Full metadata record
DC FieldValueLanguage
dc.contributor.author張長蓉en_US
dc.contributor.authorChang-Jung Changen_US
dc.contributor.author葉義雄en_US
dc.contributor.authorYi-Shiung Yehen_US
dc.date.accessioned2014-12-12T03:09:45Z-
dc.date.available2014-12-12T03:09:45Z-
dc.date.issued2006en_US
dc.identifier.urihttp://140.113.39.130/cdrfb3/record/nctu/#GT009455519en_US
dc.identifier.urihttp://hdl.handle.net/11536/82044-
dc.description.abstractWeb service的出現是為了讓使用者能夠迅速及時使用網路資源,它使用XML來傳輸資訊以適應各種開發環境。隨著電子商務的興起,為了解決資訊安全的問題,OASIS在2002年發展了一種以XML為基礎的語言SAML,可安全產生和交換使用者認證和授權資訊。SAML明確地定義了許多安全認證方式並以XML架構來加強之,這樣的優勢令許多網路廠商廣泛使用它來達到Web SSO的功能。 以目前SAML提供的SSO (Single Sign-On) 機制,是透過一個認證中心來管理使用者資訊,這個認證中心整合各種服務,使用者必須先到認證中心確認身分後,才能使用這些服務,只要在認證中心登入過一次,底下所屬的服務都無須再做登入動作即可使用。但若想使用不同IDP (identity provider) 底下的服務時,仍然要做多次登入動作認證身分。 為了提供使用者一個跨企業間的整合性服務,我們必須讓使用者在不同的認證中心底下仍可達到單一登入的功能,因此本論文以SAML1.1為基礎,提供了一種可跨IDP做聯合身分認證以達到SSO的系統。zh_TW
dc.description.abstractThe development of Web Service enables users rapidly to access network resources in time. As a result of the electronic commerce starting, Web service uses xml to transmit the information to be able to adapt each kind of development environment. In order to solve the information secure problem, the Security Assertion Markup Language (SAML) which is an XML-based framework has been developed by the OASIS (the Organization for the Advancement of Structured Information Standards) to describe and exchange authorization and authentication information between on-line business partners in 2002. SAML explicitly defines several safe confirmations ways and the security of xml architecture will be enhanced with these methods. The superiority causes SAML widely to be used to achieve Web SSO by the on-line commercial systems. At present SAML SSO mechanism is that there is an identity provider (IDP) which integrates several services managing users information. After logging in at IDP, the user can access these services. So long as a user has logged in at the authentication center, he does not need to authenticate again and then he directly can access these services at the same time. But a user has to login many times to provide valid credentials to use the services which are subordinate under different IDPs. In order to provide the users a enterprise-crossed and integrated service, we must enable the users also to achieve SSO under many identity providers, the thesis designs a SSO architecture to achieve identity federation cross-IDP using SAML 1.1.en_US
dc.language.isoen_USen_US
dc.subjectWeb 服務zh_TW
dc.subject安全宣示標記語言zh_TW
dc.subject單一登入系統SSOzh_TW
dc.subject聯合身分認證zh_TW
dc.subjectWeb Servicesen_US
dc.subjectSAMLen_US
dc.subjectSSOen_US
dc.subjectFederated Identityen_US
dc.subjectIdentity federationen_US
dc.title基於SAML架構達到多層式跨IDP之單一登入系統zh_TW
dc.titleMulti-Layered Cross-IDP SSO in SAML-based Architectureen_US
dc.typeThesisen_US
dc.contributor.department資訊科學與工程研究所zh_TW
Appears in Collections:Thesis


Files in This Item:

  1. 551901.pdf

If it is a zip file, please download the file and unzip it, then open index.html in a browser to view the full text content.