透過您的圖書館登入
IP:216.73.216.100
  • 學位論文

一個可延伸之網頁重導式單一登入服務架構之設計研究

A Study on an Extensible Web-Based Redirect Model Single-Sign-On Service Architecture

指導教授 : 周清江

摘要


政府機關、大型企業及教育機構等中大型組織普遍都已將相關服務及作業推展至網際網路,在推動組織內所屬單位之既有網站導入單一登入機制時,時常因為各網站使用不同的技術及機制,修改原有技術及機制對系統衝擊太大,導致難以順利整合部份既有網站。現有單一登入之相關研究及實務大多是採單一介接方式之設計,在實務應用上有許多限制,必須透過建立多套單一登入系統以增加整合的範圍。本研究在原有以ASP.NET建立之「重導式單一登入」系統的基礎上,提出一個以識別提供者(IdP)端通信協定套件為基礎,設計與實作一個可延伸之網頁重導式單一登入服務架構,解決單一介接方式之限制,提供既有網站更多的介接方式,而且能依據既有網站之需要提供客製化的介接方式,讓既有網站有更多選擇與彈性,降低既有網站在單一登入介接時程式修改之幅度及難度,進而增加既有網站單一登入介接成功之機會。

並列摘要


Most Organizations, such as government agencies, large enterprises and educational institutions, have extended their services and operations to the internet. When they try to bring in Single-Sign-On architecture for legacy web sites of affiliated units, they tend to face complicated issues in modifying systems that were built by various types of technologies and mechanisms. Most of existing Single-Sign-On mechanisms support only one interface protocol. That has produced restrictions on their practice and applications. Systems must establish multiple sets of Single-Sign-On mechanisms to increase the scope of consolidation. This research, based on an already established Single-Sign-On mechanism constructed in the ASP.NET architecture, designs and implements a scalable web-based redirect-model Single-Sign-On architecture based on a multiple Identify Provider (IdP) protocol suite. The architecture makes it feasible to create a flexible environment that could reduce the magnitude of difficulties and increase the chances for legacy web sites to adopt Single-Sign-On mechanism.

參考文獻


[2]卓克羽,《以身份管理整合為基礎的單一登入入口網站架構設計》,碩士論文,淡江大學資訊工程學系碩士在職專班,2008。
[3]林志達,〈適用雲端運算之單一登入平臺架構〉,資訊安全通訊,第16卷,第4期, 頁173-179,ISSN:172906056,2010。
[4]林祐正,《一個可擴充的分散式單一簽入系統》,碩士論文,國立臺北科技大學資訊工程系研究所,2011。
[9]戴有煒,《Windows Server 2008 R2網路管理與架站》,第一版,臺北市:碁峰圖書出版,ISBN:978-986-1819-37-2,2010。
[16]James, S., “Web Single Sign-On Systems,” Computer Science Department, Washington University in St. Louis, 2007.

延伸閱讀