B. Martins, D. M. F. Mattos, N. Fernandes, D. Muchaluat-Saade, A. Vieira, E. F. Silva
{"title":"An Extensible Access Control Architecture for Software Defined Networks based on X.812","authors":"B. Martins, D. M. F. Mattos, N. Fernandes, D. Muchaluat-Saade, A. Vieira, E. F. Silva","doi":"10.1109/LATINCOM48065.2019.8937972","DOIUrl":null,"url":null,"abstract":"The software-defined networking paradigm adds flexibility to network management as it allows the policy application in fined-grained flow level. However, the traditional definition of flow disregards user identification credentials. Thus, Identity Management in software-defined networking is a current challenge. In this paper, we propose an access control architecture for software-defined networking, based on ITU X.812 standard and implemented on AuthFlow authentication framework. The proposed architecture integrates AuthFlow with an attribute repository that maps network policies to user attributes. The proposal supports its integration with identity federation, and we evaluate it under a role-based access control model. The evaluated use case is a service differentiation policy according to the role of each user. The evaluation results demonstrate the correct application of the quality of service according to the role of the flow target user.","PeriodicalId":120312,"journal":{"name":"2019 IEEE Latin-American Conference on Communications (LATINCOM)","volume":"12 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 IEEE Latin-American Conference on Communications (LATINCOM)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/LATINCOM48065.2019.8937972","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
The software-defined networking paradigm adds flexibility to network management as it allows the policy application in fined-grained flow level. However, the traditional definition of flow disregards user identification credentials. Thus, Identity Management in software-defined networking is a current challenge. In this paper, we propose an access control architecture for software-defined networking, based on ITU X.812 standard and implemented on AuthFlow authentication framework. The proposed architecture integrates AuthFlow with an attribute repository that maps network policies to user attributes. The proposal supports its integration with identity federation, and we evaluate it under a role-based access control model. The evaluated use case is a service differentiation policy according to the role of each user. The evaluation results demonstrate the correct application of the quality of service according to the role of the flow target user.