信息安全研究 ›› 2019, Vol. 5 ›› Issue (10): 892-897.

• 数字认证专辑 • 上一篇    下一篇

一种便捷式Web单点登录系统

明向阳1,龙毅宏1,刘旭2   

  1. 1. 武汉理工大学信息工程学院
    2. 北京天威诚信电子商务服务有限公司
  • 收稿日期:2019-10-08 出版日期:2019-10-15 发布日期:2019-10-08
  • 通讯作者: 明向阳
  • 作者简介:明向阳 硕士研究生,主要研究方向为信息安全技术原理及应用. 1569223603@qq.com 龙毅宏 教授、硕士生导师,主要研究方向为信息安全技术、嵌入式技术、自动控制技术以及计算机与网络通信技术等. .longyihong@sina.com 刘旭 硕士,主要研究方向为信息安全. liu_xu@itrus.com.cn

A Convenient Web Single Signon System

  • Received:2019-10-08 Online:2019-10-15 Published:2019-10-08

摘要: 单点登录由于给用户带来了方便,因此,获得了广泛的应用.但是传统的单点登录技术依旧存在一些问题,如无法应对企业发展中遗留的Web应用以及跨企业联合开发的Web应用,有些技术虽然可以解决这些问题,但是实现起来比较麻烦,或者会对访问的Web应用系统的性能造成显著影响.为此,提出并实现了一种便捷式单点登录系统,该系统以页面代码引导的方式将Web应用的登录请求提交到单点登录服务器,然后由服务端使用口令代填技术完成单点登录.所述单点登录技术实现简单,只需Web应用更改少量页面代码即可.

关键词: 单点登录, 便捷, 页面代码引导, 口令代填, 身份鉴别

Abstract: Single signon has gained a wide range of applications due to its convenience to users. However, the traditional single signon technology still has some problems, such as the inability to cope with the Web applications left over from the development of the enterprise and the Web applications jointly developed by the enterprise. Some technologies can solve these problems, but they are more cumbersome to implement or may be accessed. The performance of Web applications has a significant impact. To this end, this paper proposes and implements a portable single signon system, which submits the login request of the Web application to the single signon server in the form of page code guidance, and then the server uses the password substitution technology to complete the single point log in. The single signon technology is simple to implement, and only a Web application can change a small amount of page code.

Key words: single sign-on, convenient, page code guidance, password substitution, identification