节点文献
一种新的兼容多种身份认证方式的Web单点登录方案
A New Web Single Sign-on Scheme Supporting the Multiple Authentication Modes
【摘要】 传统的Web单点登录(SSO)方案是基于用户信息资源集中存放、单种身份认证方式机制而建立的,满足不了动态松耦合环境下业务流程的认证需求.为了解决上述问题,对ticket技术、代理技术、数字签名技术进行了研究,提出了一种SSO新方案,它使用cookie作为传输载体,利用ticket代理技术实现兼容多认证方式SSO,同时它基于证书链信任关系建立认证信任链以实现跨域范围的SSO.结果表明,该方案在有效解决以往方案缺点的同时,也具备更高强度的安全性,具有广泛的应用前景.
【Abstract】 Existing single sign-on(SSO) schemes are built on centralized user information storage mechanism and single authentication mode,and it’s hard to meet the requirement of business operations in the dynamic and loose-coupled environment.To solve above problems,the ticket technology,agent mechanism and digital signature are studied,a new better SSO scheme is presented that uses cookie transmission carrier and ticket technology to support multiple authentications SSO,in addition,it establishes a authentication trust chain to support cross-domain SSO based on certificate trust chain.The results show the new scheme provides higher security and wider usage range,while it overcomes the shortcomings of the existing.
【Key words】 single sign-on; multiple authentication modes; cross-domain authentication; trust chain;
- 【文献出处】 北京邮电大学学报 ,Journal of Beijing University of Posts and Telecommunications , 编辑部邮箱 ,2006年05期
- 【分类号】TP393.08
- 【被引频次】39
- 【下载频次】364