完整後設資料紀錄
DC 欄位語言
dc.contributor.author吳國禎en_US
dc.contributor.authorKou-Chen Wuen_US
dc.contributor.author黃景彰en_US
dc.contributor.authorJing-Jang Hwangen_US
dc.date.accessioned2014-12-12T02:20:37Z-
dc.date.available2014-12-12T02:20:37Z-
dc.date.issued1998en_US
dc.identifier.urihttp://140.113.39.130/cdrfb3/record/nctu/#NT870396025en_US
dc.identifier.urihttp://hdl.handle.net/11536/64252-
dc.description.abstract日常生活中我們都擁有一些證件,它們可以用來作為個人身分、經歷、參與活動,或是個人能力、資格的證明。在電腦網路的環境中,我們也可以用數位化的資料結構來模擬這些紙張型式的證件,並以這些數位化的證書來支援類似紙張證件所提供的身分識別以及授權管理服務。 本論文延伸ITU-T的X.509身分識別模型,以討論如何利用X.509數位證書來建立企業內部及企業之間的數位證書的應用。論文中以職務為基礎的執行權管制(Role-Based Access Control,簡稱RBAC)、以及電子資料交換來源方授權確認(Verification of Authorization at Source,簡稱VAS)為例,說明X.509證書在企業電子商務環境的應用。在第一個應用中以數位證書承載證書主體的職務指派資訊來輔助執行權管制,可以整合身分識別和執行權管制兩種安全服務,減少向集中式伺服器取得授權資訊的通訊需求。第二個應用則可以提供電子文件的收方確認文件所代表的交易內容是經過寄方合法授權,而且我們設計的查驗機制也和企業內部控制,以及企業間的電子資料交換系統做了完善的結合。這樣的討論,除了擴展數位證書的應用範疇,也可以說是把X.509標準的身分識別功能,提昇到了企業授權管理的層次。zh_TW
dc.description.abstractIn real life, paper-based credentials can prove individuals’ identities, experiences, participation in activities, capabilities or professions. In computer networks, identity authentication and authorization management are as important as they are in real world, thus digital credentials which mimic the paper counterparts should be provided to support these security services. In this dissertation, we extend the ITU-T recommended X.509 authentication framework to discuss the applications of X.509 certificates, specifically public-key certificates and attribute certificates, in business network environments. The presented applications include Role-Based Access Control (RBAC), and verification of electronic documents’ authorization at source. The first application of digital credential in RBAC can effectively streamline identity authentication and authorization validation. The second application can help assuring the received electronic document was legally created within the originating enterprise, and the proposed mechanism also integrates well with business internal control and EDI systems. Our work expands the application scope of digital credentials and raises the authentication function of the X.509 standard to the level of authorization management.en_US
dc.language.isozh_TWen_US
dc.subject數位證書zh_TW
dc.subject公開金鑰證書zh_TW
dc.subject屬性證書zh_TW
dc.subjectX.509標準zh_TW
dc.subject職務為基礎的執行權管制zh_TW
dc.subject電子資料交換zh_TW
dc.subjectdigital credentialsen_US
dc.subjectpublic-key certificatesen_US
dc.subjectattribute certificatesen_US
dc.subjectX.509 standarden_US
dc.subjectrole-based access control (RBAC)en_US
dc.subjectelectronic data interchange (EDI)en_US
dc.title數位證書在電子商務安全之應用zh_TW
dc.titleApplications of Digital Credentials in Security of Electronic Commerceen_US
dc.typeThesisen_US
dc.contributor.department資訊管理研究所zh_TW
顯示於類別:畢業論文