节点文献

VPN中的分布式访问控制

Model of Distributed Access Control on VPN System

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 谢方军戴宗坤张红全成子高志

【Author】 XIE Fang jun 1, DAI Zong kun 2, ZHANG Hong 3, QUAN Cheng zi 1, GAO Zhi 1 1 (Collage of Computer Science, Sichuan University, Chengdu 610065, China) 2 (Institute of Information Security, Sichuan University, Chengdu 610065, Chian) 3 (Collage of Physics Science &Technology, Sichuan University, Chengdu 610065, China)

【机构】 四川大学计算机学院四川大学信息安全研究所四川大学物理科学与技术学院四川大学计算机学院 四川成都610065四川成都610065四川成都610065

【摘要】 针对 VPN系统中的分布式访问控制及其管理问题 ,分析了现有的 IETF模型的不足 ,提出一种分布式管理的访问控制模型 .该模型将全局策略分解为局部 (Sub Domain,每个 Sub Domain对应一个网关 )策略数据库的集合 ,同时在 IETF的模型中增加策略判决点 ,以转发用户认证请求 ,并通过 VPN的加密隧道来保护 VPN系统安全策略传输过程和用户认证数据的完整性、机密性 .本文最后给出了基于 CORBA的原型来说明该模型的工作模式 ,实践证明 ,该模型能有效解决安全 VPN中的策略的分布式管理和用户的漫游问题

【Abstract】 Distributed Access Control (DAC) was a big problem in Virtual Private Network(VPN).The existing DAC models of IETF are centralized management and cannot authenticate roaming user easily. This paper presents a model that divides the centralized security policy database into the set of distributed sub domains (asub domain equals a SG) security policy databases, and adds policy forward point to IETF model,and makes use of the encrypted VPN tunnel to protect the integrity and confidentiality of the policy database transportation and users’ authentication request.In VPN, every Secure Gateway (SG) has a unique sub domain name, and a pair (sub domain, user ID) represents the unique user identification (ID). A sub domain SG is responsible for the sub domain users’ authentication request by the sub domain security policy database.When a user leaves his home sub domain to roam about other sub domain, the sub domain SG sends the user authentication request to the user’s home sub domain SG and gets the result to authenticate roaming user.Finally, this paper implements the model based on OBE (an Embedded CORBA) and tests the performance by SmartBits 6000(it can authenticate the request of 1800 roaming users simultaneously). The results show that the model can securely solve the problem of the distributed management of security policy and authentication of roaming users in VPN.

【关键词】 安全VPN分布式访问控制CORBA漫游
【Key words】 securityVPNdistributed access controlCORBAroaming
【基金】 国家自然科学基金 (60 73 0 46)资助
  • 【文献出处】 小型微型计算机系统 ,Mini-micro Systems , 编辑部邮箱 ,2004年07期
  • 【分类号】TP393.08
  • 【被引频次】5
  • 【下载频次】90
节点文献中: 

本文链接的文献网络图示:

本文的引文网络