北京邮电大学学报

  • EI核心期刊

北京邮电大学学报 ›› 2009, Vol. 32 ›› Issue (3): 104-108.doi: 10.13190/jbupt.200903.104.lixb

• 研究报告 • 上一篇    下一篇

PKI/PMI支持多模式应用的单点登录方案

李小标 温巧燕 代战锋   

  1. 北京邮电大学网络与交换技术国家重点实验室 北京邮电大学 北京邮电大学网络与交换国家重点实验室
  • 收稿日期:2008-11-13 修回日期:2009-01-31 出版日期:2009-06-28 发布日期:2009-06-28
  • 通讯作者: 李小标

A Supporting Multi-mode Application Single Sign-On Scheme Based on PKI/PMI

LI Xiao-biao   

  • Received:2008-11-13 Revised:2009-01-31 Online:2009-06-28 Published:2009-06-28
  • Contact: Xiaobiao Li

摘要:

提出了支持C/S和B/S应用的SSO单点登录方案。认证和授权基于PKI和PMI,服务端以中间件的方式实现认证、鉴权、审计功能,引进了SAML交换认证和鉴权信息;客户端则采用安全Cookie、共享内存与ticket技术实现多模式跨域的SSO解决方案。该方案具有更高的安全性,更为全面的解决多模式的单点登录问题,因而具有广泛的应用前景。

关键词: 单点登录, 多模式应用, 跨域认证

Abstract:

A single sign-on scheme is proposed supporting C/S applications and B/S applications. Authentication and authorization based on the PKI and PMI, the service is implemented by means of middleware to achieve the functions of authentication, authorization and auditing, and SAML to support the exchange of the authentication and authorization information; secure Cookies, shared memory and the technique of tickets are used in the client to achieve the multi-mode and cross-domain SSO solution. The scheme has a higher security, more comprehensive solution to the multi-mode SSO and therefore has a broad prospect.

Key words: single sign-on(SSO), multi-mode application, cross-domain authentication