首页 | 本学科首页   官方微博 | 高级检索  
     

OpenStack身份认证安全性分析与改进
引用本文:吴玉宁,王欢,苏伟,严晔,秦雪. OpenStack身份认证安全性分析与改进[J]. 长春理工大学学报(自然科学版), 2015, 0(5). DOI: 10.3969/j.issn.1672-9870.2015.05.025
作者姓名:吴玉宁  王欢  苏伟  严晔  秦雪
作者单位:1. 长春理工大学 计算机科学技术学院,长春,130022;2. 长春理工大学 计算机科学技术学院,长春 130022;长春理工大学 信息化中心,长春 130022
摘    要:Open Stack是一个开源的云平台管理项目,旨在提供可靠的云部署方案和良好的可扩展性,但在重复失败登录、密码强度、密钥和数字证书管理等方面存在安全性问题。本文采用USB Key存储用户的密钥及数字证书,保证了双因子认证。采用基于角色的访问控制进行业务鉴权,同时设置反向认证令牌,实现用户和业务系统间的双向认证。利用PKI在Keystone进行密钥和数字证书颁发以及对数字证书的验证,增强认证的安全性。实现了Open Stack身份认证安全性的改进。方案已在校园网云存储平台上应用,为Open Stack安全性改进提供了参考。

关 键 词:云计算  OpenStack  身份认证  安全性

Security Analysis and Improvement of OpenStack Identity Authentication
Abstract:OpenStack is an open source cloud platform management program,designed to provide reliable cloud deploy-ment and good scalability, but there are some security problems about repeat failed login, password strength, key and digital certificate management and so on. The paper uses the USB Key to store the user's key and digital certificate, which can guarantee the double factor authentication. The business authentication is based on the role of access control, while the reverse authentication token is set up to realize two-way authentication between users and business systems. Use the PKI in the Keystone to be responsible for the key and certificates and verification of digital certificates,which enhances the security of authentication. The improvement of the security of OpenStack identity authentication is realized. Finally, the security of the improved scheme is analyzed. The scheme has been applied to the campus network cloud storage platform,and it provides a reference for the improvement of OpenStack security.
Keywords:cloud computing  OpenStack  identity authentication  safety
本文献已被 CNKI 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号