隨著企業或政府機關資訊化的趨勢,資訊系統日益增加。對於企業內部的許多資訊系統而言,由於系統建置的時間與平台不盡相同,因此每個資訊系統各自擁有認證授權模組與帳號角色資料庫。對於使用者而言,必須個別登入每個系統,方可使用該系統之功能。此外,若使用者於各個系統內之帳號或密碼不同,則需記憶多組帳號與密碼。上述兩點會造成使用者之不便。從系統管理層面而言,每個系統的授權規則皆儲存於各自的資料庫中,系統管理者必須各自維護每個系統之授權規則,其中包括:使用者-角色、角色-資源的對映關係。因此,分散於各系統的認證模組、授權模組、帳戶資料庫,將對使用者與管理者造成諸多不便。 本論文擬透過目錄整合與單一簽入之技術解決上述問題。運用目錄整合技術,將多個既有系統之帳號與群組資料整合至單一目錄服務資料庫。透過帳號對映與單一簽入之機制,使用者只需記憶一組帳號與密碼,即可存取後端各個資訊系統。本論文所建構之單一簽入系統,代替後端所有資訊系統進行認證、授權之作業,且管理者可針對所有授權規則進行集中式管理。綜上所述,本論文之重點包括:既有系統帳號與角色資料之整合作業、授權規則整合、單一簽入系統與後端資訊系統之系統整合。最後本論文將以兩個既有系統(網路服務營運中心、線上閱讀測驗系統)為例,實作帳號整合、授權規則整合、與單一簽入機制。
In recent years there are more and more information systems with a tendency of information technology in enterprises or governments. There are authentication modules, authorization modules, and user registries for accounts and roles in these information systems. Everybody should login every system to use it. In addition, you should memorize many pairs of account and password if you have various accounts in many systems. These key points are inconvenient for users. There are some authorization rules in every system, such as user-to-role and role-to-resource. The administrator must maintain these rules one by one in every system. So, these distributed authentication modules, authorization modules, and user registries are inconvenient for users and administrators. This research proposes a solution for the problems above by directory integration technology and single sign-on technology. We can integrate the accounts and roles into a directory server using directory integration technology. Every user can memorize an only account and password to access every system in the single sign-on mechanism. Authentication and authorization will be processed in the single sign-on system in this research. And the administrator can manage the rules of authorization in all backend systems. In short, the key points of this research are integration of accounts and roles, integration of access control, integration between the single sign-on system and backend systems. Finally, we will integration the accounts and the rules of authorization of two legacy systems and implement single sign-on mechamism.