研究生(外文):Chien-tai Lin
論文名稱(外文):A Study of Role-based Access Control with Portable Key Management
指導教授(外文):Sue-Chen Hsueh
外文關鍵詞:Key ManagementRole-based Access ControlAccess ControlRole
企業電子化應用趨勢,讓員工隨時隨地可藉由網路存取公司資訊。然而,在網路的開放性架構下,企業內部資訊易遭受非法入侵與不當的擷取。因此,為企業制訂安全有效的資訊存取管理機制是重要的研究議題。Sandhu等提出以角色為基礎的存取控制(Role-based Access Control, RBAC),並廣泛應用於各種資訊系統中。本論文運用RBAC概念,以資訊系統存取的安全控管與金鑰管理機制為研究主題。
由於透過線上處理資訊,必須對資訊傳輸的安全有所防護,所以論文中除了探討權限之合理配置外,亦對資訊傳輸安全議題中金鑰管理機制的設計作了研究。目前對金鑰管理所採用的方式,多數是將金鑰儲存在磁片或智慧卡等媒體中由合法持有人自行保管,或是將金鑰存放在金鑰持有人的電腦設備中。這樣的金鑰管理模式可能因人為或儲存設備因素,而造成危害或產生不便。因此,以EKE(Encrypted Key Exchange)通訊協定作為基礎,設計具可攜性的安全金鑰管理機制。所設計的金鑰傳輸方法,採將私密金鑰存放於遠端伺服器的方式,持有人透過所設計的安全傳輸機制來下載由伺服器統籌保管維護的金鑰。這樣的機制,不但能提供具可攜性及可追蹤性的線上下載機制,亦簡化金鑰交換通訊協定的反覆檢驗程序,降低遺失遭竊的風險。
Enterprises nowadays allow employers to access corporate information via Internet so that tasks can be done without being limited by office hours. Such an advantage could be cancelled out because, on public networks like Internet, the internal information is vulnerable to be improperly accessed. Thus, the provision of a secure and effective access control scheme, such as Role-based Access Control (RBAC), becomes a very critical issue. Guided by the principle of RBAC, this thesis aims to provide secure and controlled access, and effective key management of corporate information systems.
RBAC uses roles to bridge users and permission. Permission to access certain resources is authorized only to the user who is associated with certain role. RBAC is multi-faceted with characteristics like user-role/permission-role assignments, role hierarchy, separation of duties, least privilege, data abstraction, and so on. In this thesis, we propose a framework of RBAC information system that effectively control the access by using certificates and role-keys. Therefore, illegal use or unauthorized access due to revelation of passwords in the login-based systems can be avoided.
In addition to the authority administration, we also investigate the key management issue, the essential element used for security protection in online information processing. Usually, the private keys are stored in diskettes or smart cards that are held by the legal owners, or in the key-holders’ computers. However, the easy management might suffer from lost of keys and damage of storage devices. Hence, based on the Encrypt Key Exchange protocol, we propose a portable and secure key management mechanism. The password-encrypted private keys are stored in a remote server. The owner may download the protected keys from the server through the secure communication channel. The proposed method not only provides a portable and traceable downloading mechanism, but also simplifies the repeated checking process in key exchange protocols.
