DocumentCode
3214768
Title
The Dynamic Endpoint-Based Access Control Model on VPN
Author
Dong, Lijun ; Yu, Shengsheng ; Ouyang, Kai
Author_Institution
Coll. of Comput. Sci., Huazhong Univ. of Sci. & Technol., Wuhan
fYear
2007
fDate
29-31 July 2007
Firstpage
44
Lastpage
54
Abstract
Today more and more organizations use Virtual Private Network (VPN) to implement their private communication. By tunneling, a dynamic virtual topology is constituted. Users can access various resources far and near through VPN. Sophisticated environments and behaviors bring the new challenge to access control for VPN. Traditionally access control models for VPN focus on the content of workflow, ignoring the outside environment factors. When locating different environments, client could have dissimilar security status, but it is hard for common VPN to sense these varieties. Thereby, some hidden troubles may exist. To address this problem, this paper presents a novel Dynamic Endpoint-Based Access Control (DEBAC) approach based on Role Based Access Control (RBAC). Because of the endpoint model introduced, DEBAC extends traditional RBAC to include the notion of both environments and behaviors and tries to implement a more flexible and comprehensive protection mechanism. The framework and prototype of DEBAC is interpreted and detailed in this paper. Finally, we give the analysis about an instance of our prototype and discuss an experiment about the DEBAC model.
Keywords
authorisation; telecommunication network topology; telecommunication security; virtual private networks; DEBAC approach; VPN; dynamic endpoint-based access control model; dynamic virtual topology; private communication; role based access control; virtual private network; Access control; Computer science; Educational institutions; Internet; Network topology; Object oriented modeling; Prototypes; Security; Tunneling; Virtual private networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Networking, Architecture, and Storage, 2007. NAS 2007. International Conference on
Conference_Location
Guilin
Print_ISBN
0-7695-2927-5
Type
conf
DOI
10.1109/NAS.2007.53
Filename
4286407
Link To Document