欢迎来到天天文库
浏览记录
ID:39889547
大小:579.00 KB
页数:43页
时间:2019-07-14
《WS-Federation》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、WS-FederationJimVanDykeZhengpingWuPartiallyadaptedfromworkshopslidesbyTonyNadalin(IBM)andChrisKaler(Microsoft)AgendaIntroductionTrustTopologiesSingleSign-outAttributeServicesPseudonymServicesActive/PassiveProfilesSummaryandConclusionsDemoReferences2WhatisFederation?Fede
2、rationAcollectionofrealms/domainsthathaveestablishedtrustThetechnologyandbusinessarrangementsnecessarytointerconnectusers,applications,andsystemsFederatedsystemscaninteroperateacrossorganizationalandtechnicalboundaries(i.e.,variousoperatingsystemsorsecurityplatforms)3Fe
3、deratedATMNetworkAccountNumberandPINHomeBankNetworkVisitingBankNetworkFundsNetworkofTrust4WS-FederationPrimaryGoal:“SingleSign-On”accessacrosstrustdomainsusingidentitiesfromthedifferentdomainsWS-FederationdefinesamodelforthisbybuildingontheWS-*securityspecifications:Bro
4、keringtrustSignoutmessagesAttributeservicePseudonymservice5WS-FederationTermsAuthoritiesSecurityTokenService(STS)–Webservicethatissuessecuritytokens;makesassertionsbasedonevidencethatittruststowhoevertrustsitIdentityProvider(IP)–Entitythatactsasanauthenticationserviceto
5、endrequestors(anextensionofabasicSTS)PrinciplesRequestorResourceOtherServices6OneProtocol,MultipleBindingsCommonprotocol(WS-Trust)Two“profiles”ofthemodelaredefinedSmart/Activeclients(SOAP)Passiveclients(Browser–HTTP/S)Supportingservices(attribute/pseudonym/…)SecurityTok
6、enServiceHTTPReceiverHTTPmessagesSOAPmessagesSOAPReceiver7TrustTopologiesFederationapproachmustaddressdifferenttrusttopologiesModelexistingbusinesspracticesLeverageexistinginfrastructureSampletopologiesDirecttrustExchangeValidationIndirecttrustDelegation8DirectTrustTok
7、enExchangeTrustGetidentitytokenGetaccesstoken132IP/STSIP/STSRequestorResource9DirectTrustFlowRequestorServiceRequestorIP/STSWSServiceServiceIP/STSRequesttokenReturntokenRequesttokenReturntokenSendsecuredrequestReturnresultAcquirepolicyReturnpolicy10DirectTrustTokenVali
8、dationTrustGetidentitytokenGetaccessverification123IP/STSIP/STSRequestorResource11IndirectTrustTrustTrustCtru
此文档下载收益归作者所有
点击更多查看相关文章~~