DocumentCode :
3214768
Title :
The Dynamic Endpoint-Based Access Control Model on VPN
Author :
Dong, Lijun ; Yu, Shengsheng ; Ouyang, Kai
Author_Institution :
Coll. of Comput. Sci., Huazhong Univ. of Sci. & Technol., Wuhan
fYear :
2007
fDate :
29-31 July 2007
Firstpage :
44
Lastpage :
54
Abstract :
Today more and more organizations use Virtual Private Network (VPN) to implement their private communication. By tunneling, a dynamic virtual topology is constituted. Users can access various resources far and near through VPN. Sophisticated environments and behaviors bring the new challenge to access control for VPN. Traditionally access control models for VPN focus on the content of workflow, ignoring the outside environment factors. When locating different environments, client could have dissimilar security status, but it is hard for common VPN to sense these varieties. Thereby, some hidden troubles may exist. To address this problem, this paper presents a novel Dynamic Endpoint-Based Access Control (DEBAC) approach based on Role Based Access Control (RBAC). Because of the endpoint model introduced, DEBAC extends traditional RBAC to include the notion of both environments and behaviors and tries to implement a more flexible and comprehensive protection mechanism. The framework and prototype of DEBAC is interpreted and detailed in this paper. Finally, we give the analysis about an instance of our prototype and discuss an experiment about the DEBAC model.
Keywords :
authorisation; telecommunication network topology; telecommunication security; virtual private networks; DEBAC approach; VPN; dynamic endpoint-based access control model; dynamic virtual topology; private communication; role based access control; virtual private network; Access control; Computer science; Educational institutions; Internet; Network topology; Object oriented modeling; Prototypes; Security; Tunneling; Virtual private networks;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Networking, Architecture, and Storage, 2007. NAS 2007. International Conference on
Conference_Location :
Guilin
Print_ISBN :
0-7695-2927-5
Type :
conf
DOI :
10.1109/NAS.2007.53
Filename :
4286407
Link To Document :
بازگشت