SaaS平臺數(shù)據(jù)安全問題的研究
[Abstract]:With the rapid development of the Internet and software industry, the information demand of enterprises is increasing, and the purchase and operation costs of software are increasing. SaaS emerges as the times require, and it provides software to customers through Internet. The SaaS model can reduce the operation cost, improve the management efficiency, and provide a new choice of high quality and low price for enterprise informatization. However, with the wide application of SaaS platform, security problems also follow. Because of the frequent data leakage events in recent years, it brings huge losses to enterprises, so when enterprises choose SaaS, the first consideration is whether the security can be guaranteed, which is also the main problem faced by SaaS operators. In this paper, the security problems of SaaS platform are introduced briefly, and the related technologies of data security, such as HTTPS,SSL, digital certificate, digital signature, etc., are briefly described. Then, the security problems of data transmission and data storage in SaaS platform are analyzed. For the problem of data transmission, this paper mainly analyzes the hidden security problems of HTTP transport protocol, and the problem of data isolation caused by SaaS multi-tenancy and the security problem of data plaintext storage for data storage. Based on the analysis and research of data transmission and storage in SaaS platform, the solution of data transmission security and storage security in SaaS platform is put forward. For the security of data transmission, the transmission scheme based on HTTPS is adopted, and SSL is used to ensure the security of data transmission. Then, the redirect scheme is used to realize HTTPS secure transmission. For the problem of data storage security, three kinds of data isolation schemes are analyzed firstly. Finally, a scheme of sharing database and shared architecture is selected, and a scheme of core field segmentation is put forward on the basis of this scheme. Then we choose the scheme of encrypting the outer layer of DBMS with field as encryption granularity. Based on MD5 and DES encryption technology, we encrypt sensitive data and save it in database with ciphertext, so as to ensure the security of data storage. Finally, the feasibility of the scheme is verified by an application example.
【學(xué)位授予單位】:西安電子科技大學(xué)
【學(xué)位級別】:碩士
【學(xué)位授予年份】:2014
【分類號】:TP309.2;TP393.09
【參考文獻(xiàn)】
相關(guān)期刊論文 前10條
1 秦曉霞;李文華;羅劍芬;;探討數(shù)據(jù)庫加密技術(shù)[J];電腦知識與技術(shù);2008年18期
2 溫靜;任鑠;;SaaS模式下的信息安全探討[J];電腦知識與技術(shù);2009年18期
3 劉國萍;劉建峰;譚國權(quán);;多租戶SaaS服務(wù)安全技術(shù)研究[J];電信科學(xué);2011年S1期
4 儲晨曦;王純;李煒;;基于LAMP架構(gòu)的Web權(quán)限控制組件的設(shè)計與實現(xiàn)[J];電信工程技術(shù)與標(biāo)準(zhǔn)化;2012年09期
5 任艷芳;;基于橢圓曲線密碼(ECC)的數(shù)字簽名技術(shù)[J];硅谷;2013年12期
6 胡華平,陳海濤,黃辰林,唐勇;入侵檢測系統(tǒng)研究現(xiàn)狀及發(fā)展趨勢[J];計算機(jī)工程與科學(xué);2001年02期
7 裴瑩;徐俊剛;;基于服務(wù)的企業(yè)標(biāo)準(zhǔn)化培訓(xùn)平臺[J];計算機(jī)應(yīng)用與軟件;2010年01期
8 謝億民;;互聯(lián)網(wǎng)和軟件融合成就SaaS[J];軟件世界;2006年15期
9 宋國江;;SaaS:信息安全新途徑[J];軟件世界;2007年15期
10 莫展宏;;國內(nèi)外SaaS模式的發(fā)展現(xiàn)狀分析[J];商場現(xiàn)代化;2012年07期
本文編號:2390554
本文鏈接:http://www.sikaile.net/guanlilunwen/ydhl/2390554.html