首页> 外文OA文献 >SPKI/SDSI HTTP Server / Certificate Chain Discovery in SPKI/SDSI
【2h】

SPKI/SDSI HTTP Server / Certificate Chain Discovery in SPKI/SDSI

机译:spKI / sDsI中的spKI / sDsI HTTp服务器/证书链发现

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The issue of trust is of growing importance as our communities become increasingly interconnected. When resources are shared over an untrusted network, how are decisions on which principals are authorized to perform particular actions determined? SPKI/SDSI, a security infrastructure based on public-keys, is designed to facilitate the development of scalable, secure, distributed computing systems. It provides fine-grained access control, using a local name space hierarchy, and a simple, flexible, trust policy model; these features allow for the ability to create groups and delegate authorizations. Project Geronimo, named after the famous Native-American Apache chief, explores the viability of SPKI/SDSI by using it to provide access control over the Web. The infrastructure was integrated into the Netscape web client and Apache web server, using a previously developed SPKI/SDSI C Library. This thesis focuses on the server implementation. An SPKI/SDSI Apache module was designed and implemented: its principle functions are to protect web objects using SPKI/SDSI ACLs, and to determine whether HTTP client requests should be permitted to perform particular operations on protected objects. An administrative tool was developed to enable ACLs to be created, and updated, securely. The thesis also describes the algorithm for certificate chain discovery in SPKI/SDSI. Finally, the demonstration developed for Project Geronimo is outlined. The demo was successfully shown to our sponsors and various groups within the Laboratory for Computer Science.
机译:随着我们社区之间的相互联系越来越紧密,信任问题变得越来越重要。当在不受信任的网络上共享资源时,如何确定授权哪些主体执行特定操作的决定? SPKI / SDSI是基于公钥的安全基础结构,旨在促进可伸缩,安全,分布式计算系统的开发。它使用本地名称空间层次结构和简单,灵活的信任策略模型来提供细粒度的访问控制。这些功能允许创建组和委派授权。以著名的美国原住民Apache局长的名字命名的Geronimo项目通过使用SPKI / SDSI提供对Web的访问控制来探索SPKI / SDSI的可行性。使用以前开发的SPKI / SDSI C库将基础结构集成到Netscape Web客户端和Apache Web服务器中。本文着重于服务器的实现。设计并实现了SPKI / SDSI Apache模块:其主要功能是使用SPKI / SDSI ACL保护Web对象,并确定是否应允许HTTP客户端请求对受保护对象执行特定操作。开发了一种管理工具以使ACL可以安全地创建和更新。本文还描述了SPKI / SDSI中的证书链发现算法。最后,概述了为Geronimo项目开发的演示。该演示已成功展示给我们的赞助商和计算机科学实验室的各个小组。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号