An access control protocol is proposed based on the NSIS technology after studying the demands of equipments traversal and dynamic defense. The protocol consists of seven modules with different functions. Message types
data objects and operation process of the protocol are presented. The message types include request
response and error message. The request message is mainly for setting up different access policies
and the error message is mainly for returning error when authentication failure or message error occurs. Performance of the protocol is tested and verified
and the results show that the proposed protocol has the advantages of logical validity with acceptable cost. The access control information is safely and reliably transmitted based on the use of NSIS signaling mechanism.
关键词
Keywords
references
ROSENBERG J, WEINBERGER J, HUITEMA C, et al. STUN - simple traversal of user datagram protocol(UDP)through network address translators(NATs), RFC 3489[R]. Reston, VA, USA: Internet Society. IETF, 2003.
ROSENBERG J, MAHY R, HUTIEMA C, et al. Traversal using relay NAT(TURN), draft-rosenberg-midcom-turn-08[R]. Reston, VA, USA: Internet Society. IETF, 2006.
ROSENBERG J. Interactive connectivity establishment(ICE): a methodology for network address translator(NAT)traversal for offer/answer protocols, draft-ietf-mmusic-ice-15[R]. Reston, VA, USA: Internet Society. IETF, 2007.
PAN Jianli, CHEN Shanzhi. A mobile IPv6 firewall traversal scheme integrating with AAA[C]∥2006 International Conference on Wireless Communications, Networking and Mobile Computing. Piscataway, NJ, USA: IEEE, 2007:414-420.
MIHAI A, CERNAIANU D O. NAT/firewall traversal for SIP: issues and solutions[C]∥Proceedings of International Symposium on Signals, Circuits and Systems. Piscataway, NJ, USA: IEEE,2005: 521-524.
FU Xiaoming, TSCHOFENIG H, HOGREFE D. Beyond QoS signaling: a new generic IP signaling framework [J]. Computer Networks, 2006, 50(17):3416-3433.
HANCOCK R, KARAGIANNIS G, LOUGHNEY J, et al. Next steps in signaling(NSIS): framework, IETF RFC 4080 [R]. Reston, VA, USA: Internet Society. IETF, 2005.
SCHULZRINNE H, COLUMBIA U, HANCOCK R, et al. GIST: general internet signalling transport [EB/OL]. [2008-06-10]. http:∥www.ietf.org/internet-drafts/draft-ietf-nsis-ntlp-15.txt.
高磊, 张德运, ALAM M J, 等. 基于Petri网的TCP协议异常检测模型 [J]. 西安交通大学学报, 2006, 40(6): 659-662.
GAO Lei, ZHANG Deyun, ALAM M J, et al. Anomaly detection model based on Petri net for TCP protocol [J]. Journal of Xi'an Jiaotong University, 2006,40(6): 659-662.