• DocumentCode
    414812
  • Title

    Realizing a flexible access control mechanism for active nodes based on active networking technology

  • Author

    Hess, A. ; Schafer, G.

  • Author_Institution
    Telecommun. Networks Group, Technische Univ. Berlin, Germany
  • Volume
    1
  • fYear
    2004
  • fDate
    20-24 June 2004
  • Firstpage
    68
  • Abstract
    This paper presents a model and mechanism for flexible access control of loadable on-demand services in an active network, using code origin authentication and runtime supervision. During the development of the access control mechanism, we strongly focused on keeping the mechanism as efficient as possible, and to realize a modular design which allows to dynamically upgrade and configure the mechanism, making use of the active networking technology itself, while at the same time ensuring that mandatory security checks cannot be circumvented. Each service has to pass initial checks before it can he executed on an active node. Our approach provides access control that is dynamic, extensible and efficient, realizing a demand-driven supervision which avoids supervision of those actions that do not need to be supervised. Specific access control modules are realized as active services and activated when needed. Finally, we present results that have been achieved with a first prototype developed for the active networking platform (active multicast network) which are very promising.
  • Keywords
    authorisation; message authentication; multicast communication; telecommunication security; access control mechanism; active multicast network; active networking technology; active node; code origin authentication; loadable on-demand service; security check; Access control; Authentication; Computer languages; Internet; Mechanical factors; Operating systems; Prototypes; Runtime; Space technology; Transcoding;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2004 IEEE International Conference on
  • Print_ISBN
    0-7803-8533-0
  • Type

    conf

  • DOI
    10.1109/ICC.2004.1312454
  • Filename
    1312454