首页> 外文期刊>Journal of network and computer applications >A network access control approach based on the AAA architecture and authorization attributes
【24h】

A network access control approach based on the AAA architecture and authorization attributes

机译:一种基于AAA架构和授权属性的网络访问控制方法

获取原文
获取原文并翻译 | 示例
           

摘要

Network access control mechanisms constitute an increasingly needed service, when communications are becoming more and more ubiquitous thanks to some technologies such as wireless networks or Mobile IP. This paper presents a particular scenario where access rules are based not only on the identity of the different users but also on authorization data related to those users. In order to accomplish this general goal, it will be necessary to add to the traditional system-specific services for authentication and authorization, and also some entities able to manage the information related to identity, roles and permissions. Network access will be based on the 802. 1X framework and the Authentication, Authorization, and Accounting (AAA) architecture, as they constitute the basis for most of the existing proposals for limiting the access to a restricted network. These proposals will be extended making use of an authorization infrastructure based on SAML statements, the RBAC model, and XACML as the main language for expressing authorization policies. The solution that we present in this paper is a consequence of an exhaustive and non-trivial analysis of the different mechanisms that could be used to provide this kind of service. As we will see, the correct integration of these different mechanisms leads to the definition of a scalable and versatile network access control system which conforms to the guidelines outlined by the AAA initiative.
机译:当由于诸如无线网络或移动IP之类的某些技术而使通信变得越来越普遍时,网络访问控制机制就成为一种日益需要的服务。本文提出了一种特殊的方案,其中访问规则不仅基于不同用户的身份,而且还基于与这些用户相关的授权数据。为了实现这一总体目标,有必要在传统的系统特定服务中添加用于身份验证和授权的功能,并且还需要增加一些能够管理与身份,角色和权限有关的信息的实体。网络访问将基于802. 1X框架和身份验证,授权和计费(AAA)架构,因为它们构成了大多数现有建议的基础,用于限制对受限网络的访问。将利用基于SAML语句,RBAC模型和XACML作为表达授权策略的主要语言的授权基础结构来扩展这些建议。我们在本文中提出的解决方案是对可以用来提供这种服务的不同机制进行详尽且不重要的分析的结果。正如我们将看到的,这些不同机制的正确集成导致可扩展且通用的网络访问控制系统的定义,该系统符合AAA倡议概述的准则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号