• DocumentCode
    3522558
  • Title

    A Network Access Control Approach for QoS Support Based on the AAA Architecture

  • Author

    Wang, Shujuan ; Liang, Mangui

  • Author_Institution
    Inst. of Inf. Sci., Beijing Jiaotong Univ., Beijing, China
  • fYear
    2010
  • fDate
    28-29 Oct. 2010
  • Firstpage
    507
  • Lastpage
    511
  • Abstract
    The primary role of network access control is to decide on the validity of user´s identity accepted into the networks and authorization accessed to the particular resource so that users conforming to their established access polices achieve predefined services. This paper presents a specific scenario which supports quality of service (QoS) in network domain. The QoS access rules are based not only on the identity of end users but also authorization policies related to those users. To achieving that goal, it is necessary to add new functions as QoS authentication and QoS Authorization to the traditional access control schemes, and also some entities able to administrate the information relevant to QoS requirement, identity and decisions. The proposed approach is based on the 802.1X framework and the Authentication, Authorization and Accounting (AAA) architecture owing to the fact that they are the most widely accepted and deployed standards for network access control. XACML (eXtensible Access Control Markup Language) is used to express QoS resource assignment and authorization policies, and SAML (Security Assertion Markup Language) is selected to exchange and transport related messages. The proposed approach supports QoS provision by ensuring that only validated user with appropriate QoS requirement which satisfies the QoS access policies can get resource reserved, then the user can use the resource exclusively during the corresponding QoS session. This approach provides QoS support effectively cooperating with resource reservation technology.
  • Keywords
    XML; authorisation; computer network security; quality of service; AAA architecture; QoS; SAML; XACML; access policies; authentication-authorization-accounting; authorization; authorization policies; extensible access control markup language; network access control; quality of service; resource reservation technology; security assertion markup language; user´s identity; Authentication; Authorization; Computer architecture; Protocols; Quality of service; Servers; AAA; Access Control; Authentication; Authorization; QoS;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Intelligence Information Processing and Trusted Computing (IPTC), 2010 International Symposium on
  • Conference_Location
    Huanggang
  • Print_ISBN
    978-1-4244-8148-4
  • Electronic_ISBN
    978-0-7695-4196-9
  • Type

    conf

  • DOI
    10.1109/IPTC.2010.116
  • Filename
    5663617