节点文献

基于web的集中身份认证管理系统的网管子系统的设计与实现

The Design and the Implementation of Network Management Subsystem of Centralized Identity Authentication Management System Based on Web

【作者】 杨波

【导师】 程保中;

【作者基本信息】 北京邮电大学 , 软件工程, 2007, 硕士

【摘要】 在电信网络中,由于很多人为因素,导致系统被非法访问,给电信网络的安全造成了巨大威胁。建立对用户访问身份的认证、鉴权和审计(AAA)系统,可以解决这一问题。但是,目前的电信IP网络中,设备类型众多、数量大,存在多种AAA认证协议,各厂家设备对AAA的支持情况有所不同,同时存在系统用户帐号管理分散的问题。因而,建立一个集中的身份认证管理系统,将不同认证类型的设备纳入统一的管理系统中来,对系统中所有用户的帐号进行集中管理,对用户访问系统的行为进行集中控制就成了当务之急。本文主要通过对集中身份认证系统的发展现状,TACACS+和RADIUS两种身份认证技术和基于Web的网络管理系统的分析,针对设备认证类型多样和用户帐号管理分散的问题,提出了集中的身份认证管理;特别是针对不支持AAA认证协议的设备,提出了代理认证的方式。通过将各种认证方式集中到一个管理系统中,实现了对网络设备认证的统一管理,简化了用户认证信息的维护。此外,本文还研究了通过网络管理系统来实现集中身份认证的配置管理和查询监控,给用户的管理工作提供便捷的途径。本论文的主要工作如下:1.调查和研究了目前的集中身份认证系统,对主要的技术和策略进行了详细分析。2.研究了主要的身份技术,对TACACS+和RADIUS协议进行了重点分析。3.研究了基于Web的网络管理系统和基于jsp/servlet的Web三层软件架构,对各种关键的软件技术进行了深入分析。4.通过需求分析,给出总体方案;并按功能划分,设计出各功能子系统。5.采用了统一建模语言和面向对象的系统设计方法,设计出网管子系统各功能模块。6.主要利用java/web技术,开发实现网管子系统并进行了功能展示。随着电信网络安全性日益变得重要和集中身份认证技术的不断发展,集中身份认证管理系统也必将得到越来越广泛的应用。

【Abstract】 In telecommunication network, with some factors related with people the system is visited illegally, thus posing the huge threat for the telecommunication network security. The establishment of centralized identy authentication、authorization and accounting (AAA) system related to user’ s access can solve this problem. However,At present telecommunication IP network consists of multitudinous type of equipment which quantity is big. Many kinds of AAA authentication agreement exists together and various vendor’s equipment support AAA differently, simultaneously the system users’s accounts are managed dispersedly. Thus it is a urgent matter to establish a centralized identity authentication management system, bring the equipments into the unific management system which authentication types are different, simultaneously carry on the centralized management for all user’ accounts and carry on the common control to the users’s behavior visiting the system.Through analysis about the development of centralized identity authentication system, TACACS + and RADIUS authentication technology and Web-based network management system, we develop a centralized authentication management system against various types of equipment authentication method and user account management of the problem of dispersiveness; particularly against the equipments which don’t support AAA authentication protocol, we develop the proxy authentication approach. By integrating various authentication in a centralized management system, we implement the unified management of different authentication network equipment, simplify the maintaining of user authentication information. In addition, the system also develop the network management system through which user can achieve centralized authentication configuration management, monitoring and inquiries, thus provide user with convenient way to manage.The paper describes following parts :1. Research current centralized identity authentication system, furthermore analysise the main technical and strategy detailedly.2. Research major identity authentication technology, and emphatically analysis TACACS + and RADIUS protocol. 3. Research Web-based network management system and three-tier Web software - structure based on jsp/servlet and analysis the key software technology deeply.4. Through demand analysis, design the overall project and functionally design corresponding subsystems.5. Design network management subsystem modules Using the unified modeling language and object-oriented system designing method.6. Develop and implement network management subsystem mainly using the java / web technology and make the function display.With telecommunication network security becoming increasingly important and centralized identity authentication technology continuously developing, the centralized identity authentication management system will be widely used.

  • 【分类号】TP393.07;TP311.52
  • 【被引频次】2
  • 【下载频次】170
节点文献中: