首页> 外文会议>International Conference on Networking, Architecture, and Storage >The Dynamic Endpoint-Based Access Control Model on VPN
【24h】

The Dynamic Endpoint-Based Access Control Model on VPN

机译:基于动态端点的访问控制模型在VPN上

获取原文

摘要

Today more and more organizations use Virtual Private Network (VPN) to implement their private communication. By tunneling, a dynamic virtual topology is constituted. Users can access various resources far and near through VPN. Sophisticated environments and behaviors bring the new challenge to access control for VPN. Traditionally access control models for VPN focus on the content of workflow, ignoring the outside environment factors. When locating different environments, client could have dissimilar security status, but it is hard for common VPN to sense these varieties. Thereby, some hidden troubles may exist. To address this problem, this paper presents a novel Dynamic Endpoint-Based Access Control (DEBAC) approach based on Role Based Access Control (RBAC). Because of the endpoint model introduced, DEBAC extends traditional RBAC to include the notion of both environments and behaviors and tries to implement a more flexible and comprehensive protection mechanism. The framework and prototype of DEBAC is interpreted and detailed in this paper. Finally, we give the analysis about an instance of our prototype and discuss an experiment about the DEBAC model.
机译:今天越来越多的组织使用虚拟专用网络(VPN)来实现他们的私人通信。通过隧道,构成动态虚拟拓扑。用户可以访问远程和靠近VPN的各种资源。复杂的环境和行为为VPN提供了新的挑战。传统上用于VPN的控制模型专注于工作流程的内容,忽略了外部环境因素。当定位不同的环境时,客户端可能具有异常的安全状态,但常见的VPN很难意识到这些品种。因此,可能存在一些隐藏的麻烦。为了解决这个问题,本文提出了一种基于基于角色的访问控制(RBAC)的新型动态端点的访问控制(Debac)方法。由于端点模型引入,Debac扩展了传统的RBAC,包括环境和行为的概念,并试图实现更灵活和全面的保护机制。本文解释和详细说明了Debac的框架和原型。最后,我们对我们的原型实例进行了分析,并讨论了脱矛盾的实验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号