节点文献

基于SAML的单点登录模型及其安全的研究与实现

Research and Implementation of SAML-based SSO Model and It’s Security

【作者】 尹星

【导师】 肖铁军;

【作者基本信息】 江苏大学 , 计算机应用技术, 2005, 硕士

【摘要】 单点登录的基本思想就是一次登录,任意访问。由于Web服务业务经常需要不同域中的多个站点协同工作,这就面临跨域的协同认证和安全信息传递的问题。因此,基于统一标准的跨域的单点登录成为当前国内外安全领域的研究热点。 本文对当前单点登录系统虽然能提供单个域内多个站点之间的联合认证,却面临缺乏统一标准、运行流程过于复杂、无法跨域实施和安全性不足等问题,进行了深入的考查与阐述。在对用于跨域交换身份验证和授权信息的标准规范——SAML进行了详细研究的基础上,着重对基于SAML的两种典型的单点登录模型进行了深入的比较和分析,针对这两种模型的运行流程较为复杂等不足之处,提出了基于SAML规范的单点登录改进模型,以简化单点登录过程中系统的运行流程。 为了使改进模型不因流程的简化而降低安全性,本文接着对简化后的单点登录过程中重要信息传递将会面临的安全隐患进行详细的预测和分析。结合对现有的传输层安全技术和基于PKI的XML安全技术这两种常用的Web服务间消息保护和验证机制的研究,在对它们各自的优缺点进行了比较,并参照Web服务安全规范的基础上,通过综合使用XML签名、XML加密和添加标识符信息等技术,进一步提出了单点登录系统中端到端的安全信息传输方案。 为了将上述理论构思应用到实际的安全系统中,并加以验证,本文设计了一个基于SAML的单点登录系统的整体架构,同时对整个系统的执行流程进行详细的构思和描述,并为该系统设计了客户端、中心安全服务端和目标服务端这三个端点,以及消息安全处理模块、传输模块这两个通用模块。然后逐一对系统的各个部分进行了详细的设计和实现。 最后,本文通过一个应用示例,演示了该系统预期的简化运行步骤,验证了基于改进模型的单点登录系统的可行性和安全性。

【Abstract】 The basic philosophy of Single Sign On is to provide unlimited accessing with single sign-on. Because web services involve the coordination of many sites belonging to different domains, it will bring about the issue of cross-domain coordinated identification and the security message transport. Therefore the cross-domain Single Sign On based on uniformed standards has become a focus of the researches in the security field at home and abroad.Based on the analysis of security requirements of current Web Services, the basic philosophy of Single Sign On system, and the frequently employed Single Sign On technology at home and abroad, the present dissertation elaborates on such issues as the lack of uniform standards, over-complicacy of the flow, the inability of cross-domain operation and security deficiency, to name just a few, which are beyond the capability of the current Single Sign On system, though it can provide us with joint identification between many sites in the single domain. On the basis of a detailed study of SAML, the paper focuses on the fundamental comparison between and analysis of the two typical Single Sign On models grounded on SAML. The author then puts forward an Improved of Single Sign On model founded on SAML to simplify the flow of the system during the Single Sign On process. On the basis of the Improved Single Sign On model, the present dissertation designs an overall architecture of Single Sign On system grounded on SAML, conceives the operation flow of the whole system in great details and describes it at length with an aim to apply the above-mentioned theories into practical security system. And the paper divides the system framework into three entities and two common modules with the former being Client End, Center Secure Service End and Destination Service End and the later being XML Information Security Processor and Transport Interface. Then the paper offers detailed design and respective implementation methods one by one.The present thesis not only brings forth an Improved Single Sign On model but also makes a minute prediction and analysis of the hidden security trouble which the clients may be confronted with in the transport of important messages during the simplified Single Sign On process. The paper combines the study of the two frequently used information protection and identification mechanism in many Web Services, namely, present security technology in the transport layer and XML securitytechnology, and makes a comparison between their advantages and disadvantages. Referring to Web Service Security Criterion, the thesis further advances the end-to-end security message transport in the Single Sign On system through the comprehensive use of XML security technology and the effective identity information. In the last part the present paper employs a demonstration to identify the theories and technologies above. The demonstration shows the expected simplified Sign On step of this system and educes the system security index.

【关键词】 SAML单点登录Web服务安全XMLWeb服务
【Key words】 SAMLSingle Sign On(SSO)WS-SecurityXMLWeb Services
  • 【网络出版投稿人】 江苏大学
  • 【网络出版年期】2005年 08期
  • 【分类号】TP393.092
  • 【被引频次】37
  • 【下载频次】729
节点文献中: