节点文献

企业门户的安全基础

The Security Foundation of Enterprise Portal

【作者】 孟庆玲

【导师】 张李义;

【作者基本信息】 武汉大学 , 管理科学与工程, 2005, 硕士

【副题名】基于目录服务的企业身份管理系统研究

【摘要】 企业门户作为“出入企业的必经要地”为企业员工、客户、合作伙伴提供所需的信息和服务,及时传递所需的数据,实现内部、外部信息的直接交流。 企业门户的安全基础—认证、授权和个性化,单点登录,需要有企业用户库来支持,但是传统的关系数据库存储方式无法满足门户性能要求,企业门户需要一个高性能的企业身份管理系统来支持它的需求。目录服务的核心是一个树状结构的信息目录,将网络中的数据资源、数据处理资源和用户信息按有次序的结构进行组织,并且专门针对海量查询的使用情况进行了优化,极大地提高了数据读取和查询性能。可以满足企业门户的需要。 目前的身份管理系统共包括4个部分:保存有个人数据等信息的目录;一套能够添加,修改,删除数据的管理系统;验证访问身份的安全系统;确保企业符合隐私法律的审查系统。其中,前两部分是身份管理系统的基础,在本文中分别将其称为企业身份目录和企业身份目录管理系统,企业身份目录管理系统是基于企业身份目录之上的应用。 全文共分为六个部分: 第一部分主要阐述了企业门户的基本概念,企业门户实施的必要性以及企业门户与目录服务的关系。 第二部分以目录服务为中心,介绍了企业门户的几个与目录服务相关的安全机制,包括目录服务技术的发展、轻型目录访问协议(LDAP)、目录服务产品以及目录服务在存储信息、认证和授权方面的应用。 第三部分是本文研究的重点,主要论述了目录服务系统的规划设计方法和准则,同时将其应用于企业身份管理系统中的企业身份目录的设计中,根据企业的需求分别设计出企业身份目录树、属性类型和语法、对象等。并提出改善企业身份目录性能的方法和策略。 第四部分是基于前面部分建立的企业身份目录的基础上设计开发了一套企业身份目录管理系统,更好地实现企业身份目录的日常管理包括用户的增删、授权以及分级管理,满足企业的管理需要。 第五部分则是将企业门户与基于LDAP目录服务的企业身份目录结合,通过实例来展示了企业身份目录在企业门户的认证、授权、个性化以及单点登录方面的应用,并对结果进行了分析。 最后,本文对论文研究工作作出了总结,并提出对未来研究工作的展望。

【Abstract】 As the important place that they must go through ,enterprise portal provides the needed information and services for the employee、 customers and partners, and transfers the needed data timely, then realizes the direct communication between information from internal and external.The security foundation of enterprise portal—authentication、 authorization、 personalization and single sign on, needs the support of the enterprise users storehouse, but the traditional storage method of relational database can’t meet the performance requirement of the enterprise portal. It needs the support of one enterprise identity management with high performance. The core of directory services is a tree-like information directory. Directory services organize the data resources、 data treatment resources and users information according the ordered structure, and it has been optimized pointing at the use of a large number of search. Directory services improve greatly the performance of reading and searching data. And it can meet the need of the enterprise portal.Current identity management system includes four parts: the directory storing the personal data and etc; a management system that can be used to add, modify and delete the data; the security system that verifies the visit identity; the audit system that assures the enterprise confirms to the privacy law. Among them, the former two parts are the foundation of the identity management system, which are called the enterprise identity directory and enterprise identity directory management system. The enterprise identity directory management system is the application based on the enterprise identity directory.The dissertation is divided into six parts:The first chapter mainly introduces the basic conception of enterprise portal, presents the necessary to implement the enterprise portals and the relationship between directory services and enterprise portal.In the second part, the directory service is the core. It describes a few of security mechanisms of the enterprise portal that related with directory services. at the same time, it introduces the development of directory services technology、 the light weight directory services access protocol(LDAP)、 the production of directory services and the application of directory services in storing information、 authentication andauthority.The third part is the key point of this dissertation, it mainly tells about the means and rules of planning and designing of directory services system, at the same time, these methods and rules are applied into enterprise identity directory. According to the requirement of the enterprise, the enterprise identity directory tree> the attribute type and syntax> the objects are all designed in this part, in the meantime, the method and strategy to improve the performance of enterprise identity directory is mentioned too.The following part designs and develops one enterprise identity management system based on the identity directory, and can deal with the usual management of identity directory better, including the functions such as adding and deleting as well as the authentication and management in grades. This system can meet the management requirement of the enterprise.The fifth part integrates the enterprise portal and the enterprise identity directory based on LDAP. Some examples are present, including the application of the enterprise directory in the authentication > authorization -. personalization and single sign on of the enterprise portal. In the end, this part analyses the result.At the end of the dissertation, it summarizes the whole research work, andadvances the future research work.

  • 【网络出版投稿人】 武汉大学
  • 【网络出版年期】2006年 05期
  • 【分类号】TP393.092
  • 【被引频次】1
  • 【下载频次】140
节点文献中: