【24h】

Features and security aspects of FASS subsystem

机译:FASS子系统的功能和安全性方面

获取原文

摘要

This paper describes fundamental goals and features which one open source, free modular Administrator subsystem should provide. Main goal of entire project was to develop stand-alone administrator subsystem, with complete modular access control and strong data encryption of critical data. FASS (Free Administrator Subsystem) is a downgrade version of Administrator subsystem HEFES 2.0, and contains only its basic features. Features and security aspects of Administrator Subsystem HEFES version 1.0 where published in paper [8], while a paper describing full features of Administrator subsystem HEFES 2.0 will be published in the near future. This paper also describes technologies which were used while developing the administrator system. Data encryption is provided by SHA256 algorithm and TSL security standard. FASS subsystem relies on Java Servlet technology which provides full control over response which is sent from server to a client. Since FASS subsystem also relies on MySQL database service, system security is brought to a new level by developing a set of classes which are designed to stop MySQL injection attacks on the system. Formed classes filter every input data and Query parameters which are transmitted while communicating with servlets. Interface of FASS subsystem was developed in a way so it provides simple and functional access to FASS subsystem, which makes job of a System Administrator much easier, especially in the areas of system maintenance and access rights management through developed ROLE system. Implemented ROLE system has a feature of role inheritance by which, access rules can be inherited from some role, and then modified. This concept was borrowed from Oracle type databases.
机译:本文描述了一个开源,免费的模块化Administrator子系统应提供的基本目标和功能。整个项目的主要目标是开发独立的管理员子系统,该子系统具有完整的模块化访问控制和关键数据的强大数据加密功能。 FASS(免费管理员子系统)是管理员子系统HEFES 2.0的降级版本,仅包含其基本功能。论文[8]中发布了Administrator Subsystem HEFES版本1.0的功能和安全方面,而在不久的将来还将发布描述Administrator Subsystem HEFES 2.0的全部功能的论文。本文还介绍了开发管理员系统时使用的技术。数据加密由SHA256算法和TSL安全标准提供。 FASS子系统依赖Java Servlet技术,该技术可完全控制从服务器发送到客户端的响应。由于FASS子系统还依赖于MySQL数据库服务,因此通过开发一组旨在阻止对系统的MySQL注入攻击的类,将系统安全性提高到一个新的水平。形成的类过滤与Servlet通信时传输的每个输入数据和查询参数。 FASS子系统的接口以某种方式开发,因此它提供了对FASS子系统的简单功能访问,这使得系统管理员的工作更加轻松,尤其是在通过已开发的ROLE系统进行系统维护和访问权限管理方面。已实现的ROLE系统具有角色继承的功能,通过该功能,可以从某些角色继承访问规则,然后进行修改。这个概念是从Oracle类型数据库中借用的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号