标题: 建立于公开金钥基础建设的单一签入系统
A Single Sign-On Scheme Based on Public-Key Infrastructure
作者: 朱建达
Chien-Ta Chu
曾文贵
Wen-Guey Tzeng
资讯科学与工程研究所
关键字: 单一签入;公开金钥基础建设;Kerberos;SESAME;Single Sign-On;PKI
公开日期: 2000
摘要: 在分散式作业环境中, 所有的资讯均曝露在公开的网路上, 这些资讯可能是一
些交易过程或者是使用者的密码. 此外, 通讯双方的身份也有遭到伪装的隐忧. 为了
解决这方面的问题, Kerberos 认证服务与 SESAME 认证服务等系统均致力于相关方面的研
究.
在一个异质性系统环境中, 所有主机的系统类型和登入方式不尽相同. 使用者要登入
不同的主机, 必须使用不同组的帐号密码. 在每一次输入重要资讯的过程中, 这些资讯很有
可能遭到截取而泄漏出去. ``单一签入''这个解决方案就是要减少登入程序的繁琐.
在本论文中, 我们研究一些重要的认证服务, 并且提出一个类似的系统, 整合了公开金钥
基础建设与单一签入, 让使用者以智慧卡登入系统, 当使用不同的服务时, 不需要再重新输入
帐号密码; 而系统采用``角色为主存取控制''来管理权限, 使得权限在管理上更有弹性.
In a distributed environment, all information are exposed in the public
networks. Some of the information are perhaps transactions and some are users'
passwords. Besides, the identities of communicating parties are also under the
danger of being masqueraded. A lot of research, such as Kerberos and SESAME,
have been devoted to solve these problems.
In a heterogeneous environment, all computer hosts are not the same machine
type and all login procedures are not the same. When a user is going to login into
different computers, he has to use different pairs of identity and password.
During the procedure of login, these information might be intercepted resulting
in a leakage. ``Single Sign-On'' is the solution to reduce the complexity of
the login procedure.
In this paper, we not only investigated two representative authentication
services but also proposed a similar scheme, which is integrated with PKI and Single
Sign-On. Our scheme works as following: the user logins once using a Smart Card
and uses different services without entering password again. We adopt ``Role-Based
Access Control'' to manage privilege, and that results more flexibility in management.
URI: http://140.113.39.130/cdrfb3/record/nctu/#NT890394093
http://hdl.handle.net/11536/66998
显示于类别:Thesis