|
With the wide application of information system in the enterprise, all enterprises are established enterprise portal application of their own, and the applications of inner enterprise application integration and the integration of the enterprise portal, in order to facilitate the information system. However, all the different application systems have a identity authentication methods in their respective. In this way, the user login in each application system, these systems need to authenticate the user, obviously the drawbacks of this approach. Each application systems need to have their own authentication database, for storing user authentication information, resulting in users need to remember each application system user account, password authentication information, and increases the cost of the system. In order to solve these problems, emerge as the times require single sign on technology. Single sign on system provides the enterprise a unified identity authentication mechanism and access entrance, and a unified management of user information, the user only has a set of account and password, it is possible to access all the authorized applications. This not only reduces the workload of system administrator, also reduced the system for overhead caused by repeated authentication. In this paper, a comprehensive business maritime administration of Yunnan province platform for example, combined with the structure of shipping and maritime integrated service platform Pang Dahe complex, according to the needs of the business, to the single sign on system analysis and design, the purpose is to provide a unified user management and authentication interface for shipping and Maritime integrated service platform, service identity certification user management and user separated from the business system, system structure optimization and maritime integrated service platform. Through the study of the single sign on technology, this paper uses SAML and CAS combination model, and the model for the defects were analyzed, to strengthen the security of the data transmission between the CAS server and the user in the process of single sign on authentication database, the information encapsulation, secure connection between CAS server, application system and user browser through SSL secure sockets layer establishes, so as to further strengthen security bill information transmission. In addition, the single sign on system in the system implementation, using J2EE development framework, combined with WebWork, Spring and Hibernate lightweight framework, the system is divided into presentation layer, business logic layer and data persistence layer three layer, reduce the coupling system, make the system development more reasonable.
|