首页> 外文OA文献 >System for Cross-domain Identity Management palveluiden pääsynhallintaan palvelupohjaisessa arkkitehtuurissa
【2h】

System for Cross-domain Identity Management palveluiden pääsynhallintaan palvelupohjaisessa arkkitehtuurissa

机译:用于基于服务的体系结构中的跨域身份管理服务访问管理的系统

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。
获取外文期刊封面目录资料

摘要

Identity and Access Management systems are usually fundamental services in organizations. In Service-Oriented Architecture (SOA) they can be used to provide three different services: authentication, authorization and information about users and their access rights. For the latter, there has not been a widely used standard in SOA to provide user information to other services. System for Cross-domain Identity Management (SCIM) is a new emerging Representational state transfer (REST) based standard to help provision user information to cloud services.This Master Thesis discusses how SCIM can be used to provide user information to consuming services in a SOA based solution. The first part of the thesis studies what are the advantages and disadvantages using REST based solutions compared to SOAP based solutions. Based on a literary review, REST has better performance, measured by throughout put, and it is independent of data format. SOAP has the advantage of being very standardized and has mature tools and frameworks compared to REST. REST is more based on conventions than standards, so tools and frameworks behave differently which might lead to interoperability problems.The second part of the thesis focuses on whether SCIM can be used to provide user information service to consuming services. Three scenarios were designed and implemented in SCIM to find out whether the access right model of the SCIM is expressive enough and whether the resources defined by SCIM provide a required set of attributes. The presented scenarios have different requirements: the first one models internal access rights of an organization, the second scenario a use case in which an organization offers services to its customers and the third one a use case in which role based access rights are restricted to certain objects. The last two scenarios required extending the SCIM core resource schema.The models were tested in a proof-of-concept implementation and they were able to fulfill all the requirements. This indicates that SCIM can be used to implement user and user’s access right information service. To conclude, a five step process is presented that an organization can use to assess if SCIM is suitable for its use.
机译:身份和访问管理系统通常是组织中的基本服务。在面向服务的体系结构(SOA)中,它们可用于提供三种不同的服务:身份验证,授权以及有关用户及其访问权限的信息。对于后者,SOA中没有广泛使用的标准来向其他服务提供用户信息。跨域身份管理系统(SCIM)是一种新出现的基于表示状态转移(REST)的标准,旨在帮助向云服务提供用户信息。本硕士论文讨论了如何使用SCIM向SOA中的消费服务提供用户信息。基于解决方案。论文的第一部分研究了与基于SOAP的解决方案相比,使用基于REST的解决方案的优缺点。根据文学评论,REST的性能更好(按整个结果衡量),并且与数据格式无关。与REST相比,SOAP具有非常标准化的优势,并且具有成熟的工具和框架。 REST更多地基于约定而不是标准,因此工具和框架的行为方式不同,可能会导致互操作性问题。本文的第二部分着重探讨了SCIM是否可用于向消费服务提供用户信息服务。在SCIM中设计并实现了三种方案,以查明SCIM的访问权限模型是否足够表达,以及SCIM定义的资源是否提供所需的属性集。所呈现的场景具有不同的要求:第一个场景为组织的内部访问权限建模,第二个场景为组织向其客户提供服务的用例,第三个场景为基于角色的访问权限仅限于某些情况的用例对象。最后两个场景需要扩展SCIM核心资源架构,这些模型在概念验证的实现中进行了测试,并且能够满足所有要求。这表明SCIM可用于实施用户和用户的访问权限信息服务。总之,提出了一个五步过程,组织可以使用它来评估SCIM是否适合其使用。

著录项

  • 作者

    Korkeala Markku;

  • 作者单位
  • 年度 2016
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号