Title :
RBPIM: a PCIM-based framework for RBAC
Author :
Nabhen, Ricardo ; Jamhour, Edgard ; Maziero, Carlos
Author_Institution :
PPGIA, PUCPR, Brazil
Abstract :
This paper presents a PCIM-based framework for storing and enforcing RBAC (role based access control) policies in distributed heterogeneous systems. PCIM (policy core information model) is a generic information model proposed by IETF. This paper proposes a PCIM extension, called RBPIM (role-based policy information model), in order to represent network access policies based on the RBAC model. An RBPlM implementation framework based on the POP/PEP (policy decision point/policy enforcement point) approach is also presented. In the proposed framework, the communication between the PDP and the PEPs is implemented using the COPS (common open policy service) protocol, also defined by the IETF. The framework adopts the outsourcing approach, where the policy rules are evaluated by the PDP, as defined by the COPS standard. This paper evaluates the outsourcing model for access control by presenting a case study and the average response time of PDP under different load conditions.
Keywords :
outsourcing; protocols; subscriber loops; telecommunication network management; IETF; common open policy service protocol; distributed heterogeneous systems; generic information model; network access policies; outsourcing approach; policy core information model; policy decision point; policy enforcement point; role based access control policies; role-based policy information model; Access control; Access protocols; Computer integrated manufacturing; Context modeling; Delay; NIST; Network servers; Outsourcing; Quality of service; Resource management;
Conference_Titel :
Local Computer Networks, 2003. LCN '03. Proceedings. 28th Annual IEEE International Conference on
Print_ISBN :
0-7695-2037-5
DOI :
10.1109/LCN.2003.1243112