检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]中南大学信息科学与工程学院,湖南长沙410075
出 处:《计算机应用与软件》2010年第8期289-291,共3页Computer Applications and Software
摘 要:自由联盟的单点登录协议解决了如何在网络联盟内部多个应用系统统一身份认证的问题。介绍自由联盟规范,分析自由联盟的单点登录(SSO)协议的流程步骤及其安全性,并在此基础上,针对基于安全断言标记语言(SAML)的SSO协议提出四种攻击方式,并指明了它们各自的危害。从而从攻击的角度,完成了对自由联盟的SSO协议的安全性分析。Single sign-on (SSO) protocol of the Liberty Alliance has resolved the uniform identity authentication problem of the internet with more than one application system inside the alliance. In the thesis we described the Liberty Alliance Standard, analyzed the process and the security of SSO protocol of the Liberty Alliance; on that basis, four attacks ways against Security Assertion Markup Language (SAML)- based SSO were pointed out, and the harms of each attack were expressed as well. Therefore, the security analysis on the Liberty Alliance' s SSO protocol was worked out in terms of the attacks.
关 键 词:自由联盟规范 单点登录 重放攻击 DNS欺骗 分布式拒绝服务 源IP地址欺骗
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:18.216.94.79