长春理工大学学报(自然科学版)
長春理工大學學報(自然科學版)
장춘리공대학학보(자연과학판)
Journal of Changchun University of Science and Technology
2015年
5期
112-115,119
,共5页
吴玉宁%王欢%苏伟%严晔%秦雪
吳玉寧%王歡%囌偉%嚴曄%秦雪
오옥저%왕환%소위%엄엽%진설
云计算%OpenStack%身份认证%安全性
雲計算%OpenStack%身份認證%安全性
운계산%OpenStack%신빈인증%안전성
cloud computing%OpenStack%identity authentication%safety
OpenStack是一个开源的云平台管理项目,旨在提供可靠的云部署方案和良好的可扩展性,但在重复失败登录、密码强度、密钥和数字证书管理等方面存在安全性问题.本文采用USB Key存储用户的密钥及数字证书,保证了双因子认证.采用基于角色的访问控制进行业务鉴权,同时设置反向认证令牌,实现用户和业务系统间的双向认证.利用PKI在Keystone进行密钥和数字证书颁发以及对数字证书的验证,增强认证的安全性.实现了OpenStack身份认证安全性的改进.方案已在校园网云存储平台上应用,为OpenStack安全性改进提供了参考.
OpenStack是一箇開源的雲平檯管理項目,旨在提供可靠的雲部署方案和良好的可擴展性,但在重複失敗登錄、密碼彊度、密鑰和數字證書管理等方麵存在安全性問題.本文採用USB Key存儲用戶的密鑰及數字證書,保證瞭雙因子認證.採用基于角色的訪問控製進行業務鑒權,同時設置反嚮認證令牌,實現用戶和業務繫統間的雙嚮認證.利用PKI在Keystone進行密鑰和數字證書頒髮以及對數字證書的驗證,增彊認證的安全性.實現瞭OpenStack身份認證安全性的改進.方案已在校園網雲存儲平檯上應用,為OpenStack安全性改進提供瞭參攷.
OpenStack시일개개원적운평태관리항목,지재제공가고적운부서방안화량호적가확전성,단재중복실패등록、밀마강도、밀약화수자증서관리등방면존재안전성문제.본문채용USB Key존저용호적밀약급수자증서,보증료쌍인자인증.채용기우각색적방문공제진행업무감권,동시설치반향인증령패,실현용호화업무계통간적쌍향인증.이용PKI재Keystone진행밀약화수자증서반발이급대수자증서적험증,증강인증적안전성.실현료OpenStack신빈인증안전성적개진.방안이재교완망운존저평태상응용,위OpenStack안전성개진제공료삼고.
OpenStack is an open source cloud platform management program,designed to provide reliable cloud deploy-ment and good scalability, but there are some security problems about repeat failed login, password strength, key and digital certificate management and so on. The paper uses the USB Key to store the user's key and digital certificate, which can guarantee the double factor authentication. The business authentication is based on the role of access control, while the reverse authentication token is set up to realize two-way authentication between users and business systems. Use the PKI in the Keystone to be responsible for the key and certificates and verification of digital certificates,which enhances the security of authentication. The improvement of the security of OpenStack identity authentication is realized. Finally, the security of the improved scheme is analyzed. The scheme has been applied to the campus network cloud storage platform,and it provides a reference for the improvement of OpenStack security.