以授权管理基础设施和公钥基础设施为基础,研究了单点访问系统的实现模型.这两种技术在单点访问系统中实现身份认证和访问授权控制功能.通过中间件的方式来实现身份认证和授权管理模型,并设计了相关的安全协议,对整个体系结构的安全做了简单分析.该技术可使现有应用做较少的修改就能实现一个安全、透明的单点访问系统.
SAS(Single Access System) is studied based on the PKI (Public Key Infrastructure) model and PMI (Privilege Management Infrastructure) model. The PKI and PMI can provide functions of authentication and authority in the SAS. The way to implement the authority and authentication using middleware as well as related secure protocol is discussed. The security of the system's architecture is also analyzed. These models enable a secure, transparent SAS with least modification to current applications.