Please wait a minute...
Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering)  2006, Vol. 7 Issue (2 ): 20-    DOI: 10.1631/jzus.2006.A0240
    
An application-layer based centralized information access control for VPN
Ouyang Kai, Zhou Jing-li, Xia Tao, Yu Sheng-sheng
School of Computer Science & Technology, Huazhong University of Science & Technology, Wuhan 430074, China
Download:     PDF (0 KB)     
Export: BibTeX | EndNote (RIS)      

Abstract  With the rapid development of Virtual Private Network (VPN), many companies and organizations use VPN to implement their private communication. Traditionally, VPN uses security protocols to protect the confidentiality of data, the message integrity and the endpoint authentication. One core technique of VPN is tunneling, by which clients can access the internal servers traversing VPN. However, the tunneling technique also introduces a concealed security hole. It is possible that if one vicious user can establish tunneling by the VPN server, he can compromise the internal servers behind the VPN server. So this paper presents a novel Application-layer based Centralized Information Access Control (ACIAC) for VPN to solve this problem. To implement an efficient, flexible and multi-decision access control model, we present two key techniques to ACIAC—the centralized management mechanism and the stream-based access control. Firstly, we implement the information center and the constraints/events center for ACIAC. By the two centers, we can provide an abstract access control mechanism, and the material access control can be decided dynamically by the ACIAC’s constraint/event mechanism. Then we logically classify the VPN communication traffic into the access stream and the data stream so that we can tightly couple the features of VPN communication with the access control model. We also provide the design of our ACIAC prototype in this paper.

Key wordsVirtual private network      Access control      Tunneling      Centralized management      Stream     
Received: 23 December 2004     
CLC:  TP393.02  
Cite this article:

Ouyang Kai, Zhou Jing-li, Xia Tao, Yu Sheng-sheng. An application-layer based centralized information access control for VPN. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2006, 7(2 ): 20-.

URL:

http://www.zjujournals.com/xueshu/zjus-a/10.1631/jzus.2006.A0240     OR     http://www.zjujournals.com/xueshu/zjus-a/Y2006/V7/I2 /20

[1] Xin-sheng Yin, Ren-peng Chen, Yu-chao Li, Shuai Qi. A column system for modeling bentonite slurry infiltration in sands[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2016, 17(10): 818-827.
[2] Kai Fang, Li-min Qiu, Xiao Jiang, Zhi-hua Gan, Ning-xiang Tong. Temperature inhomogeneity in high capacity pulse tube cryocoolers[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2015, 16(11): 910-921.
[3] Xue-yan Liu, Da-jun Yuan. An in-situ slurry fracturing test for slurry shield tunneling[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2014, 15(7): 465-481.
[4] Xiang-kai Meng, Shao-xian Bai, Xu-dong Peng. An efficient adaptive finite element method algorithm with mass conservation for analysis of liquid face seals[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2014, 15(3): 172-184.
[5] Jing-hua Xu, Shu-you Zhang, Jian-rong Tan, Ri-na Sa. Collisionless tool orientation smoothing above blade stream surface using NURBS envelope*#[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2013, 14(3): 187-197.
[6] Chuan He, Kun Feng, Yong Fang, Ying-chao Jiang. Surface settlement caused by twin-parallel shield tunnelling in sandy cobble strata[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2012, 13(11): 858-869.
[7] Suhandran Muniandy, Yew Mun Hung. Analysis of streamwise conduction in forced convection of microchannels using fin approach[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2011, 12(9): 655-664.
[8] Cheng Huang, Dai Zhou, Yan Bao. A semi-implicit three-step method based on SUPG finite element formulation for flow in lid driven cavities with different geometries[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2011, 12(1): 33-45.
[9] Assaf KLAR, Itai ELKAYAM. Direct and relaxation methods for soil-structure interaction due to tunneling[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2010, 11(1): 9-17.
[10] Tao JIANG, Yu-cai FENG, Bin ZHANG, Zhong-sheng CAO, Ge FU, Jie SHI. Monitoring correlative financial data streams by local pattern similarity[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2009, 10(7): 937-951.
[11] Sheng-bo CHEN, Wei CHEN, Wei-lan HUANG, Li-jun ZHAI, Xu-ming LIU. A cross-layer approach to enable multipacket transmission in MIMO-SDMA based WLAN[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2009, 10(2): 271-278.
[12] Jin-feng ZHANG, Rong-gang WANG, Jian-wei NIU, Yuan DONG, Hai-la WANG. Rate-distortion optimized bitstream switching for peer-to-peer live streaming[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2008, 9(4): 445-456.
[13] ZUO Dong-hong, DU Xu, YANG Zong-kai. Hybrid ants-like search algorithms for P2P media streaming distribution in ad hoc networks[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2007, 8(8): 1191-1198.
[14] GUO Tong-qiang, WENG Jian-guang, ZHUANG Yue-ting. Content subscribing mechanism in P2P streaming based on gamma distribution prediction[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2007, 8(12): 1983-1989.
[15] Szwabe Andrzej, Schorr Andreas, Hauck Franz J., Kassler Andreas J.. Dynamic multimedia stream adaptation and rate control for heterogeneous networks[J]. Journal of Zhejiang University-SCIENCE A (Applied Physics & Engineering), 2006, 7(Supplement 1): 63-69.