【24h】

The Dynamic Endpoint-Based Access Control Model on VPN

机译:VPN上基于动态端点的访问控制模型

获取原文
获取原文并翻译 | 示例

摘要

Today more and more organizations use Virtual Private Network (VPN) to implement their private communication. By tunneling, a dynamic virtual topology is constituted. Users can access various resources far and near through VPN. Sophisticated environments and behaviors bring the new challenge to access control for VPN. Traditionally access control models for VPN focus on the content of workflow, ignoring the outside environment factors. When locating different environments, client could have dissimilar security status, but it is hard for common VPN to sense these varieties. Thereby, some hidden troubles may exist. To address this problem, this paper presents a novel Dynamic Endpoint-Based Access Control (DEBAC) approach based on Role Based Access Control (RBAC). Because of the endpoint model introduced, DEBAC extends traditional RBAC to include the notion of both environments and behaviors and tries to implement a more flexible and comprehensive protection mechanism. The framework and prototype of DEBAC is interpreted and detailed in this paper. Finally, we give the analysis about an instance of our prototype and discuss an experiment about the DEBAC model.
机译:如今,越来越多的组织使用虚拟专用网(VPN)来实现其专用通信。通过隧道,构成了动态虚拟拓扑。用户可以通过VPN远近访问各种资源。复杂的环境和行为给VPN的访问控制带来了新的挑战。传统上,VPN的访问控制模型关注工作流的内容,而忽略了外部环境因素。当定位不同的环境时,客户端的安全状态可能不同,但是普通VPN很难感知到这些变化。因此,可能存在一些隐患。为了解决这个问题,本文提出了一种基于角色访问控制(RBAC)的基于动态端点的动态访问控制(DEBAC)方法。由于引入了端点模型,DEBAC扩展了传统的RBAC,以包括环境和行为的概念,并尝试实现更灵活,更全面的保护机制。本文对DEBAC的框架和原型进行了解释和详细介绍。最后,我们对原型实例进行分析,并讨论有关DEBAC模型的实验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号