研究生(外文):Chiu, Chuan-Rou
論文名稱(外文):Research on Cloud Web-Based Single Sign-On Identity Authorization
指導教授(外文):Yang, Cheng-Ying
外文關鍵詞:CloudSingle Sign-OnFacebookGoogleOAuthOIDCSSL/TLSSAMLRBACMFA
鑒於雲端運算及社群網路是未來趨勢,整合社群網路臉書及谷歌帳號與微軟雲端目錄服務,可讓企業內外使用者透過社群網路及混合雲目錄帳號登入網站,統合Open Authorization (OAuth) 2.0與OpenID Connect (OIDC) 驗證授權通訊協定、Security Assertion Markup Language (SAML) 2.0驗證通訊協定、Secure Sockets Layer/Transport Layer Security (SSL/TLS)安全通道、角色型存取控制及多因素驗證等身份授權要素,可增加雲端網站其資訊安全的可用性、完整性與機密性。
For the coming era of high-speed networking, there are many enterprises promoting their competitive ability with cloud computing. In the clouding computing, there are a lot of applications including email service, storage, searching engines and social activities. Google provides a search engine service and other services in the net. On the other hand, Facebook website is a famous one in the social networking. Both Google and Facebook have over billions users within the networking. In order to give a convenience to those users to use the enterprising websites, Single Sign-On scheme is proposed for this purpose.
Within the cloud computing, integrating social network account and Microsoft Azure Active Directory (AD) to be a unit, Single Sign-On scheme allows the specific users to login to both sites without a different account. With Open Authorization(OAuth) 2.0 & OpenID Connect(OIDC), Security Assertion Markup Language(SAML) 2.0, Secure Sockets Layer/Transport Layer Security (SSL/TLS) protocols, the secure connection could be built between the enterprise website and the user. Users could be authenticated with Role-Based Access Control(RBAC) and Multi-Factor Authentication(MFA) schemes. With these secure schemes, the security including Availability, Integrity and Confidentiality could be promoted to make sure to meet the information security requirements.
In this thesis, the work concentrates on the object to create a platform for the enterprise to provide the user with a single sign-on environment. This work includes integrate Microsoft Azure AD, accounts with Google and Facebook websites and AD in the enterprise to be a unit for Single Sign-On. To increase the security, the work sets up the access control authentication with RBAC and MFA schemes. Finally, this work gives some commends to the companies which desire to create a Single Sign-on in the cloud computing.
