透過您的圖書館登入
IP:18.222.69.152
  • 學位論文

電子資源的聯盟存取管理系統:Shibboleth在臺灣學術及高等教育界的應用探討

Federated Access Management for Electronic Resources:A Study of the Application of the Shibboleth System in Research and Higher Education in Taiwan

指導教授 : 張迺貞
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


目前國內的大學及學術機構對提供的保護性線上資源,如全文電子期刊、電子資料庫、電子書、數位教學資源及研究用數據資料庫等購買的或自建的電子資源,如何達方便存取與易於管理,似乎還沒有很好的對策。目前國內的做法為:1、在校園的IP範圍內使用,其出了校園便無法使用;2、使用IP限制,校園外則用proxy伺服器,此方法是有技術性的;3、使用虛擬私有網路連線 (Virtual Private Network),此種方法針對不同資源要分別登入; 4、使用共用的密碼 (‘Shared’passwords),此方法密碼容易外洩而威脅到資源的安全;5、針對不同資源,使用者分別註冊密碼,此方法使用者隱私容易外洩且恐有身份不實的問題。 為了改善上述的電子資源存取管理問題,英、美等國所發展的Shibboleth存取管理系統,已漸漸被很多已開發國家使用。Shibboleth是一個依據標準的開放源碼套裝軟體,以提供機關內或跨機關間的網頁單一登入(Web Single SignOn,簡稱SSO)及屬性交換的架構,容許網站對個人存取保護性線上資源時,使用單一及單位所控制的辨識法,並以保護隱私的方式作確認性的授權決定,讓使用者無接縫的去存取內部與外部的資源,以減少現行使用者在使用不同領域的多種資源時,必須局限在一個校園或要去維護多個密碼,並為身份提供者及服務提供者簡化了身份管理及存取許可。 本研究:1、參加澳洲測試聯盟(Meta Access Management System),並在中央研究院地球科學研究所建置身份管理系統,同時邀請Elsevier出版商為資源提供者,以實際測試聯盟的運作方式,並瞭解其在數位環境下的認證與授權機制及分析其效益;2、從英、美、澳洲及瑞士的聯盟網站去探討其聯盟的組織、所採用的技術與政策;3、以上述兩項為基礎規畫一個適合臺灣的聯盟存取管理系統。

並列摘要


ABSTRACT As of this writing, no academic institution or higher learning in Taiwan has a demonstrable solution for access management for the many diverse and usually proprietary electronic resources they provide for users. Such resources are generally known as full texts of electronic journals and books, electronic databases, e-learning resources, and autonomously established institutional databases among many others. At present, there are five methods to access electronic resources in Taiwan. The first uses a typical IP address. This method has its advantages; however, the restriction cannot meet the increasing need for off-campus access by users. Second, an IP address restriction using a proxy-server is available whereby with the help of an intermediate server. This method is unfortunately technically challenging for users. Third is a Virtual private network (VPN) method which has yet to be fully evaluated. Fourth, a set of shared usernames and passwords, this method is easily compromised and threatens the security of a resource host. Finally, there is separate individual registration for individual resources. Some users might not be willing to reveal their identities to the resource providers or identity theft could happen by this way. In order to solve the electronic access problems mentioned above, Shibboleth has been developed in U.S.A. and the U.K. and has become an emerging solution for access management of electronic resources in a growing number of developed countries. The Shibboleth system is a standard based, open source software package for web single sign-on across or within organizational boundaries. It allows sites to make informed authorization decisions for individual access of protected online resources in a privacy-preserving manner. In order to implement the Shibboleth system, this study joined a test-bed federation in Australia called MAMS (Meta Access Management System) and set up an identity provider in Academia Sinica. At the same time a publisher, Elsevier, was invited to join MAMS as a resource provider. By joining MAMS federation, and the deployment of an IdP, the author tries to understand how a federated system is operated and how the mechanism of authentication and authorization is used and to what effect as an evaluation of its efficiency and performance. The second important method of this study was to compare the organization structures, technologies and policies adopted by four federations: InCommon (USA), UK Federation, Australian Federation, and SWITCHaai (Switzerland). The practical implementation and the comparison lead to simulate a federation system model in Taiwan for future reference.

參考文獻


陳昭珍 (2000)。二十一世紀電子圖書館的發展趨勢。國家圖書館館刊,頁89。
de Vries, A. (Nov. 27, 2009). E-mail communication with Ale de Vries, Elsevier’s Senior Product Manager, Platform & content.
DAASI (2009). Authentication and authorization with Shibboleth. Retrieved Jan. 16, 2010, from HHUUhttp://www.daasi.de/info/shibboleth-e.htmlUU
JISC (2008). Sherpa. Retrieved June 21, 2008, from
McLean,N.(2000).Matching people and information resources: authentication, authorization and access management and experiences at Macquarie University, Sydney. Program, 34, 239-225.

延伸閱讀