|
With the extensive application of information systems in the enterprise, all companies are set up their own enterprise portal applications, application integration, and integration of enterprise-class portal and enterprise application system, so as to facilitate the use of information systems. However, all of the different applications all have their own authentication method. Thus, users log in to each application system, these applications require the user authentication, the drawbacks of this approach is obvious. First, each application systems need to have their own certification database for storing user authentication information, users need to remember each application system user accounts, passwords and other authentication information. Secondly, the increase in the maintenance of the system administrator, and increased system overhead. To solve these problems, single sign-on technology came into being. Single sign-on system provides a unified authentication mechanism to enterprise applications and access to the entrance, and a unified management of user information, the user only has a set of accounts and passwords, can be realized in the portal to access all authorized applications. This will not only reduce the workload of the system administrator, and also reduces the overhead for repeated authentication. Navigational Maritime Administration of Yunnan Province business platform instance, the combination of a large and complex Navigational Maritime comprehensive business platform architecture based on business needs, single sign on system analysis and design. The goal is a Navigational Maritime comprehensive business platform in order to provide a unified user management and authentication interface, user management and user authentication services to be separated from the business systems, optimize Navigational Maritime comprehensive business platform architecture. Through single sign technology, this article uses a Java open source project of the Yale University CAS authentication model, defects and model analysis, improved model of CAS-based Web single login. Improved model Kerberos authentication mechanism, strengthen the security of the data transmission between the CAS server and user authentication database single sign-on process, and establish between the CAS servers, applications and the user's browser through SSL Secure Sockets Layer secure connection, thus further strengthening the security of bills of information transmission. In addition, this study, single sign on system in system implementation using J2EE development framework, and Web Work, Spring and Hibernate lightweight framework, the system is divided into the presentation layer, business logic and data persistence layer. reduce the coupling of the system, allowing the system to develop more reasonable.
|