节点文献

基于J2EE与OpenSSL的物流系统安全性研究及实现

Logistics System Research and Implement-Based on J2EE and OpenSSL

【作者】 田轶

【导师】 祝明德; 周晓光; 谷利泽;

【作者基本信息】 北京邮电大学 , 机械电子工程, 2008, 硕士

【摘要】 当前的物流行业发展十分迅速,我国的物流公司也在全社会的需求中得以壮大,随着人们对于物流行业的认可与期待,物流企业要进一步加强自身的业务能力,竞争力。这点在国内的中小公司中尤为重要,物流信息化,物流信息系统的采用已经成为现代物流行业的标志,然而有信息的地方,就会有信息安全问题,这里也不例外。物流信息安全的保障为维持物流业务正常工作的信息系统提出了更高的要求,简单的口令认证方式已不足以满足物流公司的需求,带有身份认证的系统成为开发使用的目标。然而这类软件大多由国外大型软件公司所开发,其功能往往过于庞大冗余,价格更是高企不下,本文就从这个角度出发,提出了基于开源技术的物流信息系统。为了实现在传统信息系统中引入PKI身份认证体系,本文首先论述PKI体系结构的基处密码学理论,讨论比较了现有加密机制。随后研究了数据安全传输的关键技术SSL通信协议。在对PKI公钥基础设施介绍后转而讨论研究了上述理论的实现技术:OpenSSL开源组件与信息系统的构成开发技术Java平台。随后对于物流信息系统分模块进行分析以及设计,其中重点在于其安全模块。并针对物流系统的特点,为系统引入USB E-KEY电子钥匙作为身份认证的关键,也是保存数字证书与用户私钥的载体。最后,根据前述分析给出信息系统的实现方法,以及安全身份认证的实现过程。

【Abstract】 With the rapid development of the world logistics industry and the demand of the whole world, Chinese logistics companies have progressed a lot recently. And the logistics corporation should improve there business management ability while people are asking for more service. Information system’s application is becoming the basic standard in the logistics industry; however, the information security problems have appeared.The logistics information security guarantee needs the normal logistics information system to do more, which is responsible for the daily business of the logistics service flow. The simple authentication which is using the old password is not capable for the modern logistic company’s demands. Information system with strict identity authentication function is becoming the new object whether in system development or software application. With the fact that such information system is always produced by huge foreign software companies and always prices high, the small companies need the system too but they can afford much less. This is the basic purpose of this paper which support a logistics information system with identity authentication function developed by open source techniques.This paper is focusing on the logistics information system which introduces the PKI hierarchy into the system. Cryptology theory is the basement of the PKI system and is the first preparation of the information system construction. After the comparison of the most popular encrypts arithmetic, we start to learn the key technique of the security data transmission: SSL protocol. The last part of the theory study is OpenSSL software and java technique which are the mainly part of the system development.The next part of the paper is the analyzing and structure design of the logistic information system. where information security is the most important part. At the end of this paper, we provide the implement of the logistics information system and the progress of the identity authentication.

【关键词】 物流系统信息安全PKI体系J2EEOpenSSL
【Key words】 Logistics SystemInformation SecurityPKIJ2EEOpenSSL
  • 【分类号】F252;TP311.52;TP309
  • 【被引频次】2
  • 【下载频次】252
节点文献中: 

本文链接的文献网络图示:

本文的引文网络