Design of a Web Security Component for Code Authorization Based on Dual-roles

Lei Dian · Microcomputer applications · 2004

Security is one of weighty problems in computer software application at all times. This paper presents a method that provides guidelines for designing code authorization based on dual-roles in ASP NET application. Through performing authorization configuration for code statically or dynamically, authenticating user's identity is requested before protected code is executed, and only authenticated users can get the permission to perform specific actions. Using this technique can allow appointed users to perform certain actions, protect business rules, prevent data tampering and information disclosure and avoid malicious acts. Considering the reusability of component, the author design a security component using this method.

Read the paper · More papers on PaperTik