|
With the rapid development of the construction of the power system, access to power enterprise information network systems gradually increased, data exchange and collaboration between the various systems are becoming increasingly frequent, constitute a typical multi-domain heterogeneous environment. Meet under the premise of open, interconnected, standardized, how to solve the electricity enterprise security integration of heterogeneous systems, and reliable operation of legitimate users across multiple security domains, has become a reality affect the power system safe and stable operation. In this regard, we proceed from the security requirements of the power system integration services, to study how the various open, advanced security technology standards into the information construction of the power system, the support platform based on Web Services Integration Services security solutions. Around the security platform, this article focuses secure communications, account management and identity synchronization, access control, unified identity authentication research and solve key implementation of each module is given. This work: (1) to discuss the power system integration services environment secure communication mechanisms, web services security on the C / S mode communication process discussed Web services security communication system, combined with the WS-Security functional model, designed and implemented the signature node in the process of secure communications, encryption node, node of decryption, signature verification logic node, through the cooperation of the node, to ensure the safety of the end-to-end communication in heterogeneous integration environment. (2) unified management of heterogeneous application systems integrated service environment, multi-user identity and account synchronization problem, based on the analysis of existing methods of user account management, combined with the SPML design a user identity management model; discuss the new user join created the problem, the user identity in a multi-application system; synchronous mode of secure identity, design Password Synchronizer class diagram, a detailed analysis of the normal and non-normal case identity synchronization process, and gives a core class key. (3) access control, analysis of the static reference model traditional access control technology, as well as the basic principles of the XACML access control, designed to meet the requirements of the electric power enterprise access control system, focusing on user access control, dynamic process model, as well as access control strategy, given the key access control model with the software demo. (4) for the realization of a unified identity authentication, analysis of the basic idea of ??the unified authentication service, the to combine SAML security standards, given the unified authentication service model, SAML security token generation and verification mechanism. Finally, the model instance analysis and programming demo, demonstration of the model to meet the future electricity system required to facilitate the integration and reuse of design and development principles.
|