基于策略的网络漫游基础设施安全访问控制机制

Tetsuo Imai, Hideaki Goto, H. Sone
{"title":"基于策略的网络漫游基础设施安全访问控制机制","authors":"Tetsuo Imai, Hideaki Goto, H. Sone","doi":"10.1109/SAINT-W.2007.12","DOIUrl":null,"url":null,"abstract":"In the Internet society, IP address is treated as information of organization. This is a problem that visitor uses IP address of visited organization because IP address user of visited organization is treated as a member of the organization. For that, the user's access to home resources may be blocked by firewalls because the user's IP address is not home's one. Therefore an application of authentication and access control is needed. The requirements for authentication and access control method are summarized to six items; (1) getting accessibility to the Internet by using a user credential of the home. (2) Keeping accessibility to home resources. (3) Keeping a local accessibility to visited resources for the visitor. (4) Getting enough security along the wireless/wired channel. (5) Authenticating a user, and trusting by the result, and assigning an IP address of visited organization. (6) By the authentication information, keeping accessibility to the Internet by using a home IP address. The authors investigate the existing methods and point out the merit and demerit for these requirements. Finally, the authors propose a method named 'campus ubiquitous network' that fulfill these all requirements","PeriodicalId":254195,"journal":{"name":"2007 International Symposium on Applications and the Internet Workshops","volume":"19 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-01-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"A Policy-Based, Secure Access Control Mechanism for Network Roaming Infrastructures\",\"authors\":\"Tetsuo Imai, Hideaki Goto, H. Sone\",\"doi\":\"10.1109/SAINT-W.2007.12\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In the Internet society, IP address is treated as information of organization. This is a problem that visitor uses IP address of visited organization because IP address user of visited organization is treated as a member of the organization. For that, the user's access to home resources may be blocked by firewalls because the user's IP address is not home's one. Therefore an application of authentication and access control is needed. The requirements for authentication and access control method are summarized to six items; (1) getting accessibility to the Internet by using a user credential of the home. (2) Keeping accessibility to home resources. (3) Keeping a local accessibility to visited resources for the visitor. (4) Getting enough security along the wireless/wired channel. (5) Authenticating a user, and trusting by the result, and assigning an IP address of visited organization. (6) By the authentication information, keeping accessibility to the Internet by using a home IP address. The authors investigate the existing methods and point out the merit and demerit for these requirements. Finally, the authors propose a method named 'campus ubiquitous network' that fulfill these all requirements\",\"PeriodicalId\":254195,\"journal\":{\"name\":\"2007 International Symposium on Applications and the Internet Workshops\",\"volume\":\"19 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2007-01-15\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2007 International Symposium on Applications and the Internet Workshops\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SAINT-W.2007.12\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 International Symposium on Applications and the Internet Workshops","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SAINT-W.2007.12","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

在互联网社会中,IP地址被视为组织的信息。这是一个访问者使用被访问组织的IP地址的问题,因为被访问组织的IP地址用户被视为该组织的成员。因此,用户对家庭资源的访问可能被防火墙阻止,因为用户的IP地址不是家庭的IP地址。因此,需要一种身份验证和访问控制的应用。对认证和访问控制方法的要求总结为6项;(1)使用家庭用户凭证访问互联网。(2)保持对家庭资源的可及性。(3)为访问者保留访问资源的局部可达性。(4)在无线/有线通道上获得足够的安全性。(5)对用户进行身份验证,并根据结果进行信任,分配访问组织的IP地址。(6)通过认证信息,保持使用家庭IP地址访问Internet。作者对现有的方法进行了研究,并指出了满足这些要求的优缺点。最后,作者提出了一种满足这些要求的“校园泛在网络”方法
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A Policy-Based, Secure Access Control Mechanism for Network Roaming Infrastructures
In the Internet society, IP address is treated as information of organization. This is a problem that visitor uses IP address of visited organization because IP address user of visited organization is treated as a member of the organization. For that, the user's access to home resources may be blocked by firewalls because the user's IP address is not home's one. Therefore an application of authentication and access control is needed. The requirements for authentication and access control method are summarized to six items; (1) getting accessibility to the Internet by using a user credential of the home. (2) Keeping accessibility to home resources. (3) Keeping a local accessibility to visited resources for the visitor. (4) Getting enough security along the wireless/wired channel. (5) Authenticating a user, and trusting by the result, and assigning an IP address of visited organization. (6) By the authentication information, keeping accessibility to the Internet by using a home IP address. The authors investigate the existing methods and point out the merit and demerit for these requirements. Finally, the authors propose a method named 'campus ubiquitous network' that fulfill these all requirements
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信