节点文献

在线招投标系统中安全体系的设计与开发

【作者】 刘微微

【导师】 程景云;

【作者基本信息】 上海海运学院 , 计算机科学及应用, 2001, 硕士

【摘要】 随着互联网的推广和普及,电子商务发展得如火如荼。安全问题——作为保证电子商务健康有序发展的关键因素也越来越突出,越来越受到关注。 我的论文工作就是在一个具体的电子商务系统——在线招投标(e_Tender)系统中实施安全保障措施,从而确保招投标业务公平、公开、公正地进行。 本文结合论文的展开,主要讨论了以下内容: (1)论文背景、论文来源和论文目标。 (2)介绍电子商务的定义、框架构成及其安全性。其中对于电子商务的安全性主要从如何认识安全、安全隐患、安全所涉及到的技术、安全体系结构、国内外研究现状等几个方面进行了详细的说明,从而对电子商务的安全有一个总体的了解。 (3)主要介绍信息安全的关键技术——加密技术。加密技术是保障信息安全的最核心的技术措施,其他所有的安全防范措施都是建立在加密技术的基础之上的。本章内容包括密码学的基础、单钥密码体制(对称密码体制)、公钥密码体制(非对称密码体制)等,并展望当前加密技术的发展趋势。 (4)讨论了公开密钥基础设施PKI/CA认证体系。PKI/CA可以支持认证、完整性、机密性和不可否认性。它是在SSL协议的支持下,通过将对称和非对称加密技术结合起来实现的,为系统实施安全提供了一种体系结构。 (5)重点介绍了e-Tender系统的总体目标、业务流程、整体架构、层次功能、设计方案及开发环境。 (6)探讨了e-Tender系统中安全子系统的设计方案及具体实施。描述了一个具体的PKI/CA系统是如何实施的,其中包括安全的需求分析、安全方案的设计、证书的使用、客户端、服务器端及开标时安全的实现。 作为e_Tender项目组的重要成员,我主要负责整个系统的安全设计与实现。该系统的安全是基于PKI/CA框架来实施的。PKI/CA是一个比较全面的实施安全的体系结构,用来实现基于公钥密码体制的证书产生、管理存储、发行和作废等功能,其中证书体制和CA得到了广泛的应用。从而为系统提供了诸如数据完整性、防否认和身份认证等的安全服务。 此外,实用安全性与用户需求和应用环境也是紧密相关的。每个系统对于安全都有自己特殊的要求,招投标系统也不例外。在该系统中,由于投标文件的敏感性,我们对此进行了进一步的保密工作。引入了一个新的概念——项目证书,项目证书是由招标人根据特定的招标项目向CA申请的。投标人利用项目证书和站点服务器证书对 投标文件进行双重加密,以避免招标人和站点服务器任何一方在开标之前打开投标文 件,从而确保了投标文件的安全,防止有人从中牟利,泄漏信息,破坏招投标工作的 顺利展开。

【Abstract】 With the development of the Internet, the Electronic Business develops rapidly. The security, which is the key factor to the development of the Electronic Business, is becoming more and more important.This paper presents my work on the design and implementation of the security institution of the Electronic Tendering System.The contents are:(1) The background, source and goal of the research.(2) The definition, frame and security of the Electronic Business. Emphasis is put on the latter.(3) The encrypting technology. It is the core technology on assuring information safe that other technologies are based on. Here the foundation of the cryptology, symmetrical encrypting system, unsymmetrical encrypting system and the prospect of the cryptology are introduced.(4) The PKI (Public Key lnfrastructure)/CA (Certificate Authority) frame. The PKI/CA supports authentication, confidentiality, integrality and undeniablilty. Based on SSL (Secure Socket Lay) protocol, the PKI/CA combines the symmetrical encrypting technology and unsymmetrical encrypting technology and provides a frame for the implementation of the security.(5) The whole goal, operation flow, hiberarchy, functions, design scheme and development environment of the Electronic Tendering System.(6) The design and implementation of the security sub-system in the Electronic Tendering System. This chapter describes how a certain PKI/CA system is implemented, including the requirement analysis, the safety scheme design, the using of the certificates, the client safety, the server safety and the security at the time of unsealing the bidding files.As an important member in this project group, I am in charge of the design and implementation of the security of the whole system. The security implementation of this system is based on PKI/CA. The PKI/CA frame realizes the creating, storing, issuing, recalling certificates so as to provide data integrity and identity authentication for the system.In addition, applied security is closely related to the user’s requirement and the environment. Each system has special safety requirements, so does theElectronic Tendering System. We introduce a new concept in this system-Project Certificate because of the sensitivity of the bidding files. The Project Certificate is requested by the tenderee and created by CA according to the tendering project. The bidders doubly encrypt the bidding files with the Project Certificate and the Server Certificate so that both tenderee and server can’t open the bidding files before the unsealing moment. This step assures the bidding files safe so as to enable the tendering work to go on wheels.Liu Weiwei (Computer Science and Application) Directed by Prof. Cheng Jingyun

  • 【分类号】TP399
  • 【被引频次】5
  • 【下载频次】197
节点文献中: