Journal of Jilin University(Information Science Ed ›› 2015, Vol. 33 ›› Issue (6): 700-.

Previous Articles     Next Articles

Research and Improvement of OpenStack‘s Authorization Mechanism

CHI Yaping1, WANG Huili1, YUAN Zhibo1, ZHANG Jian1, LI Xin1,2   

  1. 1. College of Communication Engineering, Beijing Institute of Electronic Technology, Beijing 100070, China;
    2. College of Communication Engineering, Xi蒺an University of Electronic Science and Technology, Xi蒺an 710071, China
  • Received:2015-04-24 Online:2015-11-27 Published:2016-01-04

Abstract:

Based on the analysis of the interactive process between the OpenStack’s platform structure, generating process, security mechanism and other service components, an improved ID authentication project is proposed to solve the deficiency of fine-grained authentication, low-usage of database and security flaw of data. This project integrates the LDAP(Lightweight Directory Access Protocol), RBAC(Role-Based Access Control), and SSL/ TLS(Secure Sockets Layer/ Transport Layer Security) into Keystone service, which strengthens the performance of Opentack‘s cloud platform in the aspect of the extension and security of ID management.

Key words: OpenStack, Keystone service, role-based access control(RBAC), lightweight directory access protocol(LDAP), authentication mechanism

CLC Number: 

  • TP39