首页> 外文会议>Information and Communications Security >A Policy Based Framework for Access Control
【24h】

A Policy Based Framework for Access Control

机译:基于策略的访问控制框架

获取原文

摘要

This paper presents a policy-based framework for managing access control in distributed heterogeneous systems. This framework is based on the PDP/PEP approach. The PDP (Policy Decision Point) is a network policy server responsible for supplying policy information for network devices and applications. The PEP (Policy Enforcement Point) is the policy client (usually, a component of the network device/application) responsible for enforcing the policy. The communication between the PDP and the PEP is implemented by the COPS protocol, defined by the IETF. The COPS (Common Open Policy Service) protocol defines two modes of operation: outsourcing and provisioning. The choice between outsourcing and provisioning is supposed to have an important influence on the policy decision time. This paper evaluates the outsourcing model for access control policies based on the RBAC (Role-Based Access Control) model. The paper describes a complete implementation of the PDP/PEP framework, and presents the average response time of PDP under different load conditions.
机译:本文提出了一种用于管理分布式异构系统中访问控制的基于策略的框架。该框架基于PDP / PEP方法。 PDP(策略决策点)是一个网络策略服务器,负责为网络设备和应用程序提供策略信息。 PEP(策略执行点)是负责执行策略的策略客户端(通常是网络设备/应用程序的组件)。 PDP和PEP之间的通信是由IETF定义的COPS协议实现的。 COPS(通用开放策略服务)协议定义了两种操作模式:外包和供应。外包和供应之间的选择应该对策略决策时间有重要影响。本文评估了基于RBAC(基于角色的访问控制)模型的访问控制策略的外包模型。本文描述了PDP / PEP框架的完整实现,并介绍了在不同负载条件下PDP的平均响应时间。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号