The content security requirements of a radio frequency identification (RFID) based logistics-customs clearance service platform (LCCSP) are analysed in this paper. Then, both the unified identity authentication an...The content security requirements of a radio frequency identification (RFID) based logistics-customs clearance service platform (LCCSP) are analysed in this paper. Then, both the unified identity authentication and the access control modules are designed according to those analyses. Finally, the unified identity authentication and the access control on the business level are implemented separately. In the unified identity authentication module, based on an improved Kerberos-based authentication approach, a new control transfer method is proposed to solve the sharing problem of tickets among different servers of different departments. In the access control module, the functions of access controls are divided into different granularities to make the access control management more flexible. Moreover, the access control module has significant reference value for user management in similar systems.展开更多
针对上海电网各级调度监控系统和数据网络的安全防护,指出安全防护的重点在于:控制安全、信息安全和应用系统的安全。提出了安全防护分区原则和"胖区、瘦区"的分区方案。为适应网络安全分区和安全隔离的需要,在横向上,建立电...针对上海电网各级调度监控系统和数据网络的安全防护,指出安全防护的重点在于:控制安全、信息安全和应用系统的安全。提出了安全防护分区原则和"胖区、瘦区"的分区方案。为适应网络安全分区和安全隔离的需要,在横向上,建立电网调度自动化系统数据中心统一支撑平台;在纵向上,建设基于异步传输模式ATM的上海电力调度数据网SPDnet(State Power Dispatching Network)和基于多业务传输平台MSTP的电力数据通信网SPTnet(State Power Telecommunication Network),并分析了安全防护实施过程中应注意的事项。提出的防护方案体系结构清晰,有利于应用系统的整改,从而保证上海电网调度核心业务系统的安全稳定运行。展开更多
基金supported by Department of Science & Technology of Guangdong Province (No.2006A15006003)National High Technology Research and Development Program of China (863 Program)(No.2006AA04A120)
文摘The content security requirements of a radio frequency identification (RFID) based logistics-customs clearance service platform (LCCSP) are analysed in this paper. Then, both the unified identity authentication and the access control modules are designed according to those analyses. Finally, the unified identity authentication and the access control on the business level are implemented separately. In the unified identity authentication module, based on an improved Kerberos-based authentication approach, a new control transfer method is proposed to solve the sharing problem of tickets among different servers of different departments. In the access control module, the functions of access controls are divided into different granularities to make the access control management more flexible. Moreover, the access control module has significant reference value for user management in similar systems.
文摘针对上海电网各级调度监控系统和数据网络的安全防护,指出安全防护的重点在于:控制安全、信息安全和应用系统的安全。提出了安全防护分区原则和"胖区、瘦区"的分区方案。为适应网络安全分区和安全隔离的需要,在横向上,建立电网调度自动化系统数据中心统一支撑平台;在纵向上,建设基于异步传输模式ATM的上海电力调度数据网SPDnet(State Power Dispatching Network)和基于多业务传输平台MSTP的电力数据通信网SPTnet(State Power Telecommunication Network),并分析了安全防护实施过程中应注意的事项。提出的防护方案体系结构清晰,有利于应用系统的整改,从而保证上海电网调度核心业务系统的安全稳定运行。