Glory

星期二, 八月 29, 2006

Web Request Process in Windows Server

When a request arrived at a web server, http.sys, which work in kernal level, would firstly process the request format, such as number of URL's segements(255 by default) and how many bytes contained in each segments(260 by default).


to be continued...

星期六, 八月 26, 2006

About Wangxuan

Wangxuan, the most famous computer scientist in China, was an academician of Chinese Academy of Sciences, Chinese Academy of Engineering and Third World Academy of Sciences. He died on 13th, February, 2006, when he was 70 years old. Though he was dead, the treasure he created will do good to all Chinese people as well as everyone in the world.
Wangxuan was famous for his Laser Zhaopai for Chinese characters, invented in 1985, which has greatly improved publishing technology in China.
As we know, the first computer was ‘born’ in USA and the development of computer science was led by Americans, so English is its mother language. So it is much more easy to deal with English for computer than other languages, especially Chinese. And it is convenient and efficient to work with the help of computers and since the invention of computer it has played an important role in people’s life. It can be said that the development of any country can not do without application of computers.
But it had been very hard to store and process Chinese information in computer especially in computer-aided publishing system, before the invention of Laser Zhaopai for Chinese characters. It was very inefficient to publish in Chinese then. Many foreign companies developed their own Chinese laser typesetting and desired to sell them to China in very high price. Though they were extremely expensive, they were not efficient enough. So it was necessary to develop our own Laser typesetting technology. Wangxuan set out to study laser typesetting for Chinese characters from 1975.
After overcoming millions of difficulties, the Laser Zhaopai was invented in 1985, and has been practically used since 1987. These days 99% of Chinese publications in China and 90% of oversea Chinese publications are typeset by the Laser Zhaopai system.
Not only is The Laser Zhaopai important to the computer aided publishing in China, but also it helped improve the storage and processing of Chinese characters in computers. Even the short message, which we may use everyday, can not do without Wangxuan’s technique of compression of Chinese characters.
Though Wangxuan has passed away, but the technology he created will continue to work for us. He will never be forgotten by us.

星期三, 八月 23, 2006

信息系统安全之访问控制



信息系统安全中包括的方面很多,其中访问控制是一个重要的组成部分。


访问控制就是对访问系统资源的用户进行控制,使得有权限的用户访问系统资源,没有权限的用户被拒绝在系统之外。


访问控制策略主要有:自主访问控制,强制访问控制以及基于角色的访问控制等,目前基于角色的访问控制研究、应用的比较多。


访问控制策略对用户的访问请求进行授权判断的时候,依赖的主要是用户的身份,而对用户身份的判断应该分为两个部分:一、用户身份信息的判断,这个过程往往由用户在被系统提出要求时自主提供,提供的信息的正确性需要得到验证,这是验证的第一步;二、系统根据用户提供的身份信息和系统的策略进行决策判断,授予用户权限或者不授予。前者为认证,完成的功能为:判断用户声称的信息是否可信;后者真正进入访问控制的控制范围,根据用户具有的权限资格授予其对特定资源的访问权限。


自主访问控制策略和强制访问控制策略中用户直接对应的是权限,如果权限的数量过大进行权限授予的时候繁琐;而基于角色的访问控制策略,引入角色的概念,类似于权限代理,每个角色具备不同的权限集合,授予用户角色那么用户就具备角色拥有的权限了,这样用户权限的分配效率得到提高。另外,基于角色的访问控制还引入角色层次,提供角色之间的继承,使得权限分配更加有效;还引入职责分离约束等。


随着信息技术的发展,访问控制也在不断的发展已适应更新的技术环境,目前移动计算、普适计算等新概念、新技术已经提出并出现使用,传统的访问控制在这些新领域无法得到很好的适应,现在国内外很多信息安全方面的专家提出了很多新的访问控制模型,以用于新的环境,比如:支持时间(空间)的、环境因素、任务的访问控制等等。每种方案都针对特定的应用环境,基本上每种新的模型都是在旧的模型的基础之上进行的扩展使之支持以上的新增要素,新的模型的能力得到了提高但是不可否认的是访问控制系统的效率是大大降低了,在访问控制完成的功能和它费的资源之间能否达到一种平衡,这些模型往往都没有提到。但是,新的模型替代旧的模型是趋势,






Technorati : , , , , ,Access Control

星期五, 八月 18, 2006

暑假回家

这次暑假回家真的是专门回来生病了,第一天食物中毒拉肚子发高烧,一连3天,要走了,却又开始感冒发烧,今天晚上11点多的火车,现在才刚刚好了一些,怎么这么背呢?这次回来真是马不停蹄,大热天去青岛逛,完了回来走亲戚,积累的邪火终于在临走前这两天爆发,今天输完液,蒙着被子睡了一觉,出的汗湿透了被褥,但是发烧总算是控制住了。这次生病妈妈对我真的太好了,一个人在外面那么久,又一次体会到了母亲的伟大。咪咪也非常体贴,天天陪我输液,真的挺感动的!