A VPN configuration method to allow hierarchical security domains
A VPN configuration method to allow hierarchical security domains
批准号:
13680421
负责人:
ISHIBASHI Hayato
金额:
$0.58万
依托单位:
依托单位国家:
日本
项目类别:
Grant-in-Aid for Scientific Research (C)
财政年份:
2001
资助国家:
日本
项目状态:
已结题
起止时间:
2001 至 2002
中文摘要
使用现有VPN技术建立VPN连接需要具有到目标安全网关的IP级可访问性。这意味着,如果安全域(与其他域共享相同安全策略并被安全网关隔开的网络域)是分层组织的,则由于外部计算机无法直接到达内部安全网关,因此无法建立VPN连接。此外,为了对该方法进行验证和评估,我们使用SOCKS5实现了该方法,并提出并实现了一种对各个安全域的访问策略分别进行有效管理的方法。在该方法中,访问策略由每个用户的可用性和身份验证要求组成,基于安全域的层次结构采用树形结构进行管理。由于访问策略是从内部域自动传播到外部域,因此内部域管理员可以自由更改他们的访问策略,而不会打扰外部域管理员。为了对该方法进行评估,我们实现了一个策略服务器,用于查找访问策略并分发到安全网关。访问策略存储在使用LDAP(轻量级目录访问协议)服务器的分布式分层数据库中。
英文摘要
Establishing VPN connections using existing VPN technology requires IP-level reachability to the destination security gateway. This means, if security domain (a network domain which shares the same security policy and separated by security gateways with other domains) is hierarchically organized, VPN connection cannot be established because external computers cannot reach inner security gateways directly.To solve this issue, we have proposed a method to allow establishing VPN connections in such an environment, traversing security gateways. Furthermore, to demonstrate and evaluate the proposed method, we have implemented the method using SOCKS5.We also have proposed and implemented a method to separately and effectively manage each security domain's access policy. In our method, access policy, which consists of per user availability and authentication requirements, is managed with tree structure, based on the security domain hierarchy. As access policy is automatically propagated from inner domain to outer domain, inner domain's administrator can freely change their access policy without bothering outer domain's administrator. To evaluate this method, we have implemented a policy server that lookups access policy and distribute to security gateways. Access policy is stored in distributed, hierarchical databases using LDAP (Lightweight Directory Access Protocol) servers.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
Hayato Ishibashi: "New Approach for Configuring Hierarchical Virtual private Networks using Proxy Gateways"Lecture Notes in Computer Science, LNCS 2662. (to be published). (2003)
Hayato Ishibashi:“使用代理网关配置分层虚拟专用网络的新方法”计算机科学讲义,LNCS 2662。(待出版)。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
Hayato Ishibashi: "New Approach for Configuring Hierarchical Virtual Private Networks using Proxy Geteways"Lecture Notes in Computer Science. 2662(to appear). (2003)
Hayato Ishibashi:“使用代理 Geteways 配置分层虚拟专用网络的新方法”计算机科学讲义。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
Hayato Ishibashi: "New Approach for Configuring Hierarchical Virtual Private Networks using Proxy Gateways"Lecture Notes in Computer Science. 2662(to appear). (2003)
Hayato Ishibashi:“使用代理网关配置分层虚拟专用网络的新方法”计算机科学讲座笔记。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
Study on a Cooperative Distributed Caching Method for DTN Clusters
-
批准号:24500090
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$2.0万
-
财政年份:2012
-
负责人:ISHIBASHI Hayato
-
依托单位:
A Study on Constructing Virtual Overlay Networks Being Aware of Underlying Physical Networks
-
批准号:19500058
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$2.5万
-
财政年份:2007
-
负责人:ISHIBASHI Hayato
-
依托单位: