位置:成果数据库 > 期刊 > 期刊详情页
一个可扩展企业应用系统安全模型的设计与实现
  • ISSN号:0469-5097
  • 期刊名称:《南京大学学报:自然科学版》
  • 时间:0
  • 分类:TP393[自动化与计算机技术—计算机应用技术;自动化与计算机技术—计算机科学与技术]
  • 作者机构:[1]东北大学研究院,沈阳110004, [2]沈阳东软集吲股份有限公司,沈阳110179
  • 相关基金:国家自然科学基金(60602061),“863”计划(2006AA01Z413)
中文摘要:

随着现代企业信息化的发展,企业的各种信息系统日益庞大和复杂,系统安全形势也日益严峻,企业应用系统的每个环节都有可能遭到安全威胁,应用系统需要保护众多的资源,对认证和授权以及资源的访问控制管理变得越来越困难.因此,为企业提供一套易使用的、易扩展和易管理的企业应用安全框架湿得十分重要.本文深入研究了基于J2EE(Java 2 Platform,Enterprise Edition)的企业应用系统的安全问题,以RBAC(Role-Based Aceess Control)访问控制模型、Acegi安全框架为基础,从多维度组织机构、认证系统和授权系统三个方面设计与实现了一种具有通用性和高度可扩展性的安全架构方案,能够满足不同企业个性化的安全需求.该方案能够降低企业信息系统安全管理的复杂度,增强系统的安全性.

英文摘要:

With the development of the modern enterprise information technology, various enterprise application systems are becoming more and more complex, and the security issues are also becoming more prominent. It is extremely necessary to provide a security system which is easy to use, easy to manage and easy to expand for the enterprise. In this paper, we give an in depth study to the security issues of the J2EE(Java 2 Platform, Enterprise Edition) based enterprise application systems. Based on the RBAC (Role-Based Access Control) access control model and Acegi security framework, we design a versatile and highly scalable security architecture program which can meet the individual security needs of the different enterprise. This thesis is based on RBAC Model, the Acegi Security Framework and the structure of the existing UniEAP (Universal Enterprise Application Platform) syslem which is a universal enterprise application platform developed hy Neusoft Group Ltd. This thesis begins with the security of J2EE enterprise application platform and discusses how to deal with overall information security problems through several views and several layers, and gives us an overall scheme based on security technology and method. The security framework is divided into three parts: muhidimension organization structure, authentication system and authorization system. The thesis gives us a concrete design and implement from the aspects. Because eyery enterprise has different requirements, the security framework is a basic framework that just resolved to commonly security problems. At the same time, the security framework is a highly extensible framework. The design solution, which is put forward here, can reduce the complexity of authority management and strengthen the systematic security. The design and implementation will be also useful to other enterprise application platforms and other enterprise applications.

同期刊论文项目
期刊论文 31 会议论文 11
同项目期刊论文
期刊信息
  • 《南京大学学报:自然科学版》
  • 中国科技核心期刊
  • 主管单位:中华人民共和国教育部
  • 主办单位:南京大学
  • 主编:龚昌德
  • 地址:南京汉口路22号南京大学(自然科学版)编辑部
  • 邮编:210093
  • 邮箱:xbnse@netra.nju.edu.cn
  • 电话:025-83592704
  • 国际标准刊号:ISSN:0469-5097
  • 国内统一刊号:ISSN:32-1169/N
  • 邮发代号:28-25
  • 获奖情况:
  • 中国自然科学核心期刊,中国期刊方阵“双效”期刊
  • 国内外数据库收录:
  • 美国化学文摘(网络版),美国数学评论(网络版),德国数学文摘,中国中国科技核心期刊,中国北大核心期刊(2004版),中国北大核心期刊(2008版),中国北大核心期刊(2011版),中国北大核心期刊(2014版),中国北大核心期刊(2000版)
  • 被引量:9316