Jinjin Wang, Bin Zhang, Guohui Li, Yan Li, Xuesong Gao
{"title":"Improvement of XACML access control mechanism based on NETCONF subtree filtering rpc","authors":"Jinjin Wang, Bin Zhang, Guohui Li, Yan Li, Xuesong Gao","doi":"10.1109/ICNIDC.2010.5657947","DOIUrl":null,"url":null,"abstract":"The Network Configuration Protocol (NETCONF) is a new network Management Protocol which becomes more and more widely used in network management area. To make NETCONF much safer, we extend the extensible Access Control Markup Language(XACML) access control mechanism and implement it on our NETCONF network management system-BUPT-NEP. We use subtree filtering expression to represent resource instead of xpath expression, which makes the new mechanism suitable for access control on NETCONF subtree filtering rpc","PeriodicalId":348778,"journal":{"name":"2010 2nd IEEE InternationalConference on Network Infrastructure and Digital Content","volume":"97 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2010-12-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2010 2nd IEEE InternationalConference on Network Infrastructure and Digital Content","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICNIDC.2010.5657947","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
The Network Configuration Protocol (NETCONF) is a new network Management Protocol which becomes more and more widely used in network management area. To make NETCONF much safer, we extend the extensible Access Control Markup Language(XACML) access control mechanism and implement it on our NETCONF network management system-BUPT-NEP. We use subtree filtering expression to represent resource instead of xpath expression, which makes the new mechanism suitable for access control on NETCONF subtree filtering rpc