首页> 外文期刊>IEICE Transactions on Information and Systems >A Multi-Domain Access Control Infrastructure Based on Diameter and EAP
【24h】

A Multi-Domain Access Control Infrastructure Based on Diameter and EAP

机译:基于Diameter和EAP的多域访问控制基础架构

获取原文
获取原文并翻译 | 示例
       

摘要

The evolution of Internet, the growth of Internet users and the new enabled technological capabilities place new requirements to form the Future Internet. Many features improvements and challenges were imposed to build a better Internet, including securing roaming of data and services over multiple administrative domains. In this research, we propose a multi-domain access control infrastructure to authenticate and authorize roaming users through the use of the Diameter protocol and EAP. The Diameter Protocol is a AAA protocol that solves the problems of previous AAA protocols such as RADIUS. The Diameter EAP Application is one of Diameter applications that extends the Diameter Base Protocol to support authentication using EAP. The contributions in this paper are: 1) first implementation of Diameter EAP Application, called DiamEAP, capable of practical authentication and authorization services in a multi-domain environment, 2) extensibility design capable of adding any new EAP methods, as loadable plugins, without modifying the main part, and 3) provision of EAP-TLS plugin as one of the most secure EAP methods. DiamEAP Server basic performances were evaluated and tested in a real multi-domain environment where 200 users attempted to access network using the EAP-TLS method during an event of 4 days. As evaluation results, the processing time of DiamEAP using the EAP-TLS plugin for authentication of 10 requests is about 20 ms while that for 400 requests/second is about 1.9 second. Evaluation and operation results show that DiamEAP is scalable and stable with the ability to handle more than 6 hundreds of authentication requests per second without any crashes. DiamEAP is supported by the AAA working group of the WIDE Project.
机译:互联网的发展,互联网用户的增长以及新的启用的技术功能对形成未来互联网提出了新的要求。为了构建更好的Internet,必须进行许多功能改进和挑战,包括保护多个管理域上的数据和服务的漫游。在这项研究中,我们提出了一种多域访问控制基础结构,以通过使用Diameter协议和EAP来认证和授权漫游用户。 Diameter协议是一种AAA协议,解决了诸如RADIUS之类的先前AAA协议的问题。 Diameter EAP应用程序是Diameter应用程序之一,该应用程序扩展了Diameter基本协议以支持使用EAP的身份验证。本文的贡献是:1)首次实现称为DiamEAP的Diameter EAP应用程序,该应用程序能够在多域环境中提供实用的身份验证和授权服务; 2)可扩展性设计,能够添加任何新的EAP方法作为可加载插件,而无需修改主体部分,以及3)提供EAP-TLS插件作为最安全的EAP方法之一。 DiamEAP Server的基本性能在真实的多域环境中进行了评估和测试,其中200名用户在4天的活动中尝试使用EAP-TLS方法访问网络。作为评估结果,使用EAP-TLS插件对10个请求进行身份验证的DiamEAP的处理时间约为20毫秒,而对400个请求/秒的处理时间约为1.9秒。评估和操作结果表明,DiamEAP具有可扩展性和稳定性,能够每秒处理600多个身份验证请求而不会发生崩溃。 DiamEAP得到WIDE项目AAA工作组的支持。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号