Font Size: a A A

Research Of Information Platform Security Based On WCF

Posted on:2011-12-28Degree:MasterType:Thesis
Country:ChinaCandidate:L JiFull Text:PDF
GTID:2178360305961307Subject:Computer application technology
Abstract/Summary:PDF Full Text Request
With rapid development of the computer technology, information technology is running aging day by day. It plays the important role of lowering its costs and increasing its and company staffs'efficiency. But information technology is faced an important problem--security. So, according to an information platform model based on WCF, this article gives a secure program based on.NET platform.Through research on information platform, the author findes two major problems on most information platform:security access and data transfer. The article puts the two points as research focus.In respect of user authorization, combining role-based and claim-based model, WCF's technical ascendancy and Security Token Service, this article brings forward a new authorization model---putting claimset into Security Token Service and sending it. Completing the authorization by sending claimset can simplify the whole authorization process and reduce codes writen by projectors, also, it simplifies the authorize access process.In respect of data transfer, the article uses popular SOAP security and SSL protocol. According different environment which information platform runs on, this article uses two different transport security by WCF security---Message Security Model and Mixed Security Model. Message Security Mode needs configure Host Certificate on the server side, configure Service Certificate on the client side, and set security mode to Message Security, Message Security Model widely applies to complex external network, avoiding security threats from intermediate network node in effect. Mixed Security Mode completes transport mainly through SSL protocol, configuring Service Certificate for creating a connection, then, associating Server and Certificate and completing binding, Mixed Security Model applies to intranet to achieve point to point security. WCF frame can provide flexibility under differnet conditions. WCF security can put both techniques into the whole business processing on information platform according specific security requirements. As WCF security technology can exist independently of business processing, every business can select own WCF security technology according personal situation,this is the reason why information platform select WCF.Information platform development based on WCF will be bound to a trend, but WCF is not a substitute for Web Service, it not only can do same work as Web Service, but also its action is embodied in the whole service processing on the information platform, and WCF plays an important part in cross-platform.
Keywords/Search Tags:information platform, security, WCF, Web Service
PDF Full Text Request
Related items