การออกแบบและประเมินผลระบบส่งต่ออีเมลปลอดภัยที่มีความพร้อมใช้งานสูง ด้วยการยืนยันตัวตน OAuth2 สำหรับระบบดั้งเดิม

ผู้แต่ง

  • พิชิต ทองดำ สาขาวิศวกรรมคอมพิวเตอร์ วิทยาลัยนวัตกรรมด้านเทคโนโลยีและวิศวกรรมศาสตร์ มหาวิทยาลัยธุรกิจบัณฑิตย์ จังหวัดกรุงเทพมหานคร 10210 ประเทศไทย https://orcid.org/0009-0003-4074-6851
  • ธนัญ จารุวิทยโกวิท สาขาวิชาวิศวกรรมคอมพิวเตอร์ วิทยาลัยนวัตกรรมด้านเทคโนโลยีและวิศวกรรมศาสตร์ มหาวิทยาลัยธุรกิจบัณฑิตย์ จังหวัดกรุงเทพมหานคร 10210 ประเทศไทย

DOI:

https://doi.org/10.65205/jcct.2026.e2971

คำสำคัญ:

ระบบส่งต่ออีเมลปลอดภัย, แอปพลิเคชันดั้งเดิม, การยืนยันตัวตนสมัยใหม่, โอออธ 2 เอเจนต์, ความพร้อมใช้งานสูงระดับบริการ

บทคัดย่อ

ท่ามกลางภัยคุกคามทางไซเบอร์ที่ทวีความรุนแรง มาตรฐานการยืนยันตัวตนสมัยใหม่บนโปรโตคอล OAuth 2.0 ของ Microsoft 365 ได้สร้างปัญหาความเข้ากันไม่ได้สำหรับแอปพลิเคชันดั้งเดิมที่ไม่สามารถแก้ไขซอร์สโค้ดได้ ส่งผลให้องค์กรเผชิญความเสี่ยงทั้งด้านความปลอดภัยและความต่อเนื่องทางธุรกิจ โดยเฉพาะในระบบสื่อสารผ่านอีเมล งานวิจัยนี้นำเสนอสถาปัตยกรรมระบบส่งต่ออีเมลปลอดภัยที่มีความพร้อมใช้งานสูง จุดเด่นอยู่ที่การพัฒนา “OAuth2 Agent Module” ซึ่งทำหน้าที่เป็นตัวกลางในการแปลงโปรโตคอลการยืนยันตัวตนจากระบบเดิมไปสู่มาตรฐาน OAuth 2.0 ได้อย่างราบรื่นโดยไม่ต้องแก้ไขแอปพลิเคชันดั้งเดิม และบูรณาการร่วมกับระบบความพร้อมใช้งานสูงที่สามารถตรวจสอบความผิดปกติได้ในระดับบริการ ผลการทดสอบเชิงประจักษ์ยืนยันว่า 1) สถาปัตยกรรมที่นำเสนอสามารถส่งต่ออีเมลด้วยมาตรฐาน OAuth 2.0 ได้สำเร็จ 100% 2) แม้กระบวนการความปลอดภัยที่เพิ่มขึ้นจะทำให้ความหน่วงเฉลี่ยเพิ่มขึ้นเล็กน้อยเป็น 2.158 วินาที เมื่อเทียบกับระบบการยืนยันตัวตนพื้นฐานแบบดั้งเดิม 1.908 วินาที แต่ยังอยู่ในเกณฑ์ที่ยอมรับได้ และ 3) ระบบ HA สามารถกู้คืนการทำงานเมื่อบริการล้มเหลวได้ภายในเวลาเฉลี่ย 1.312 วินาที งานวิจัยนี้จึงเป็นแนวทางสำคัญในการยกระดับความปลอดภัยให้ระบบดั้งเดิมสามารถทำงานร่วมกับมาตรฐานสมัยใหม่ได้อย่างมั่นคงและปลอดภัย

Downloads

Download data is not yet available.

เอกสารอ้างอิง

Cassen, A., & Contributors. (2017). Keepalived User Guide (Release 1.2.15). The Keepalived Project. https://keepalived.readthedocs.io/_/downloads/en/stable/pdf/

Chatterjee, N., Majumdar, S., Das, P. P., & Chakrabarti, A. (2024). Tool Assisted Agile Approach for Legacy Application Migration. Research Square. https://doi.org/10.21203/rs.3.rs-3323311/v1 DOI: https://doi.org/10.21203/rs.3.rs-3323311/v1

Cryptography. (2023). Welcome to Pyca/Cryptography (Version 41.0.7) [Computer Software]. Cryptography. https://cryptography.io/en/41.0.7 DOI: https://doi.org/10.3390/cryptography7030041

Dovecot Team. (n.d.). Postfix and Dovecot SASL. Dovecot. https://doc.dovecot.org/2.3/configuration_manual/howto/postfix_and_dovecot_sasl/#howto-postfix-and-dovecot-sasl

Faseeha, U., Jamil Syed, H., Samad, F., Zehra, S., & Ahmed, H. (2025). Observability in Microservices: An In-Depth Exploration of Frameworks, Challenges, and Deployment Paradigms. IEEE Access, 13, 72011-72039. https://doi.org/10.1109/ACCESS.2025.3562125 DOI: https://doi.org/10.1109/ACCESS.2025.3562125

Gbenle, T. P., Abayomi, A. A., Uzoka, A. C., Ogeawuchi, J. C., Adanigbo, O. S., & Odofin, O. T. (2022). Applying OAuth2 and JWT Protocols in Securing Distributed API Gateways: Best Practices and Case Review. International Journal of Multidisciplinary Research and Growth Evaluation, 3(5), 628-634. https://doi.org/10.54660/.IJMRGE.2022.3.5.628-634 DOI: https://doi.org/10.54660/.IJMRGE.2022.3.5.628-634

Hardt, D. (2012). The OAuth 2.0 Authorization Framework (No. RFC6749). Internet Engineering Task Force. https://doi.org/10.17487/rfc6749 DOI: https://doi.org/10.17487/rfc6749

Hoffman, P. (2002). SMTP Service Extension for Secure SMTP over Transport Layer Security (No. RFC3207). Internet Engineering Task Force. https://doi.org/10.17487/rfc3207 DOI: https://doi.org/10.17487/rfc3207

Klensin, J. (2008). Simple Mail Transfer Protocol (No. RFC5321). Internet Engineering Task Force. https://doi.org/10.17487/rfc5321 DOI: https://doi.org/10.17487/rfc5321

Matcha, S., & Kumar, M. (2025). Enhancing Software Security with OAuth 2.0: Implementation Strategies and Vulnerability Mitigation. Journal of Emerging Technologies and Innovative Research, 12(3), e886–e902.

Microsoft. (2025a). Microsoft Identity Platform and OAuth 2.0 Client Credentials Flow. Microsoft Learn. https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-client-creds-grant-flow

Microsoft. (2025b). Microsoft Authentication Library (MSAL) for Python. Microsoft Learn. https://learn.microsoft.com/en-us/entra/msal/python

Mishra, A. (2020). Legacy System Modernization: Effective Strategies and Best Practices. International Journal of Leading Research Publication, 1(3), 1-7. https://doi.org/10.5281/zenodo.14769544

Oliveira, P. M., Vieira, M. B., Ferreira, I. C., Leite, J. P. R. R., Oliveira, E. M., Kuehne, B. T., Moreira, E. M., & Carpinteiro, O. A. S. (2022). ABL: An Original Active Blacklist Based on a Modification of the SMTP. arXiv. https://doi.org/10.48550/arXiv.2208.10602

Postfix. (n.d.). Postfix Architecture Overview. https://www.postfix.org/OVERVIEW.html

Putranto, E. A. (2019). High Availability Server Implementation Using NGINX, Keepalived, and Varnish to Ease Web Server Access. ResearchGate. https://www.researchgate.net/publication/334451751

Python Software Foundation. (2025). smtplib - SMTP Protocol Client. https://docs.python.org/3.12/library/smtplib.html#module-smtplib

Sharabov, M., Tsochev, G., Gancheva, V., & Tasheva, A. (2024). Filtering and Detection of Real-Time Spam Mail Based on a Bayesian Approach in University Networks. Electronics, 13(2), 374. https://doi.org/10.3390/electronics13020374 DOI: https://doi.org/10.3390/electronics13020374

The aiosmtpd Developers. (2025). The SMTP Module. Read the Docs. Python. https://aiosmtpd.aio-libs.org/en/latest/smtp.html

The Exchange Team. (2024). Exchange Online to Retire Basic Auth for Client Submission (SMTP AUTH). Microsoft Community Hub. https://techcommunity.microsoft.com/blog/exchange/exchange-online-to-retire-basic-auth-for-client-submission-smtp-auth/4114750

ดาวน์โหลด

เผยแพร่แล้ว

21-04-2026

รูปแบบการอ้างอิง

ทองดำ พ., & จารุวิทยโกวิท ธ. (2026). การออกแบบและประเมินผลระบบส่งต่ออีเมลปลอดภัยที่มีความพร้อมใช้งานสูง ด้วยการยืนยันตัวตน OAuth2 สำหรับระบบดั้งเดิม. วารสารคอมพิวเตอร์และเทคโนโลยีสร้างสรรค์, 4(1), e2971. https://doi.org/10.65205/jcct.2026.e2971