首页> 外文会议>International Conferece For Internet Technology And Secured Transactions >Authorization model of SSO for a distributed environment based on the attributes
【24h】

Authorization model of SSO for a distributed environment based on the attributes

机译:基于属性的分布式环境的SSO授权模型

获取原文

摘要

With the distributed application of computer technology and continuous development, more and more service systems provide us with information services, each service needs to have permission to verify this general requirement. At the same time, based on dynamic, loosely coupled environment, the business process will involve more than one ISP so that users need to face the trouble of multiple logins to complete it. Traditional users single sign-on (SSO) mechanism have solved the trouble of users' multiple logins to complete the business [1]. However, the traditional authorization is based on the role of request access to the entity of resources, either directly or indirectly assigned to the login access to these entities or log on roles, but these are unable to meet current validation requirements service, for example: we need to verify the status of the entities, the balance, consumer grade and so on [2]. Therefore, this paper based on an open source framework, called CAS; develops a model of SSO Service authorization under distributed environment [4]. It uses the XACML to achieve an attribute based access control (ABAC) [3], this model is characterized by the following three points: 1. complete SSO under distributed environment [4], 2. Able to verify data sources from different databases when completing SSO; 3. Able to use property-based verification for more accurate authorization after authentication. These make access control to be more flexible, a wider range of usage and a finer granularity of control.
机译:通过计算机技术的分布式应用和持续发展,越来越多的服务系统为我们提供信息服务,每个服务都需要有权验证这一普遍要求。同时,基于动态,松散耦合的环境,业务流程将涉及多个ISP,以便用户需要面对多个登录的麻烦来完成它。传统用户单点登录(SSO)机制解决了用户多个登录的麻烦,以完成业务[1]。但是,传统授权是基于请求访问资源实体的角色,无论是直接还是间接分配给对这些实体的登录访问或登录角色,但这些都无法满足当前验证要求服务,例如:我们需要验证实体的状态,余额,消费者等级等[2]。因此,本文基于开源框架,称为CAS;在分布式环境下开发SSO服务授权的模型[4]。它使用XACML实现了基于属性的访问控制(ABAC)[3],该模型的特点是以下三个点:1。在分布式环境下完成SSO [4],2.能够验证来自不同数据库的数据源完成SSO; 3.能够在身份验证后使用基于属性的验证以进行更准确的授权。这些使访问控制更灵活,更广泛的使用范围和更精细的控制粒度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号