首页 | 本学科首页   官方微博 | 高级检索  
     

柔性微服务安全访问控制框架
引用本文:刘一田,林亭君,刘士进.柔性微服务安全访问控制框架[J].计算机系统应用,2018,27(10):70-74.
作者姓名:刘一田  林亭君  刘士进
作者单位:南瑞集团(国网电力科学研究院)有限公司, 南京 211106,河海大学 能源与电气学院, 南京 210003,南瑞集团(国网电力科学研究院)有限公司, 南京 211106
基金项目:南瑞集团有限公司(国网电力科学研究院有限公司)科技项目“柔性微服务框架关键技术研究与应用”
摘    要:微服务架构实现了应用服务的业务解耦和技术栈分离,但更多的微服务也增加了进程间无状态服务调用频度,如何在保证服务性能的同时确保无状态服务之间的安全访问控制是微服务安全架构面临的关键问题.本文设计了一种柔性微服务安全访问控制框架,结合微服务API网关、轻量级微服务访问令牌构建方法以及柔性适配的微服务安全控制策略等特征,提高了微服务的柔性安全控制能力,经试验分析,代价更小,并在实际项目中验证了框架及方法的有效性.

关 键 词:微服务API网关  服务访问令牌  柔性安全访问控制策略
收稿时间:2018/2/26 0:00:00
修稿时间:2018/3/19 0:00:00

Flexible Microservice Security Access Control Framework
LIU Yi-Tian,LIN Ting-Jun and LIU Shi-Jin.Flexible Microservice Security Access Control Framework[J].Computer Systems& Applications,2018,27(10):70-74.
Authors:LIU Yi-Tian  LIN Ting-Jun and LIU Shi-Jin
Affiliation:NARI Group Corporation(State Grid Electric Power Research Institute), Nanjing 211106, China,College of Energy and Electrical Engineering, Hohai University, Nanjing 210003, China and NARI Group Corporation(State Grid Electric Power Research Institute), Nanjing 211106, China
Abstract:The microservice architecture facilitates the service decoupling of application services and the separation of the technology stack. However, more microservices also increase the frequency of stateless service invocation across processes. How to ensure secure service access control between stateless services while ensuring service performance is a key issue for the microservices security architecture. In this study, we design a flexible microservice security access control framework. Combining the features of microservice API gateway, the lightweight microservice token construction mechanism and the flexible adaptation of microservices security control strategy, we improve the flexible security control ability of microservice. After the experimental analysis, the cost is smaller, and the validity of the framework and the method is verified in the actual project.
Keywords:microservice API gateway  service access token  flexible safety access control strategy
点击此处可从《计算机系统应用》浏览原始摘要信息
点击此处可从《计算机系统应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号