首页> 外文会议>International Parallel and Distributed Processing Symposium >A Network Access Control Approach based on the AAA Architecture and Authorization Attributes
【24h】

A Network Access Control Approach based on the AAA Architecture and Authorization Attributes

机译:基于AAA架构和授权属性的网络访问控制方法

获取原文

摘要

Network access control mechanisms constitute an increasingly needed service, when communications are becoming more and more ubiquitous thanks to some technologies such as wireless networks or Mobile IP. This paper presents a particular scenario where access rules are based not only on the identity of the different users, but also on authorization data related to those users. In order to accomplish this general goal, it will be necessary to add to the traditional systems specific services for authentication and authorization, and also some entities able to manage the information related to identity, roles and permissions. Network access will be based on the 802.1X framework and the AAA architecture, as they constitute the basis for most of the existing proposals for limiting the access to a restricted network. Those proposals will be extended using an authorization infrastructure based on SAML statements, the RBAC model, and XACML as the language for expressing authorization policies.
机译:当由于诸如无线网络或移动IP的某些技术而变得越来越繁重时,网络访问控制机制构成了越来越需要的服务。本文介绍了一个特定的方案,其中访问规则不仅基于不同用户的身份,还基于与这些用户相关的授权数据。为了实现这一普遍目标,有必要添加到传统的系统特定服务进行身份验证和授权,以及一些能够管理与身份,角色和权限相关的信息的实体。网络访问将基于802.1x框架和AAA架构,因为它们构成了大多数现有建议的基础,用于限制对受限制网络的访问。这些提案将使用基于SAML语句,RBAC模型和XACML作为用于表达授权策略的语言的授权基础架构来扩展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号