节点文献

管理信息系统安全模型的研究

Research on Security Model for Management Information System

【作者】 向华萍

【导师】 万仲保;

【作者基本信息】 华东交通大学 , 计算机应用技术, 2006, 硕士

【摘要】 随着计算机技术的发展与普及,许多企事业单位和管理机构都建立了自己的管理信息系统。在信息系统开发设计过程中,安全性能总是被放在首要的位置,成为信息系统生存的关键。构建企业级信息系统的安全模型已日益成为一个重要的研究领域。 本文以管理信息系统的安全要求为出发点,对信息安全模型及相关的信息安全技术展开了深入的研究,从授权的时限性方面对典型的RBAC96做了扩展,设计了一个具有时限的基于角色的访问控制模型。它是一个具有通用性的企业级信息系统的安全模型,由一系列组件构成,包括访问控制组件、身份验证组件及数据库加密组件。 访问控制组件用来实现对系统的安全访问,防止非法用户进入系统以及合法用户对系统资源的非法操作。本文将访问权限与角色相联系,通过给用户分配适合的角色,让用户与访问权限相联系。在本模型中,用户的授权是具有时限性的,用户通过身份认证后,系统只激活在时限内的权限,将此作为用户能否访问系统资源的依据。而且在本模型中,实行三权分立方案,将管理权限分割给系统管理员,安全管理员和应用管理员,这三个角色各行其责,相互监督制约。 本文从系统运行效率和安全性出发,采用两种认证方式实现对不同级别用户的身份认证,即基于摘要口令的认证方式和基于椭圆曲线的认证方式。后者的安全级别更高,其安全性是基于解椭圆曲线离散对数问题的困难度。 在数据库加密方面,通过对各种加密算法的分析比较,选择综合性能比较好的3DES算法结合子密钥技术对数据库中敏感信息进行加密,并采用二级密钥工作方式,主密钥用于生成工作密钥,用工作密钥对数据进行加密,实现密钥的动态管理。数据的加密解密都在客户端进行,保证了数据传输的安全。 最后通过一个实际的应用系统——基于B/S的高校信息统计管理系统,验证了本模型的实用性和通用性。

【Abstract】 With the development and the widely use of computer technology, lots of corporations and institutions have established management information systems. In the process of developing an information system, security has always been given the first priority, which is critical for the survival of the information system. Therefore, designing a security model of enterprise information becomes a more important research field.This paper starts at the security requirement of management information system, focuses on information security model and related security technology, and extends the traditional RBAC96 from temporal delegation to design temporal role-based access control model. This model, an enterprise information system universal security model, is composed of a series of the components including access control components, identity authentication components and database encryption components.The access control components implements security access to the system, and prevents the illegal user from entering the system, keeping the validated user from the illegal using of system resource. In the paper, user contacts with access permissions through contacting roles with access permissions and allocating suitable roles to the user. The security model supports temporal delegation. After identity authentication of the user, the system will activate his valid permissions which decide whether he can access the system resources. Moreover the paper divides the superpower into three parts, conferred respectively on the system administrator, the security administrator and the application administrator, and these three roles take their respective responsibility and supervise each other.The paper implements identity authentication for different ranked users with different authentication mode, digest-password-based authentication mode and elliptic-curve-based authentication mode, considering the requirements of system security and efficiency. Security of the latter relies on the difficulty to solve the discrete logarithm problem of elliptic curve.In the database encryption aspect, the paper analyses kinds of encryption algorithm, and combines 3DES algorithm which is better than others with sub key technology to encrypt the important information in the databases. The paper adopts two-level key management mechanism, including the main key used to create the work key and the work key used to

  • 【分类号】TP315
  • 【被引频次】6
  • 【下载频次】611
节点文献中: