首页> 外文期刊>Communications Magazine, IEEE >Virtualized security at the network edge: a user-centric approach
【24h】

Virtualized security at the network edge: a user-centric approach

机译:网络边缘的虚拟化安全性:以用户为中心的方法

获取原文
获取原文并翻译 | 示例
           

摘要

The current device-centric protection model against security threats has serious limitations. On one hand, the proliferation of user terminals such as smartphones, tablets, notebooks, smart TVs, game consoles, and desktop computers makes it extremely difficult to achieve the same level of protection regardless of the device used. On the other hand, when various users share devices (e.g., parents and kids using the same devices at home), the setup of distinct security profiles, policies, and protection rules for the different users of a terminal is far from trivial. In light of this, this article advocates for a paradigm shift in user protection. In our model, protection is decoupled from users' terminals, and it is provided by the access network through a trusted virtual domain. Each trusted virtual domain provides unified and homogeneous security for a single user irrespective of the terminal employed. We describe a user-centric model where nontechnically savvy users can define their own profiles and protection rules in an intuitive way. We show that our model can harness the virtualization power offered by next-generation access networks, especially from network functions virtualization in the points of presence at the edge of telecom operators. We also analyze the distinctive features of our model, and the challenges faced based on the experience gained in the development of a proof of concept.
机译:当前针对安全威胁的以设备为中心的保护模型具有严重的局限性。一方面,诸如智能手机,平板电脑,笔记本电脑,智能电视,游戏机和台式计算机之类的用户终端的激增,使得无论使用何种设备,都很难获得相同级别的保护。另一方面,当各种用户共享设备时(例如,父母和孩子在家中使用相同的设备),为终端的不同用户设置不同的安全配置文件,策略和保护规则绝非易事。有鉴于此,本文提倡用户保护模式的转变。在我们的模型中,保护与用户终端分离,并且由访问网络通过受信任的虚拟域来提供。每个受信任的虚拟域都为单个用户提供统一且同质的安全性,而与所使用的终端无关。我们描述了一个以用户为中心的模型,在此模型中,非技术娴熟的用户可以以直观的方式定义自己的配置文件和保护规则。我们证明了我们的模型可以利用下一代接入网提供的虚拟化功能,尤其是在电信运营商边缘的网络中从网络功能虚拟化中获得的功能。我们还将分析模型的鲜明特征,并基于在概念验证的开发中获得的经验来应对所面临的挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号