首页 | 本学科首页   官方微博 | 高级检索  
     

VPN中的分布式访问控制
引用本文:谢方军,戴宗坤,张红,全成子,高志. VPN中的分布式访问控制[J]. 小型微型计算机系统, 2004, 25(7): 1250-1252
作者姓名:谢方军  戴宗坤  张红  全成子  高志
作者单位:1. 四川大学,计算机学院,四川,成都,610065
2. 四川大学,信息安全研究所,四川,成都,610065
3. 四川大学,物理科学与技术学院,四川,成都,610065
基金项目:国家自然科学基金 (60 73 0 46)资助
摘    要:针对VPN系统中的分布式访问控制及其管理问题,分析了现有的IETF模型的不足,提出一种分布式管理的访问控制模型。该模型将全局策略分解为局部(SubDomain,每个SubDomain对应一个网关)策略数据库的集合,同时在IETF的模型中增加策略判决点,以转发用户认证请求。并通过VPN的加密隧道来保护VPN系统安全策略传输过程和用户认证数据的完整性、机密性。本文最后给出了基于CORBA的原型来说明该模型的工作模式,实战证明,该模型能有效解决安全VPN中的策略的分布式管理和用户的漫游问题。

关 键 词:安全 VPN 分布式访问控制 CORBA 漫游
文章编号:1000-1220(2004)07-1250-03

Model of Distributed Access Control on VPN System
XIE Fang jun ,DAI Zong kun ,ZHANG Hong ,QUAN Cheng zi ,GAO Zhi. Model of Distributed Access Control on VPN System[J]. Mini-micro Systems, 2004, 25(7): 1250-1252
Authors:XIE Fang jun   DAI Zong kun   ZHANG Hong   QUAN Cheng zi   GAO Zhi
Affiliation:XIE Fang jun 1,DAI Zong kun 2,ZHANG Hong 3,QUAN Cheng zi 1,GAO Zhi 1 1
Abstract:Distributed Access Control (DAC) was a big problem in Virtual Private Network(VPN).The existing DAC models of IETF are centralized management and cannot authenticate roaming user easily. This paper presents a model that divides the centralized security policy database into the set of distributed sub domains (asub domain equals a SG) security policy databases, and adds policy forward point to IETF model,and makes use of the encrypted VPN tunnel to protect the integrity and confidentiality of the policy database transportation and users' authentication request.In VPN, every Secure Gateway (SG) has a unique sub domain name, and a pair (sub domain, user ID) represents the unique user identification (ID). A sub domain SG is responsible for the sub domain users' authentication request by the sub domain security policy database.When a user leaves his home sub domain to roam about other sub domain, the sub domain SG sends the user authentication request to the user's home sub domain SG and gets the result to authenticate roaming user.Finally, this paper implements the model based on OBE (an Embedded CORBA) and tests the performance by SmartBits 6000(it can authenticate the request of 1800 roaming users simultaneously). The results show that the model can securely solve the problem of the distributed management of security policy and authentication of roaming users in VPN.
Keywords:security  VPN  distributed access control  CORBA  roaming
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号