Constructing a Highly Efficient Integrated Access Control Scheme for Web Services

碩士 === 大葉大學 === 資訊管理學系碩士在職專班 === 94 === Web services technology is an extreme efficient structure of information system for promoting enterprises to lower operating cost and raise profits. Nevertheless, with the pluralism of trading platforms, the security of transmitting message and how to execute...

Full description

Bibliographic Details
Main Authors: Mei-chih Hwang, 黃美治
Other Authors: Woei-Jiunn Tsaur
Format: Others
Language:zh-TW
Published: 2006
Online Access:http://ndltd.ncl.edu.tw/handle/67212327336953416621
id ndltd-TW-094DYU01396018
record_format oai_dc
spelling ndltd-TW-094DYU013960182015-12-18T04:03:45Z http://ndltd.ncl.edu.tw/handle/67212327336953416621 Constructing a Highly Efficient Integrated Access Control Scheme for Web Services 建構高效率之整合式網路服務存取控制機制 Mei-chih Hwang 黃美治 碩士 大葉大學 資訊管理學系碩士在職專班 94 Web services technology is an extreme efficient structure of information system for promoting enterprises to lower operating cost and raise profits. Nevertheless, with the pluralism of trading platforms, the security of transmitting message and how to execute the access control for information systems will become an important issue for securing the web service environment. Using certificate-based public key cryptosystems to solve the problems related to the demand of security under the current environment of web services causes rather complicated identity verifying and management. The methods of access control in operation can be divided into two kinds. One is that each user must register at different web sites, and therefore the system administrator will be busy in establishing the authority connection for these users; the other is at one specific web site, but every single site is connected with the others through the way of “loosely coupled”, but user may face the problem of different level of authority from a variety of web domains. For this reason, in the thesis the mechanism of integrated access control with high efficiency is constructed using the ECC-based self-certified public key cryptosystems and role-based access control scheme. The proposed mechanism can identify the user without employing certificates, and solve the limits of access authority across different web domains without any influence upon current system operations. Furthermore, after the comparisons with the current access control schemes for web services, we can find the proposed one will be superior to the others in terms of security and efficiency. We affirm that the proposed scheme will be able to lower the cost of maintenance and lighten the burden of system administrator, and thus promote the efficiency of access control to web services environments. Woei-Jiunn Tsaur 曹偉駿 2006 學位論文 ; thesis 98 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 大葉大學 === 資訊管理學系碩士在職專班 === 94 === Web services technology is an extreme efficient structure of information system for promoting enterprises to lower operating cost and raise profits. Nevertheless, with the pluralism of trading platforms, the security of transmitting message and how to execute the access control for information systems will become an important issue for securing the web service environment. Using certificate-based public key cryptosystems to solve the problems related to the demand of security under the current environment of web services causes rather complicated identity verifying and management. The methods of access control in operation can be divided into two kinds. One is that each user must register at different web sites, and therefore the system administrator will be busy in establishing the authority connection for these users; the other is at one specific web site, but every single site is connected with the others through the way of “loosely coupled”, but user may face the problem of different level of authority from a variety of web domains. For this reason, in the thesis the mechanism of integrated access control with high efficiency is constructed using the ECC-based self-certified public key cryptosystems and role-based access control scheme. The proposed mechanism can identify the user without employing certificates, and solve the limits of access authority across different web domains without any influence upon current system operations. Furthermore, after the comparisons with the current access control schemes for web services, we can find the proposed one will be superior to the others in terms of security and efficiency. We affirm that the proposed scheme will be able to lower the cost of maintenance and lighten the burden of system administrator, and thus promote the efficiency of access control to web services environments.
author2 Woei-Jiunn Tsaur
author_facet Woei-Jiunn Tsaur
Mei-chih Hwang
黃美治
author Mei-chih Hwang
黃美治
spellingShingle Mei-chih Hwang
黃美治
Constructing a Highly Efficient Integrated Access Control Scheme for Web Services
author_sort Mei-chih Hwang
title Constructing a Highly Efficient Integrated Access Control Scheme for Web Services
title_short Constructing a Highly Efficient Integrated Access Control Scheme for Web Services
title_full Constructing a Highly Efficient Integrated Access Control Scheme for Web Services
title_fullStr Constructing a Highly Efficient Integrated Access Control Scheme for Web Services
title_full_unstemmed Constructing a Highly Efficient Integrated Access Control Scheme for Web Services
title_sort constructing a highly efficient integrated access control scheme for web services
publishDate 2006
url http://ndltd.ncl.edu.tw/handle/67212327336953416621
work_keys_str_mv AT meichihhwang constructingahighlyefficientintegratedaccesscontrolschemeforwebservices
AT huángměizhì constructingahighlyefficientintegratedaccesscontrolschemeforwebservices
AT meichihhwang jiàngòugāoxiàolǜzhīzhěnghéshìwǎnglùfúwùcúnqǔkòngzhìjīzhì
AT huángměizhì jiàngòugāoxiàolǜzhīzhěnghéshìwǎnglùfúwùcúnqǔkòngzhìjīzhì
_version_ 1718153170339758080