A Flexible and Dynamic Access Control Policy Framework for an Active Networking Environment
نویسندگان
چکیده
To provide security for active networking nodes with respect to availability and controlled access the introduction of an access control mechanism and consequently a policy framework are mandatory. We follow the approach of a scenario-tailored runtime supervision of the service. During the development of the access control mechanism we strongly focused on keeping the mechanism as efficient as possible and to realize a modular design which allows to dynamically upgrade and configure the mechanism making use of the active networking technology itself while at the same time ensuring that mandatory security checks cannot be circumvented. Each service has to pass initial checks before it could be executed on an active node. Furthermore, also service-specific adaptive criterions could be included into the initial check. This paper presents the resulting flexible and dynamic access control policy framework. The approach considers the following aspects: service-specific supervision requirements, node-specific protection, extensibility in order to satisfy future security requirements and a dynamic reaction mechanism. The framework provides a mechanism for the authors of services to express the resource and authorization requirements of their services. Additionally, the network administrator is able to express its trust into a service and to configure the protection mechanisms of each active node in an individual way. Further on, the administrator is able to change the configuration of an active node at runtime and finally a reaction mechanism is integrated into the policy framework. The policy framework utilizes the possibilities provided by an active networking infrastructure. In this report we discuss the policy framework and we also present results achieved with a first prototype realized for the active networking environment AMnet.
منابع مشابه
A Flexible IP Active Networks Architecture
This paper presents the main concepts of the IST Project FAIN “Future Active IP Networks” [10], a three-year collaborative research project, whose main task is to develop and validate an open, flexible, programmable and dependable network architecture based on a novel active node approach. This generic architecture for active networks is an innovative integration of active networking, distribut...
متن کاملA semantic-aware role-based access control model for pervasive computing environments
Access control in open and dynamic Pervasive Computing Environments (PCEs) is a very complex mechanism and encompasses various new requirements. In fact, in such environments, context information should be used in access control decision process; however, it is not applicable to gather all context information completely and accurately all the time. Thus, a suitable access control model for PCEs...
متن کاملA context-sensitive dynamic role-based access control model for pervasive computing environments
Resources and services are accessible in pervasive computing environments from anywhere and at any time. Also, due to ever-changing nature of such environments, the identity of users is unknown. However, users must be able to access the required resources based on their contexts. These and other similar complexities necessitate dynamic and context-aware access control models for such environmen...
متن کاملAuthorization models for secure information sharing: a survey and research agenda
This article presents a survey of authorization models and considers their 'fitness-for-purpose' in facilitating information sharing. Network-supported information sharing is an important technical capability that underpins collaboration in support of dynamic and unpredictable activities such as emergency response, national security, infrastructure protection, supply chain integration and emerg...
متن کاملPolicy-based Management for ALAN-Enabled Networks
This paper presents the architecture, the policy schema, and the policy specifications necessary to accomplish effective management of the Application Level Active Networking (ALAN) environment. Using ALAN, developers can engineer applications through the network by utilising platforms (active servers) on which 3 party software (proxylets) can be dynamically loaded and run. Redirection of packe...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2003