东北大学计算机软件国家工程研究中心,沈阳,110004
网络首发:2009-04-10,
纸质出版:2009
移动端阅览
陈书义 1, 孙锦山 1, 闻英友 1, 等. NSIS下通用访问控制信令协议的设计与验证[J]. 西安交通大学学报, 2009,43(4):34-38.
Design and Validation of Universal Access Control Signaling Protocol Based on Next Steps in Signaling[J]. 2009, 43(4): 34-38.
在深入研究设备穿越和动态防御需求的基础上
提出了基于下一代信令(NSIS)技术的通用访问控制协议.协议实体由7个不同的功能模块组成
并定义了协议的消息类型、数据对象和执行流程.其中
消息类型包括请求消息、应答消息和错误.请求消息将为访问控制设备部署不同的访问控制策略
而错误消息主要是在鉴权失败或者检查到信令消息出错时返回出错的原因.最后
对协议进行了测试、验证
结果表明所提协议具有逻辑正确性
且性能开销较小.通过引入NSIS信令机制
保障了访问控制信令信息安全、可靠传输.
An access control protocol is proposed based on the NSIS technology after studying the demands of equipments traversal and dynamic defense. The protocol consists of seven modules with different functions. Message types
data objects and operation process of the protocol are presented. The message types include request
response and error message. The request message is mainly for setting up different access policies
and the error message is mainly for returning error when authentication failure or message error occurs. Performance of the protocol is tested and verified
and the results show that the proposed protocol has the advantages of logical validity with acceptable cost. The access control information is safely and reliably transmitted based on the use of NSIS signaling mechanism.
ROSENBERG J, WEINBERGER J, HUITEMA C, et al. STUN - simple traversal of user datagram protocol(UDP)through network address translators(NATs), RFC 3489[R]. Reston, VA, USA: Internet Society. IETF, 2003.
ROSENBERG J, MAHY R, HUTIEMA C, et al. Traversal using relay NAT(TURN), draft-rosenberg-midcom-turn-08[R]. Reston, VA, USA: Internet Society. IETF, 2006.
ROSENBERG J. Interactive connectivity establishment(ICE): a methodology for network address translator(NAT)traversal for offer/answer protocols, draft-ietf-mmusic-ice-15[R]. Reston, VA, USA: Internet Society. IETF, 2007.
PAN Jianli, CHEN Shanzhi. A mobile IPv6 firewall traversal scheme integrating with AAA[C]∥2006 International Conference on Wireless Communications, Networking and Mobile Computing. Piscataway, NJ, USA: IEEE, 2007:414-420.
MIHAI A, CERNAIANU D O. NAT/firewall traversal for SIP: issues and solutions[C]∥Proceedings of International Symposium on Signals, Circuits and Systems. Piscataway, NJ, USA: IEEE,2005: 521-524.
王文奇. 入侵检测与安全防御协同控制研究 [D]. 西安:西北工业大学信息科学与技术学院,2006.
FU Xiaoming, TSCHOFENIG H, HOGREFE D. Beyond QoS signaling: a new generic IP signaling framework [J]. Computer Networks, 2006, 50(17):3416-3433.
HANCOCK R, KARAGIANNIS G, LOUGHNEY J, et al. Next steps in signaling(NSIS): framework, IETF RFC 4080 [R]. Reston, VA, USA: Internet Society. IETF, 2005.
SCHULZRINNE H, COLUMBIA U, HANCOCK R, et al. GIST: general internet signalling transport [EB/OL]. [2008-06-10]. http:∥www.ietf.org/internet-drafts/draft-ietf-nsis-ntlp-15.txt.
高磊, 张德运, ALAM M J, 等. 基于Petri网的TCP协议异常检测模型 [J]. 西安交通大学学报, 2006, 40(6): 659-662.
GAO Lei, ZHANG Deyun, ALAM M J, et al. Anomaly detection model based on Petri net for TCP protocol [J]. Journal of Xi'an Jiaotong University, 2006,40(6): 659-662.
0
浏览量
4
下载量
1
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621