Title :
Improvement of XACML access control mechanism based on NETCONF subtree filtering rpc
Author :
Wang, Jinjin ; Zhang, Bin ; Li, Guohui ; Li, Yan ; Gao, Xuesong
Author_Institution :
Pattern Recognition & Intell. Syst. Lab., Beijing Univ. of Posts & Telecommun., Beijing, China
Abstract :
The Network Configuration Protocol (NETCONF) is a new network Management Protocol which becomes more and more widely used in network management area. To make NETCONF much safer, we extend the extensible Access Control Markup Language(XACML) access control mechanism and implement it on our NETCONF network management system-BUPT-NEP. We use subtree filtering expression to represent resource instead of xpath expression, which makes the new mechanism suitable for access control on NETCONF subtree filtering rpc.
Keywords :
authorisation; hypermedia markup languages; information filtering; protocols; tree data structures; BUPT-NEP; Netconf subtree filtering RPC; XACML access control mechanism; extensible access control markup language; network configuration protocol; xpath expression; Authorization; Context; Filtering; Protocols; XML; NETCONF; XACML; subtree filtering rpc;
Conference_Titel :
Network Infrastructure and Digital Content, 2010 2nd IEEE International Conference on
Conference_Location :
Beijing
Print_ISBN :
978-1-4244-6851-5
DOI :
10.1109/ICNIDC.2010.5657947