With the rapid development of information and network technology, the demand of the sharing of information between different enterprises and different government departments is getting more intense.At the request mentioned above, this paper researches and analyses the security challenges when sharing information between different operational systems, then designs and realizes a secure distributed information sharing system which have an authentication and authorization center. SOA framework based on Web Services, SAML token designed to exchange secure information for users and the role-based access control (RBAC) are used in this system.SAML is a based on XML development describable language that is to exchange secure information in Internet. It defines the exchange mechanism of secure information in different systems. According to the advantage of platform independent, loose coupling and opening, Web Services application... |