Constructing a Highly Efficient Integrated Access Control Scheme for Web Services
碩士 === 大葉大學 === 資訊管理學系碩士在職專班 === 94 === Web services technology is an extreme efficient structure of information system for promoting enterprises to lower operating cost and raise profits. Nevertheless, with the pluralism of trading platforms, the security of transmitting message and how to execute...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2006
|
Online Access: | http://ndltd.ncl.edu.tw/handle/67212327336953416621 |
id |
ndltd-TW-094DYU01396018 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-094DYU013960182015-12-18T04:03:45Z http://ndltd.ncl.edu.tw/handle/67212327336953416621 Constructing a Highly Efficient Integrated Access Control Scheme for Web Services 建構高效率之整合式網路服務存取控制機制 Mei-chih Hwang 黃美治 碩士 大葉大學 資訊管理學系碩士在職專班 94 Web services technology is an extreme efficient structure of information system for promoting enterprises to lower operating cost and raise profits. Nevertheless, with the pluralism of trading platforms, the security of transmitting message and how to execute the access control for information systems will become an important issue for securing the web service environment. Using certificate-based public key cryptosystems to solve the problems related to the demand of security under the current environment of web services causes rather complicated identity verifying and management. The methods of access control in operation can be divided into two kinds. One is that each user must register at different web sites, and therefore the system administrator will be busy in establishing the authority connection for these users; the other is at one specific web site, but every single site is connected with the others through the way of “loosely coupled”, but user may face the problem of different level of authority from a variety of web domains. For this reason, in the thesis the mechanism of integrated access control with high efficiency is constructed using the ECC-based self-certified public key cryptosystems and role-based access control scheme. The proposed mechanism can identify the user without employing certificates, and solve the limits of access authority across different web domains without any influence upon current system operations. Furthermore, after the comparisons with the current access control schemes for web services, we can find the proposed one will be superior to the others in terms of security and efficiency. We affirm that the proposed scheme will be able to lower the cost of maintenance and lighten the burden of system administrator, and thus promote the efficiency of access control to web services environments. Woei-Jiunn Tsaur 曹偉駿 2006 學位論文 ; thesis 98 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 大葉大學 === 資訊管理學系碩士在職專班 === 94 === Web services technology is an extreme efficient structure of information system for promoting enterprises to lower operating cost and raise profits. Nevertheless, with the pluralism of trading platforms, the security of transmitting message and how to execute the access control for information systems will become an important issue for securing the web service environment.
Using certificate-based public key cryptosystems to solve the problems related to the demand of security under the current environment of web services causes rather complicated identity verifying and management. The methods of access control in operation can be divided into two kinds. One is that each user must register at different web sites, and therefore the system administrator will be busy in establishing the authority connection for these users; the other is at one specific web site, but every single site is connected with the others through the way of “loosely coupled”, but user may face the problem of different level of authority from a variety of web domains.
For this reason, in the thesis the mechanism of integrated access control with high efficiency is constructed using the ECC-based self-certified public key cryptosystems and role-based access control scheme. The proposed mechanism can identify the user without employing certificates, and solve the limits of access authority across different web domains without any influence upon current system operations. Furthermore, after the comparisons with the current access control schemes for web services, we can find the proposed one will be superior to the others in terms of security and efficiency. We affirm that the proposed scheme will be able to lower the cost of maintenance and lighten the burden of system administrator, and thus promote the efficiency of access control to web services environments.
|
author2 |
Woei-Jiunn Tsaur |
author_facet |
Woei-Jiunn Tsaur Mei-chih Hwang 黃美治 |
author |
Mei-chih Hwang 黃美治 |
spellingShingle |
Mei-chih Hwang 黃美治 Constructing a Highly Efficient Integrated Access Control Scheme for Web Services |
author_sort |
Mei-chih Hwang |
title |
Constructing a Highly Efficient Integrated Access Control Scheme for Web Services |
title_short |
Constructing a Highly Efficient Integrated Access Control Scheme for Web Services |
title_full |
Constructing a Highly Efficient Integrated Access Control Scheme for Web Services |
title_fullStr |
Constructing a Highly Efficient Integrated Access Control Scheme for Web Services |
title_full_unstemmed |
Constructing a Highly Efficient Integrated Access Control Scheme for Web Services |
title_sort |
constructing a highly efficient integrated access control scheme for web services |
publishDate |
2006 |
url |
http://ndltd.ncl.edu.tw/handle/67212327336953416621 |
work_keys_str_mv |
AT meichihhwang constructingahighlyefficientintegratedaccesscontrolschemeforwebservices AT huángměizhì constructingahighlyefficientintegratedaccesscontrolschemeforwebservices AT meichihhwang jiàngòugāoxiàolǜzhīzhěnghéshìwǎnglùfúwùcúnqǔkòngzhìjīzhì AT huángměizhì jiàngòugāoxiàolǜzhīzhěnghéshìwǎnglùfúwùcúnqǔkòngzhìjīzhì |
_version_ |
1718153170339758080 |