摘要
本文提出了一个集中式的RFID公共服务体系架构,并结合X.509证书技术,使用PKI和PMI实现了安全的,完整的,不可否认的包括身份认证和权限控制在内的远程访问控制。为了适应RFID公共服务体系用户数量多,变化速度快的特点,以RBAC为基本理念,提出角色与权限分离的属性证书,与传统单一的属性证书相比,提高了访问速度,减少了更新频率。作为本文核心,以现有成熟的EPCglobal标准簇为基础,搭建了以集中式发现服务(DS)为主要手段的RFID公共服务体系,从不同类型的用户角度出发,结合实际业务流程,分析说明了该体系的运行情况和总体流程。
This paper proposed a centralized RFID Public Service Infrastructure. According to the X.509 Certificate Standards, a secure, integrated and no-denying remote access control model including user authentication and privilege authorization is presented. In order to fit with the huge amount of users and continual change, using both role attribute certificate and privilege attribute certificate refers to RBAC. Compared with the traditional single attribute certificate, separated roles and privileges make it access faster and update less. At a core, the RFID Public Service Infrastructure is implemented based on the EPCglobal standards and uses the Discovery Service as its main part. At different kinds of users' view, we discussed their main operational procedures, and the data collecting and registry procedure as well.
出处
《微计算机信息》
2009年第35期178-180,共3页
Control & Automation