...
首页> 外文期刊>International Journal of Network Security & Its Applications >A Formal Verification Framework for Security Policy Management in Mobile IP Based WLAN
【24h】

A Formal Verification Framework for Security Policy Management in Mobile IP Based WLAN

机译:基于移动IP的WLAN中安全策略管理的形式验证框架

获取原文
           

摘要

The continuous advancement of wireless technologies especially for enterprise Wireless local area networks (LANs), demands well defined security mechanisms with appropriate architectural support to overcome various security loopholes. Implementing security policies on the basis of Role based Access Control (RBAC) models is an emerging field of research in WLAN security. However, verifying the correctness of the implemented policies over the distributed network devices with changes in topology, remains unexplored in the aforesaid domain. The enforcement of organizational security policies in WLANs require protection over the network resources from unauthorized access. Hence, it is required to ensure correct distribution of access control rules to the network access points conforming to the security policy. In WLAN security policy management, the standard IP based access control mechanisms are not sufficient to meet the organizational requirements due to its dynamic topology characteristics. In an enterprise network environments, the role-based access control (RBAC) mechanisms can be deployed to strengthen the security perimeter over the network resources. Further, there is a need to model the time and location dependent access constraints. In this paper, we propose a WLAN security management system supported by a formal spatio-temporal RBAC (STRBAC) model and a Boolean satisfiability (SAT) based verification framework. The concept of mobile IP has been used to ensure fixed layer 3 address mapping for the mobile hosts in a dynamic scenario. The system stems from logical partitioning of the WLAN topology into various security policy zones. It includes a Global Policy Server (GPS) that formalises the organisational access policies and determines the high level policy configurations for different policy zones; a Central Authentication & Role Server (CARS) which authenticates the users (or nodes) and the access points (AP) in various zones and also assigns appropriate roles to the users. Every host has to register their unique MAC address to a Central Authentication and Role Server(CARS). Each policy zone consists of an Wireless Policy Zone Controller (WPZCon) that coordinates with a dedicated Local Role Server (LRS) to extract the low level access configurations corresponding to the zone access router. We also propose a formal spatio-temporal RBAC (STRBAC) model to represent the global security policies formally and a SAT based verification framework to verify the access configurations
机译:无线技术的不断发展,特别是针对企业无线局域网(LAN)的技术,要求定义完善的安全机制以及适当的体系结构支持,以克服各种安全漏洞。在基于角色的访问控制(RBAC)模型的基础上实施安全策略是WLAN安全研究的新兴领域。然而,在上述领域中仍未探索通过拓扑的变化来验证在分布式网络设备上所实施策略的正确性。 WLAN中组织安全策略的实施要求保护网络资源免受未经授权的访问。因此,需要确保将访问控制规则正确分配给符合安全策略的网络访问点。在WLAN安全策略管理中,基于标准IP的访问控制机制由于其动态拓扑特性而不足以满足组织要求。在企业网络环境中,可以部署基于角色的访问控制(RBAC)机制以增强网络资源上的安全范围。此外,需要对时间和位置相关的访问约束进行建模。在本文中,我们提出了一种由正式的时空RBAC(STRBAC)模型和基于布尔可满足性(SAT)的验证框架支持的WLAN安全管理系统。移动IP的概念已用于确保动态场景中移动主机的固定第3层地址映射。该系统源自将WLAN拓扑逻辑划分为各种安全策略区域。它包括一个全球策略服务器(GPS),用于规范组织访问策略并确定不同策略区域的高级策略配置。中央身份验证和角色服务器(CARS),该服务器对各个区域中的用户(或节点)和访问点(AP)进行身份验证,并为用户分配适当的角色。每个主机都必须将其唯一的MAC地址注册到中央身份验证和角色服务器(CARS)。每个策略区域都由一个无线策略区域控制器(WPZCon)组成,该控制器与专用的本地角色服务器(LRS)协调以提取与区域访问路由器相对应的低级访问配置。我们还提出了一个正式的时空RBAC(STRBAC)模型来正式表示全球安全策略,并提出了一个基于SAT的验证框架来验证访问配置

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号