针对现有安全策略的不足,提出一种新的应用于Web系统的安全策略——基于"信号量"的双重身份策略。在新策略的保护下,首先必须通过带验证码的身份认证,即使攻击者绕过口令认证等方式的第一道关口,基于"信号量"原理的第二次认证也会将攻击者阻止在Web系统之外。该策略是已有安全策略的有效补充,以不同以往的新途径提高了Web系统的安全性。
A new secure policy for web system is presented to supplement existed security policies: The two-factor authentication policy based on semaphore.Under the protection of the policy,authentication with verification code will be used.If hacker passed the first security door without password verification,he will be stopped out of the system.The new policy supplements existed secure policies,the security of the web system in a different way is improved.