标题: 应用智慧卡实现RBAC执行权管制
Using Smart Cards for Implementing
作者: 郭素馨
KER SOR KHENG
黄景彰
Jing-Jang Hwang
资讯管理研究所
关键字: 智慧卡;执行权管制;Windows 2000;Smart Card;Role-Based Access Control;RBAC;Windows 2000
公开日期: 1999
摘要: 本论文的主要目标是为了提供一个较安全的凭证储存及存取管制媒介,希望籍由智慧卡的高安全性能来提升整个以职务为基础的执行权管制环境(Role-Based Access Control,简称RBAC)的安全性,加强前端的使用者身份鉴别,进而维护后端的执行权管制。
为了加强使用者身份鉴别,本论文利用ITU-T X.509公开金钥凭证的观念来做为使用者身份鉴别机制的依据。并藉由智慧卡的高安全存取控制功能,将“员工电子识别证书”和“员工电子职务证书”储存于智慧卡中,以加强这两种证书的存取控制。
本论文将从“员工电子识别证书获得程序”、“员工电子职务证书获得程序”二方面来说明将智慧卡应用于RBAC环境的设计理念,实地了解如何应用智慧卡来加强RBAC环境的使用者身份鉴别。紧结着,论文中也将进一步探讨如何于Windows 2000系统架构中加入智慧卡及RBAC的执行权管制政策,以达到高安全性能的执行权管制环境。最后,本论文也以请假流程为例说明如何经由存取储存于智慧卡内的“员工电子识别证书”及“员工电子职务证书”来达成以职务为基础的执行权管制。
The objective of this thesis is to design a vehicle for conveying authentication and access control information. Smart cards are the vehicle that stores credentials of their owners in the format defined in the X.509 certificate.
Two types of certificates are defined. One is used to store individual information for the authentication purpose; the other is used to convey role assignments. The author designs procedures for the enrollment of these certificates and then implements these procedures in the platform of Windows 2000.
Finally, a case study is conducted, showing how the certificates are used in a process of requesting for leave in organizations.
URI: http://140.113.39.130/cdrfb3/record/nctu/#NT880396018
http://hdl.handle.net/11536/65598
显示于类别:Thesis