文档介绍:华中科技大学
硕士学位论文
基于公钥基础设施的公文系统设计与实现
姓名:宋玮
申请学位级别:硕士
专业:软件工程
指导教师:胡雯蔷
20090522
摘要
长期以来,我国省级以下党政机关,包括市、州、直管市等党政机构大量通过
明文传真、明文电子邮件、未加密的短波无线信道和未加密的网络办公系统等手段
传递国家重要敏感信息,存在严重的安全隐患,引起了国家安全管理部门的高度重
视。采用密码技术对信息进行加密保护和安全认证,是保护信息安全的有效手段。
在黄山市进行电子政务建设的招标背景下,依托信安通公司资源,对课题进行了研
究,并成功的基于 Java 语言开发出 B/S 结构的基于公钥系统的安全公文交换系统。
通过对需求的细致分析及提炼,将系统整体划分成三个大的模块。首先是公文
流转模块,主要涉及到信息化办公软件的开发。其次是对基于 PKI 体系的加密体系
进行了研究。除了与安徽数字认证中心进行对接之外,还探索性的尝试了系统自带
公钥基础设施的简化实现工作,使得系统无需依赖第三方认证机构即可小规模的应
用。最后同时有鉴于几乎所有开发项目中均需重复编写“用户认证”及“权限模块”的开
发,系统中通过面向对象方式的组件封装,抽象出一套通用的、可移植的基础 RBAC
权限框架。
整个系统实现了完整的政务公文流转办公需求,采用目前较为先进的加密算法
模型和安全的物理链路保障,可以大大提高党政机关的信息交换安全性,并极大提
高部门之间的协作效率。另外本课题在实现简化的公钥基础设施上进行了探索性开
发,对类似应用领域有一定的参考价值。
关键词关键词:: :: 公文系统公钥基础设施加密传输权限模型
I
Abstract
Long period of time, following China's provincial-level party and ans,
including the city, state, city, etc. straight through a large number of government agencies
expressly fax, express mail, short-wave radio channel is not encrypted and unencrypted
networks such as office systems, an important means of transmission sensitive information,
there are serious security risks, arising from the national security management attention.
The use of cryptographic techniques for encryption of information security protection and
authentication, is to protect an effective means of information security. Huangshan City in
the conduct of electronic-government context of the tender, pany relies on a letter
Antong resources, conducted a study on the subject, and the ess of Java-based
development of B / S structure of the safety of the system based on public key exchange
system documents.
Through a detailed analysis of demand and refining, the overall system is divided into
three modules. First of all, document circulation module, mainly related to information-based
office software. Followed by the PKI-based encryption system of the system were studied. In
addition to the number of certified centers Anhui docking, bu