理站点和用户认证机制,是制造资源重组过程中的关键问题。对整个制造企业动态联盟的发展有着及其重要的意义。 本文顺应制造资源重组的变革趋势,通过对网络技术、信息安全技术、人工智能技术、数据库技术研究,建立联盟资源共享环境的安全控制模型,并最终实现联盟资源安全与统一身份认证的原型系统。 本文的主要工作为: 1、分析了制造企业动态联盟的基本特征和联盟资源的支撑环境;归纳总结了网络信息安全的支撑技术;分析现有统一认证系统,讨论了各自的优缺点。 2、针对制造联盟企业资源分布式的特点,提出了联盟网格(Alliance Grid)的概念;根据联盟网格安全访问控制的指导思想,提出了联盟网格访问控制模型;在一般RBAC模型的基础上提出了基于角色的联盟网格访问控制模型,清晰的表述了角色之间的层次关系;初步分析了AG-RBAC的实现模式,重点讨论了角色定义和权限配置的实现方法。 3、针对统一身份认证技术的有关问题进行了深入探讨,分析了现有的认证理论和技术特点;提出了统一身份认证技术是一个多技术支持的概念统称;是众多相关技术集成后统一体,并归纳总结了相关技术;提出了本文的重点内容,统一身份认证系统的体系结构、网络模型和功能模型。 4、进一步从安全性的角度,分析总结了网络安全的相关问题;针对WEB安全威胁进行了分析,并提出了相应的对策;针对信息加密的要求,总结了有关的加密服务,提供了MD5算法的实现原型;提出了基于Agent的实时监控系统模型,提供了C#下的相关算法程序,并完成了基于C/S结构的Agent实时监机械科学研究院硕士学位论文 控原型系统。5、根据基于角色的网络资源访问控制的理论,以及统一身份认证的网络模型和 功能模型实现了本文的原型系统;通过对集团管理、角色管理、用户管理、 用户组管理、资源管理、模块管理、日志管理等的模块实践,验证了系统原 理的正确性以及实践的可行性;整个原型系统采用B/S三层结构。

【Abstract】 Dynamic Alliance, Resource Sharing and Information Security are key problems in modern recombinating manufacture resource. The emergence of dynamic alliance of manufacture enterprise, drivers great changes of traditional producing ways in manufacture enterprise, realizes supplement, cooperation and resource sharing between allied enterprises, optimizes environment of recombinating manufacture resource. But they are the key problems in process of recombinating manufacture resource, how to ensure the security about sharing environment of allied resource for allied enterprises, how to build the better access control ways, build unitive resource management site and authenticating users rules. The research on above issues has very important meanings to the improvement of dynamic alliance in manufacture enterprise.This paper follows mutative direction of recombinating manufacture resource, builds security control model of sharing environment of allied resource, by the research of network technology, information security technology, artificial intelligence technology and database technology. And finally realized prototype system of allied resource security and unitive authentication.The main content of research is as following:1. The basic character of dynamic alliance of manufacture enterprise and supporting environment of allied resource are analyzed. The supporting technologies of network information security are summarized. The unitive authentication systems existing are analyzed in this paper; their virtues and shortcomings are discussed.2. About the distributed peculiarities of allied resource, the concept of alliance grid is established. The access control model of alliance grid is established by directive ideas of access control security of alliance grid. AG-RBAC model is set up in the basic of common RBAC, interbedded relations between roles are set forth. This paper analyzes the realized model primarily, discusses methods of defining roles andconfiguring privilege.3. To discuss some problems of unitive authentication system deeply, the existing authentication theories and technologies are analyzed. It is established that the unitive authentication technology is a general concept of many supporting technologies, an entia many correlative technologies compositing, and other correlative technologies are summarized. The main content in this paper, the architecture, the network model, the function model of unitive authentication system, are brought forward.4. From the view of security, the correlative problems of network security are analyzed and summarized deeply. To get the solution of web security, the conditions of threatening web security are analyzed. The encryption service related with this paper are summarized, and the model of MD5 algorithm are set up for requirement of information encryption. Some problems are resolved in this paper, it includes real-time monitor model, algorithm program under C, and realized agent real-time monitor prototype system based C/S framework.5. The prototype system is set up in coordination with theory of AG-RBAC, the network model and function model of unitive authentication. The main functions, such as group management, role management, user management, user group management, resource management, module management, log management, are carried on practice. The exactness and feasibility of the prototype system has been verified. The B/S structure is adopted in the prototype system.

  • 【分类号】TP399
  • 【被引频次】3
  • 【下载频次】173
节点文献中: 

本文链接的文献网络图示:

本文的引文网络